What to Do If Your Online Account Is Hacked: 12 Immediate Steps

Repairing a hacked online account security shield on a laptop and phone

Updated:
10 September 2026 · Reading time: about 9 minutes

An unfamiliar login, password-reset notice, message you did not send or changed recovery address can mean someone else has access to your account. Move quickly, but do not let panic push you into a fake “recovery service.” Use only the provider’s official app, a saved bookmark or a website address you independently know.

First priority

Secure the email account used to reset your other passwords. If email is compromised, an attacker may intercept recovery messages and regain accounts after you change them. If money, identity documents, workplace data or another person’s information is involved, contact the relevant bank, provider or administrator through a verified channel immediately.

Signs an account may be compromised

  • A login, device or location you do not recognise.
  • A password, recovery phone, recovery email or security method changed without you.
  • Messages, posts, comments, files or purchases you did not create.
  • Friends receive strange links or requests from your account.
  • Email stops arriving, disappears, or is automatically forwarded.
  • New connected apps, browser extensions, payment methods or permissions appear.
  • You are signed out and the correct password no longer works.

One unfamiliar location can occasionally be caused by mobile networks, travel or a provider’s location estimate. Do not ignore it, but confirm using the account’s official security-activity page instead of trusting a link in the alert.

1. Use a device you trust

If you suspect malware or remote access on the affected device, use another updated device for account recovery when possible. Disconnect a device from the network if someone is actively controlling it. Do not install software recommended by an unsolicited caller or message.

2. Open the official recovery route

Navigate independently to the service. If you can still sign in, open its security settings. If you cannot, use the provider’s official account-recovery page. Avoid phone numbers and “support agents” found in social-media replies, sponsored posts or unexpected messages.

For a Google Account, the official compromised-account guidance directs users who cannot sign in to Google’s account-recovery page and users who can sign in to review recent security events and registered devices.

3. Change the password

Create a completely new password that has never been used on another account. Do not make a small variation of the old one. Store it in a protected password manager. Our guide to creating strong, unique passwords explains a safe migration process.

If the exposed password was reused, assume every account sharing it is at risk. Change the primary email and financial accounts first, then continue through the rest.

4. Sign out unknown sessions and devices

Look for a page named “Your devices,” “Where you’re signed in,” “Sessions” or “Recent activity.” Remove devices and sessions you do not recognise. If the service offers “sign out everywhere,” understand that it will also sign out your own devices and make sure you know the new password and recovery route first.

5. Repair recovery details

Check the recovery email, phone number, alternate address, trusted contacts and account name. Remove changes you did not make. An attacker may add a recovery path so that changing the password alone does not remove their access.

6. Reset multi-factor authentication

Review every registered passkey, security key, authenticator, prompt device and phone number. Remove unknown methods and replace backup codes if an old copy may be exposed. Then configure a safe primary and recovery method using our two-step verification comparison.

Never share a recovery code.

A legitimate support process should not require you to read a one-time code or backup code to a stranger. Enter codes only into the genuine service during a recovery action you started.

7. Review connected apps and permissions

A third-party app can retain access even after a password change. Review linked apps, OAuth access, mail clients, browser extensions, automation tools and app-specific passwords. Remove anything unfamiliar or no longer needed. Reconnect a legitimate app later through its official process if necessary.

8. Check hidden account settings

Email accounts need special attention because attackers may create rules that silently copy or hide messages. Review:

  • Automatic forwarding addresses.
  • Filters and inbox rules.
  • Mail delegation and connected inboxes.
  • Blocked addresses and automatic replies.
  • POP, IMAP and app-password access.
  • Sent, deleted and archived messages.

Google’s hacked-account guidance specifically tells Gmail users to remove unfamiliar labels, filters or forwarding rules. Other mail services use different names for similar controls.

9. Review what the attacker could reach

Check purchases, payment methods, stored cards, private messages, cloud files, shared albums, advertising accounts and business tools. Look for new owners, administrators, destinations or sharing links. Save evidence of unauthorised changes before reversing them when a bank, employer or investigation may need details.

Exposed area Immediate contact What to review
Banking or card data Bank or card issuer using a verified number Transfers, cards, payees and account details
Work account Employer’s IT or security team Files, messages, permissions and connected systems
Identity documents Relevant issuer and official identity-theft service New accounts, impersonation and credit activity where applicable
Social account Platform’s official recovery channel Posts, messages, linked pages, admins and ad spend

10. Check the device for harmful software

Update the operating system, browser, apps and trusted security software. Remove unknown apps and browser extensions. Run the device’s built-in or reputable security scan. A factory reset is a major last-resort action: back up essential files first and use the device maker’s current official instructions.

Changing passwords on an infected or remotely controlled device can expose the new passwords. If you are unsure, get help from a qualified local technician or your organisation’s security team.

11. Warn affected people without spreading the scam

Tell contacts to ignore suspicious links, payment requests or files sent from your account. Use another trusted channel if the account is still uncertain. Do not forward a dangerous attachment as evidence. If a workplace account is involved, follow the organisation’s incident-reporting process.

12. Monitor and document

Keep a simple incident record with dates, alerts, unauthorised actions, support case numbers and steps completed. Monitor the account, email, phone number and financial activity for follow-up attempts. Attackers sometimes pose as recovery specialists after the first incident.

If you cannot recover the account

  • Use only the provider’s official recovery process and answer accurately.
  • Try from a familiar device and network if the provider recommends it.
  • Do not pay a stranger who promises guaranteed recovery.
  • Tell contacts the account is unsafe through another channel.
  • Protect other accounts that used the same password or recovery email.
  • Preserve ownership evidence and case references, but never post identity documents publicly.

What not to do

  • Do not click a “secure your account” link in the suspicious alert.
  • Do not argue with the attacker or announce every recovery step.
  • Do not reuse the old password with one character changed.
  • Do not assume a password change removes linked apps or forwarding rules.
  • Do not give a code, password or remote screen access to “support.”
  • Do not delete all evidence before financial or workplace reporting.

Prevent a repeat

  1. Give every account a unique password.
  2. Use a phishing-resistant sign-in method where practical.
  3. Keep recovery details current and backup codes protected.
  4. Remove apps and extensions you no longer need.
  5. Install security updates promptly.
  6. Learn the warning signs of phishing.
  7. Review security activity after changing a phone, computer or employee role.

Frequently asked questions

Is changing the password enough?

Not always. Unknown sessions, recovery methods, forwarding rules and connected apps may remain. Review the full account-security surface.

Should I delete the hacked account?

Secure and review it first if possible. Immediate deletion can remove evidence, access to recovery messages or data you need. Consider the consequences and follow the provider’s documented process.

Should I announce the hack publicly?

Warn people who may receive fraudulent messages, but do not publish recovery details or a live description of every defensive step. Use a separate trusted channel when possible.

What if money or identity data was exposed?

Contact the relevant financial institution or official identity-theft authority promptly. General blog guidance cannot replace institution-specific action.

Sources and review note

Editorial note: This is a general incident checklist. Exact recovery controls differ by provider. Use the responsible service’s current official process, and escalate immediately when financial, workplace or identity data is involved.

Comments

Popular posts from this blog

How to Create Strong Passwords Without Reusing Them

12 Online Safety Habits Every Beginner Should Use