Guides Recovery

What to do when an account is hacked

Order matters. Doing these in the wrong sequence lets the attacker undo your work while you are still doing it.

7 min read  ·  Last reviewed 11 August 2026  ·  Written for people looking after their own devices

The order that stops the attacker undoing your work Email first it resets everything else Change from a clean device not the suspect machine Sign out everywhere revoke live sessions Check what changed recovery, forwarding, apps
Changing a password does not always end existing sessions, which is why revoking them is a separate step.

1. Start with email

Whatever was breached, secure the email account first. It can reset the password of nearly everything else, so it is the account the attacker wants. Regaining a shopping account while they still hold your inbox achieves nothing.

2. Change the password from a device you trust

If malware on the machine is a possibility, use a different device. Changing a password on a computer with a keylogger simply tells the attacker the new one.

3. Sign out everywhere

Changing a password does not always end existing sessions. Most services have an option to sign out of all devices or revoke active sessions - use it, or the attacker stays signed in with the old credential.

4. Check what they changed

  • Recovery email address and phone number - a common quiet change that keeps access open after you reset the password.
  • Mail forwarding rules and filters, which silently copy or hide messages.
  • Connected apps and third-party access, which can act on the account independently of your password.
  • Second-factor devices registered to the account.
  • Reply-to address and signature.
What to check that they quietly changed Recovery address and phone number Forwarding rules and filters Connected apps third-party access Second-factor devices registered keys Reply-to address and signature Active sessions sign out everywhere
Changing the password does not undo any of these. A recovery address left in place keeps the door open.

5. Turn on a second factor

If it was not on before, now is the moment. If it was on and they got in anyway, re-register it and remove any device you do not recognise.

6. Work outwards

Any account that used the same password, and any account whose recovery goes through the compromised one. This is the point at which reuse turns one incident into an afternoon of work.

7. Tell the people who will be targeted next

Contacts often receive messages from a compromised account. A short note saying it was compromised and to ignore anything unusual costs nothing and prevents the next person falling for it.

If money is involved

Contact the bank or card provider straight away - this is genuinely time-sensitive in a way the rest is not. Keep the messages and any transaction references. Depending on where you are, reporting it to the national fraud or cybercrime body may also be worthwhile.