Technology

What to Do Immediately After Suspecting Your Account Was Hacked

What to Do Immediately After Suspecting Your Account Was Hacked

Photo credit: TrendingExperts.net

Think your account has been compromised? These prioritized steps can help you regain control, limit damage, and protect your other accounts.

Key Takeaways

  • Act immediately — the first 30 minutes after suspecting a hack are the most critical for limiting damage.
  • Change your password on the compromised account before doing anything else, if you still have access.
  • Enable two-factor authentication to block attackers even if they have your password.
  • Check all linked accounts and email addresses for signs of unauthorized access.
  • Reusing passwords on multiple sites dramatically amplifies the damage from a single breach.
  • Report the compromise to the platform and monitor for any financial or identity-related activity.

How to Know If Your Account Was Actually Compromised

Not every unfamiliar login alert means your account has been taken over, but certain signals are hard to ignore. Common indicators include: a password-reset email you didn't request, login notifications from an unfamiliar city or device, emails in your sent folder that you didn't write, posts or messages appearing under your name that you didn't create, or friends asking why you sent them a strange link.

If you see any of these signs, treat the situation as a potential compromise and act immediately. The tools and accounts you'll need are listed below.

What you will need

Access to a trusted device (phone, tablet, or computer not suspected of malware)
Access to your account recovery email address or phone number
Knowledge of which email address is tied to the compromised account
A few minutes of uninterrupted time to work through recovery steps
Required

Account Recovery Page

The platform's official recovery flow for regaining access to a locked or compromised account.

Required

Authenticator App (e.g., any TOTP-based app)

Generates time-based one-time codes for two-factor authentication, stronger than SMS codes.

Optional

Password Manager

Stores and generates unique passwords for every account so you never need to reuse credentials.

Optional

Have I Been Pwned (haveibeenpwned.com)

Free public tool that checks whether your email address appears in known data breach databases.

Step-by-Step: Regaining Control of a Hacked Account

Speed matters. The faster you respond, the less time an attacker has to change your recovery details, exfiltrate data, or use your account to harm others. Work through the steps below in order — skipping ahead can leave gaps that attackers exploit.

If You've Lost Account Access

If you can no longer log in, go directly to the platform's account recovery page — look for links like 'Forgot password' or 'Can't access your account.' Most major services have a dedicated recovery flow for compromised accounts. Act as fast as possible, because attackers often change the recovery email address shortly after gaining access.

1

Stay calm and don't click anything suspicious

Before taking any action, stop interacting with any unexpected emails, texts, or login prompts that may have triggered your suspicion. Clicking links in phishing emails or fake 'account alert' messages can deepen the compromise. Open a new browser tab and navigate directly to the platform's official website by typing the address yourself.

Tip: Look for warning signs like login alerts from unfamiliar locations, emails you didn't send, or unexpected password-reset notifications in your inbox.
2

Change your password immediately

If you still have access to the account, go to the security or account settings and change your password right away. Choose a long, unique passphrase — at least 12 characters — that you haven't used on any other site. Do not reuse a password from a different account; credential stuffing attacks can quickly compromise multiple accounts when one password leaks.

Warning: Do not change your password on a device you believe may be infected with malware. See the warning below before proceeding.
3

Enable two-factor authentication

Once you've secured your password, turn on two-factor authentication (2FA) in the account's security settings. This adds a second verification step — typically a code from an authenticator app or a text message — so that knowing your password alone isn't enough to log in. Authenticator apps generally offer stronger protection than SMS codes, which can be intercepted in rare SIM-swapping attacks.

Tip: Most major platforms — including email providers, social networks, and financial sites — offer 2FA. Enable it on every account that supports it, not just the one that was compromised.
4

Review active sessions and connected apps

Navigate to the security or privacy section of the account and look for an option showing active sessions or logged-in devices. Sign out of all sessions except your current one. Also review any third-party apps connected to the account and revoke access for anything unfamiliar or no longer needed.

5

Secure your recovery email and phone number

Attackers frequently change recovery contact information to lock legitimate owners out permanently. Verify that the recovery email address and phone number listed in your account settings are still yours. If anything has changed, correct it immediately. Then log into your recovery email account and change that password too, since it's a gateway to everything else.

6

Check for unauthorized activity

Review the account's activity log or sent folder for any actions you didn't take — sent messages, purchases, profile changes, or posts. Document what you find by taking screenshots; this record can be useful when reporting the incident to the platform or, if financial fraud occurred, to your bank or relevant authorities.

Tip: If the compromised account was linked to a financial service or online store, contact that institution directly to flag any potentially fraudulent transactions.
7

Report the compromise and notify affected contacts

Use the platform's official reporting tool to flag that your account was hacked — most services have a dedicated form for this. If the attacker sent messages to your contacts impersonating you, notify those people directly so they don't fall for follow-up scams. A brief message through a separate channel (such as a text) warning them not to click links they may have received from your account is often enough.

Use a Password Manager Going Forward

A password manager generates and stores unique, complex passwords for every account, eliminating the temptation to reuse credentials. Most reputable managers also alert you when a saved password appears in a known data breach, giving you an early warning system built into your daily workflow.

What to Do After You've Recovered Access

Once you've regained control, take a broader look at your overall account security. Check whether your email address appears in any known data breaches by visiting haveibeenpwned.com — a free, widely trusted public database. If your email shows up, change the password for every account associated with that address.

Consider auditing all your other accounts with the same disciplined approach described above. Our account security checklist walks you through proactive steps to prevent future compromises. The goal is to ensure that even if one account is breached again, attackers can't use it as a stepping stone into the rest of your digital life.

Don't Log In from an Untrusted Device

If you suspect your device itself may be infected with malware, avoid using it to enter new passwords or recovery codes. Malware can capture keystrokes and hand fresh credentials directly to attackers. Use a trusted device — such as a friend's computer or your smartphone on a separate network — to take initial recovery steps.

Technology Editorial Team

Author

Technology Editorial Team

Technology Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles →
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.