Practical Answers for Everyday Independence

Category: Technology

What to Do If You Think an Account Has Been Hacked

An unexpected password-reset message appears. A login alert comes from a place you have never been. A friend says your account sent them a strange message. Maybe your password suddenly does not work, purchases appear that you did not make, or settings have changed without your permission.

That can be frightening, but panic makes it harder to decide what to do first. You do not need to understand exactly how the account was accessed before you begin protecting yourself. The immediate goal is to stop anyone else from using the account, protect connected accounts, check for financial or identity theft, and create a record of what happened.

Work through this guide in order. If a step does not apply, move to the next one.

First: Make Sure the Warning Is Real

Some security alerts are legitimate. Others are phishing messages designed to scare you into clicking a link and giving a scammer your password.

Do not click the link in an unexpected security email or text. Instead:

  1. Open the company’s official app, or type its website address into your browser yourself.
  2. Sign in from there if you can.
  3. Open the account’s Security, Recent Activity, Login Activity, or Devices section.
  4. Look for the warning, sign-in, message, purchase, or change that concerned you.

If the alert does not appear in the official account, the message may have been fake. Delete or report it as phishing. If you already clicked the link, entered information, downloaded a file, or installed something, continue with the steps in this guide.

Signs That an Account May Have Been Hacked

One unusual event does not always mean someone has control of your account. Services may flag your own activity when you use a new device, travel, connect through a different network, or update an app. However, take the situation seriously if you notice:

  • A correct password suddenly stops working
  • A password, phone number, recovery email, or username was changed without your permission
  • Login alerts from unfamiliar devices or locations
  • Verification codes or approval requests you did not request
  • Messages, posts, comments, or friend requests you did not send
  • Purchases, transfers, subscriptions, or advertisements you did not authorize
  • Deleted messages or new forwarding rules in your email
  • Unknown devices, apps, browser extensions, or connected services
  • Friends receiving strange links or requests for money from your account
  • Security notifications being deleted or marked as read
  • Your phone suddenly losing cellular service when it should have service

If several accounts are affected, your email account, device, phone number, or reused password may be the common connection.

Helpful Resources: Browse Device & Account Security for products, equipment, services, or supplies related to this section.

The First 10 Minutes

If you can still access the account, begin here:

  1. Use a device you trust. If you think the current phone or computer may contain harmful software, use another updated device if one is available.
  2. Open the official app or website directly.
  3. Take screenshots of important evidence before changing anything.
  4. Change the password to a new, unique password.
  5. Choose Sign out of all devices or End all sessions if the account offers it.
  6. Turn on two-factor authentication or replace any second-step method you do not recognize.
  7. Check that the recovery email address and phone number belong to you.
  8. Remove unfamiliar devices, apps, passkeys, security keys, and connected accounts.
  9. Review recent activity and report anything you did not do.
  10. Protect your email account and any other account that used the same password.

If you cannot access the account, skip to If You Have Been Locked Out below.

Step 1: Use a Safe Device

Changing a password on an infected device may give the new password to the same person who stole the old one. Before changing important account information, think about how the problem started.

Use a different trusted device if:

  • You installed an unfamiliar app or browser extension.
  • You downloaded or opened a suspicious attachment.
  • Your device is displaying unusual pop-ups or redirects.
  • Security software reports malware.
  • Several unrelated accounts were accessed shortly after you used the device.

If another device is not available, update the operating system, browser, apps, and security software. Run a complete security scan and remove anything identified as harmful. Restart the device when the scan is finished.

Do not call a phone number displayed in a pop-up claiming that your device is infected. Legitimate security warnings do not require you to pay a stranger, buy gift cards, install remote-access software, or give someone control of your screen.

Step 2: Preserve Useful Evidence

Before deleting unfamiliar messages or changing settings, save enough information to explain what happened. This can help with account recovery, disputed charges, identity-theft reports, insurance claims, or conversations with law enforcement.

Save:

  • Screenshots of login alerts and security notifications
  • Dates and approximate times
  • Email addresses, usernames, phone numbers, and website addresses involved
  • Unfamiliar devices and locations shown in account activity
  • Messages or posts sent from the account
  • Transaction numbers, receipts, and unauthorized charges
  • Changes to recovery information or account settings
  • Any communication with the company’s support team

Do not continue communicating with the suspected scammer just to gather more evidence. Save what you already have, then block and report them.

Step 3: Change the Password

Create a password that is:

  • Long—aim for at least 12 characters, and longer when possible
  • Unique to this account
  • Difficult for another person to guess
  • Not based on information someone could find online

A password manager can create and store a strong random password. A long passphrase made from unrelated words can also work when the service permits it.

Do not make a small change to the old password. Changing Garden2025! to Garden2026! is predictable. Do not reuse a password from another account either.

After changing it, look for an option to sign out everywhere. A password change does not always close sessions that are already active. Ending all sessions forces other devices to sign in again.

Step 4: Secure Your Recovery Information

Recovery information determines who can reset the password later. Someone who gained access may have added their own phone number or email address so they can return after you change the password.

Review:

  • Recovery email addresses
  • Recovery phone numbers
  • Security questions
  • Backup codes
  • Passkeys
  • Physical security keys
  • Authenticator apps
  • Trusted devices
  • App-specific passwords

Remove anything you do not recognize. Confirm that your own recovery information is current. Create a new set of backup codes if the service offers them; generating new codes usually cancels the old set.

If an unfamiliar method cannot be removed, contact the company’s official support service through its app or website.

Step 5: Turn On Two-Factor Authentication

Two-factor authentication requires another form of proof in addition to a password. This can prevent someone with a stolen password from signing in again.

When possible, use a passkey, physical security key, authenticator app, or approval prompt with number matching. A text-message code is not the strongest method, but it is still better than using only a password when no stronger option is available.

If two-factor authentication was already enabled, make sure the intruder did not:

  • Add their own verification method
  • Create backup codes
  • Register a passkey or security key
  • Mark an unfamiliar device as trusted
  • Disable your existing method

Never approve a login request you did not initiate, and never give anyone a verification or recovery code.

Step 6: Review Devices, Sessions, and Connected Apps

Most major accounts show devices or sessions that are currently or recently signed in. Review the list carefully.

For each unfamiliar entry:

  1. Take a screenshot if it may be useful evidence.
  2. Select Sign Out, Remove, This Wasn’t Me, or Secure Account.
  3. Follow any additional instructions provided by the service.

Then review apps and websites connected to the account. These may have permission to read email, view files, post messages, access contacts, or manage information even after the password changes.

Remove:

  • Apps you no longer use
  • Services you do not recognize
  • Browser extensions you did not install
  • Third-party email programs you did not authorize
  • Connected social media or shopping accounts you did not add

If you are unsure about an app, search for its name using a separate browser tab before removing it. Do not click a link inside an unfamiliar app listing.

Step 7: Check What Was Changed or Taken

Regaining control is only part of the job. Review what happened while the other person had access.

Look for:

  • Sent, deleted, archived, or forwarded email
  • Changes to filters and automatic forwarding rules
  • Deleted security notices
  • New contacts, followers, administrators, or account managers
  • Posts, private messages, comments, or advertisements
  • New subscriptions or recurring payments
  • Saved addresses and payment methods
  • Orders, refunds, gift-card purchases, or reward-point transfers
  • Downloaded files or exported account data
  • Changes to privacy settings
  • Files shared with unfamiliar people

Email forwarding rules deserve special attention. An intruder may create a rule that quietly sends copies of your messages elsewhere, hides security alerts, or moves incoming mail out of sight. Check Forwarding, Filters, Rules, Delegation, and Automatic Replies in your email settings.

Protect Your Email Account First

Your primary email account is often the key to everything else. Banks, stores, social media platforms, and other services send password-reset links there. If someone controls your email, they may be able to take over additional accounts even after you secure the first one you noticed.

If your email may be affected:

  1. Secure it before lower-priority accounts.
  2. Change its password from a trusted device.
  3. Sign out other sessions.
  4. Review recovery methods and connected apps.
  5. Check forwarding rules, filters, deleted mail, and sent mail.
  6. Turn on two-factor authentication.
  7. Review other accounts that use that email address for recovery.

If your email password was reused anywhere else, change those accounts immediately using different passwords.

If You Have Been Locked Out

Use the company’s official account-recovery process. Start from the official app or type the company’s address yourself, then look for:

  • Forgot Password
  • Can’t Sign In
  • Recover Account
  • My Account Was Hacked
  • I Don’t Have Access to This Phone or Email

Complete the recovery form from a familiar device, browser, network, and location when possible. Those details may help the provider recognize you. Answer questions carefully and provide as much accurate information as you can.

You may be asked for:

  • A previous password
  • The approximate date the account was created
  • A recovery email address or phone number
  • Recent contacts or email subject lines
  • Purchases, subscriptions, or billing information
  • A code sent to a previously trusted device
  • Identification for accounts that require identity verification

Recovery may not be immediate. Security delays can be frustrating, but they are designed to prevent someone else from quickly replacing your information and taking permanent control.

Do not pay an online “account recovery expert” who claims to have special access. They may take your money, steal more information, or use the situation to continue the scam.

If Money or Payment Information Is Involved

Contact the financial institution using the number on the back of your card, on a statement, or on its official website. Do not use a phone number from the suspicious message.

Tell the bank, card issuer, payment service, or retailer that the account may have been accessed without permission. Ask about:

  • Freezing or locking the account or card
  • Disputing unauthorized transactions
  • Replacing the card or account number
  • Stopping transfers or recurring charges
  • Reviewing recent login and transaction activity
  • Adding additional security to the account

Act quickly. The rules and deadlines for reporting unauthorized payments vary by payment method and account type.

If a shopping account was hacked, remove unfamiliar addresses and payment methods, cancel unrecognized orders when possible, and contact the retailer and payment provider.

If Personal Information Was Exposed

An intruder may have accessed more than the account itself. Consider what information the account contained, including:

  • Social Security number
  • Driver’s license or passport information
  • Bank or credit card numbers
  • Tax records
  • Health or insurance information
  • Photographs of identification documents
  • Home address, birth date, or answers to security questions

If someone used—or may be able to use—your personal information, visit IdentityTheft.gov, the Federal Trade Commission’s official identity-theft recovery site. It can create a recovery plan based on the information involved.

You may also need to contact the affected organization, place a fraud alert or security freeze on your credit reports, replace compromised identification, or monitor financial and insurance statements. The right steps depend on what was exposed.

If Your Phone Suddenly Loses Service

Unexpected loss of cellular service can be a warning sign of a SIM-swap attack, especially if password-reset messages or account changes happen at the same time. In a SIM swap, someone convinces a mobile carrier to move your phone number to another SIM or device.

From another phone:

  1. Contact your mobile carrier using its official number.
  2. Ask whether your number or SIM was recently transferred or changed.
  3. Tell the carrier that you suspect unauthorized activity.
  4. Add or change the account PIN or port-out protection.
  5. Secure email, banking, and other accounts that use text messages for verification.
  6. Replace text-message verification with a stronger method when possible.

Warn People Who May Be Affected

If the account sent messages, links, requests for money, or files, tell your contacts that the messages were not from you. Use another communication method if you no longer control the account.

Keep the warning simple:

My account was accessed without my permission. Please do not click links, open attachments, send money, or respond to recent unusual messages from it. Delete those messages and let me know if you shared any information.

Do not include your new password, recovery details, or other sensitive information in the warning.

If the affected account belongs to an employer, school, volunteer organization, or other group, notify its IT or security contact promptly. The account may provide access to information belonging to other people.

Change Reused Passwords

If the compromised password was used anywhere else, assume those accounts are at risk. Criminals routinely try stolen username-and-password combinations on other services.

Prioritize:

  1. Email accounts
  2. Banks and payment services
  3. Password managers
  4. Apple, Google, and Microsoft accounts
  5. Mobile carrier accounts
  6. Shopping sites with stored payment information
  7. Social media
  8. Cloud storage and health, tax, insurance, or government accounts

Give every account a different password. A password manager can make this much easier.

Check Your Devices

Update the operating system, browser, apps, and security software on devices used with the compromised account. Run a security scan, remove unfamiliar apps and browser extensions, and restart the device.

Also check for:

  • Remote-access programs you did not intentionally install
  • New device-administrator permissions
  • Unknown user profiles
  • Changes to browser search or homepage settings
  • Unfamiliar virtual private network profiles
  • Accessibility permissions granted to suspicious apps

If someone had remote control of the device, or if suspicious behavior continues after a scan, get help from a reputable local technician or the device manufacturer’s official support service. A factory reset may sometimes be appropriate, but back up important information and understand what will be erased before doing it.

Watch for Follow-Up Scams

After an account compromise, you may receive messages from people claiming to be:

  • The company’s fraud department
  • A bank investigator
  • A government agent
  • A cybersecurity specialist
  • A person who can recover the account or stolen money

They may already know personal details from the compromised account, which can make them sound convincing. Do not assume someone is legitimate because they know your name, email address, recent purchase, or part of an account number.

Never send money, cryptocurrency, gift cards, passwords, verification codes, backup codes, or remote access to your device. End the conversation and contact the organization through a verified official channel.

After the Account Is Secure

For the next several weeks:

  • Review login history and security alerts.
  • Watch bank, credit card, and payment statements.
  • Look for password-reset messages you did not request.
  • Check sent mail, forwarding rules, posts, and connected apps again.
  • Confirm that recovery information remains correct.
  • Monitor other accounts that shared the old password.
  • Keep copies of reports, screenshots, and case numbers.

If new unauthorized activity appears, the original access may not have been completely removed. Repeat the security review from a trusted device and contact official support.

A Simple Recovery Checklist

When you need the shortest version, use this order:

  1. Open the official app or website—do not use the alert’s link.
  2. Use a trusted, updated device.
  3. Save screenshots and important details.
  4. Change the password to one that is new and unique.
  5. Sign out every other device and session.
  6. Correct recovery information and remove unfamiliar methods.
  7. Turn on two-factor authentication.
  8. Remove unknown devices, apps, forwarding rules, and connections.
  9. Secure your email and every account that reused the password.
  10. Contact banks or payment services about unauthorized transactions.
  11. Visit IdentityTheft.gov if personal information may have been misused.
  12. Warn affected contacts and monitor the account.

Discovering that someone may have accessed an account can feel personal and overwhelming. It does not mean you were careless or should have known better. Scams, stolen passwords, data breaches, and convincing fake login pages affect people with every level of technical experience.

What matters now is responding in a clear order: regain control, remove access, protect connected accounts, report financial or identity theft, and strengthen recovery options. One step at a time is enough.

Related Guides