What to Do If Your Account Is Hacked
Recover the email first, then sessions, then passwords. Doing it in the wrong order lets the attacker back in.
Short answer: Secure the email inbox first — it is the master key that resets everything else. Then, on each compromised account: change the password, sign out all active sessions, remove unknown recovery emails, phone numbers, app passwords and forwarding rules, and only then turn on two-factor authentication. Resetting a password without killing existing sessions leaves the attacker logged in.
Most account takeovers are credential stuffing: a password reused from a site that was breached years ago. That is why the fix is not just one password but every place that password went.
Recovery in order
- Email first: new unique password, sign out all devices, check filters and forwarding rules for silent copies going out.
- Check the account's security activity log and note the times and locations you do not recognise.
- Remove unknown recovery phone numbers, backup emails, trusted devices and third-party app access.
- Turn on two-factor authentication with an authenticator app or hardware key rather than SMS where possible.
- Save the backup codes somewhere offline.
- Repeat for banking, then social, then shopping accounts — highest damage first.
- If money moved, tell the bank the same day and report it to the national fraud service.
Signs it happened at all
| Signal | What it usually means |
|---|---|
| Password reset emails you did not request | Someone is probing your accounts |
| Missing emails or a new forwarding rule | Attacker is hiding alerts from you |
| Logins from unfamiliar locations | Active session in someone else's hands |
| Friends receiving odd messages from you | Account is being used for onward scams |
After the clean-up
Check whether your address appears in known breaches, review connected apps every few months, and keep two-factor backup codes printed somewhere physical. If a work account was involved, tell your IT team immediately — the same credentials often unlock far more than your inbox.
Want to go further? Read our guide on Is Charging Your Phone Overnight Actually Bad? or browse everything in Technology.
Frequently asked questions
- Is SMS two-factor good enough?
- It is far better than nothing, but SIM-swap attacks defeat it. Prefer an authenticator app or a hardware key for email and banking.
- Should I delete the account and start again?
- Rarely. Recovering it keeps your history and prevents someone else re-registering the identity. Delete only if recovery genuinely fails.
- How do I know the attacker is out?
- After signing out all sessions, revoking app access and changing the password, the activity log should show only your own devices. Recheck it a day later.
Sources & references
About the author
Daniel Okoye
Technology Writer
Daniel tests consumer hardware and software and explains what actually changes for everyday users, without the marketing language.
All articles by Daniel Okoye →Related articles
Is Charging Your Phone Overnight Actually Bad?
Modern phones stop drawing full power once they hit 100%, so the real damage comes from heat and long spells at a full charge.
· 6 min read
Why Does an AI Assistant Get Your Question Wrong? Five Fixes That Work
Most bad answers come from missing context, not a weak model. The five rewrites that turn a vague prompt into a usable one.
· 6 min read
How to Make an Old Laptop Usable Again Instead of Replacing It
An SSD and more RAM beat any software tweak. What a 60 EUR upgrade fixes, and when the machine is genuinely finished.
· 7 min read
Why Is My Phone Battery Draining Overnight? The Checks in Order
If you lose more than 5-10% overnight, something specific is running. How to find it in the battery menu without installing anything.
· 5 min read
Read next
Why Does an AI Assistant Get Your Question Wrong? Five Fixes That WorkMost bad answers come from missing context, not a weak model. The five rewrites that turn a vague prompt into a usable one.
Comments
Questions, corrections and experiences from readers are welcome. We read everything and update articles when you spot something wrong. Please keep it civil — see our comment policy.
No comments on this article yet — be the first.