Skip to content
DailyInsights.Life
Live
Technology

What to Do If Your Account Is Hacked

Recover the email first, then sessions, then passwords. Doing it in the wrong order lets the attacker back in.

Daniel OkoyeDaniel OkoyePublished Updated 7 min read
Share:
What to Do If Your Account Is Hacked
Short answer: Secure the email inbox first — it is the master key that resets everything else. Then, on each compromised account: change the password, sign out all active sessions, remove unknown recovery emails, phone numbers, app passwords and forwarding rules, and only then turn on two-factor authentication. Resetting a password without killing existing sessions leaves the attacker logged in.

Most account takeovers are credential stuffing: a password reused from a site that was breached years ago. That is why the fix is not just one password but every place that password went.

Recovery in order

  1. Email first: new unique password, sign out all devices, check filters and forwarding rules for silent copies going out.
  2. Check the account's security activity log and note the times and locations you do not recognise.
  3. Remove unknown recovery phone numbers, backup emails, trusted devices and third-party app access.
  4. Turn on two-factor authentication with an authenticator app or hardware key rather than SMS where possible.
  5. Save the backup codes somewhere offline.
  6. Repeat for banking, then social, then shopping accounts — highest damage first.
  7. If money moved, tell the bank the same day and report it to the national fraud service.

Signs it happened at all

SignalWhat it usually means
Password reset emails you did not requestSomeone is probing your accounts
Missing emails or a new forwarding ruleAttacker is hiding alerts from you
Logins from unfamiliar locationsActive session in someone else's hands
Friends receiving odd messages from youAccount is being used for onward scams

After the clean-up

Check whether your address appears in known breaches, review connected apps every few months, and keep two-factor backup codes printed somewhere physical. If a work account was involved, tell your IT team immediately — the same credentials often unlock far more than your inbox.

Want to go further? Read our guide on Is Charging Your Phone Overnight Actually Bad? or browse everything in Technology.

Frequently asked questions

Is SMS two-factor good enough?
It is far better than nothing, but SIM-swap attacks defeat it. Prefer an authenticator app or a hardware key for email and banking.
Should I delete the account and start again?
Rarely. Recovering it keeps your history and prevents someone else re-registering the identity. Delete only if recovery genuinely fails.
How do I know the attacker is out?
After signing out all sessions, revoking app access and changing the password, the activity log should show only your own devices. Recheck it a day later.

Sources & references

    About the author

    Daniel Okoye

    Daniel Okoye

    Technology Writer

    Daniel tests consumer hardware and software and explains what actually changes for everyday users, without the marketing language.

    All articles by Daniel Okoye
    Why Does an AI Assistant Get Your Question Wrong? Five Fixes That Work

    Most bad answers come from missing context, not a weak model. The five rewrites that turn a vague prompt into a usable one.

    Comments

    Questions, corrections and experiences from readers are welcome. We read everything and update articles when you spot something wrong. Please keep it civil — see our comment policy.

    No account needed. Your comment is stored in your browser and sent to the desk for review.

    No comments on this article yet — be the first.