Check active sessions: who is logged into your accounts?
Every major service keeps a list of signed-in devices and connected apps. Five minutes in that list tells you whether someone else is reading along – and ends their access with one click.
Whoever had your password once often stays signed in – even after you have long since changed it. That makes the device list one of the most useful checks you can run. It is free, takes five minutes per account, and ends unwanted access immediately.
Where to find the list
| Service | Path |
|---|---|
| Account → Security → Your devices and Third-party apps with account access | |
| Apple | Settings → your name → device list at the bottom |
| Microsoft | Account → Security → Sign-in activity; devices under “Devices” |
| Facebook / Instagram | Settings → Accounts Center → Password and security → Where you’re logged in |
| App → Settings → Linked devices | |
| Amazon | Account → Login & security → Devices |
Start with your email account. It is the master key: whoever controls it can trigger “forgot password” on nearly every other service you use.
The check, in five steps
Per account
- 1. Open the device list and look at each entry: device type, location, last access.
- 2. Sign out anything unfamiliar. When in doubt, sign it out – you can always log back in.
- 3. Review connected apps and revoke anything you no longer use or do not recognize.
- 4. Change the password – afterwards, not before, or the attacker reads the new one through the old session.
- 5. Enable two-factor authentication if it is not already on.
Connected apps: the forgotten door
Every “Continue with Google” or “Sign in with Facebook” creates a lasting connection. Some of those services are allowed to read your contacts, post on your behalf, or access your inbox – years after you last opened them.
Go through the list and revoke anything you do not actively use. Pay particular attention to apps with access to email, contacts, files or calendar. You can always grant access again later if you genuinely need the service.
Also check on your email account
Anyone who gets into a mailbox almost always sets up a quiet redirect so they can keep reading after a password change:
- Forwarding rules: is a copy being sent to an unfamiliar address?
- Filters: are messages from your bank being auto-archived or deleted?
- Recovery address and phone number: are those still yours?
- App passwords: delete old entries you cannot account for.
The test that counts
A changed password is meaningless while a foreign session is open or a forwarding rule is running. End sessions, check forwarding, then enable 2FA – only those three together actually lock someone out.If you find someone
Then it is an incident, not a check. Work through account hacked , and afterwards move to unique passwords with a password manager so one leak cannot cascade again.
How often?
Twice a year for your important accounts – and immediately after a login warning you did not trigger, a breach at a service you use, an accidental click on a phishing link , or selling or passing on a device.
Frequently asked questions
What happens if I sign out of all sessions?
You will have to log in again on your own devices. That is all – and that is exactly the point: anyone else who was still signed in gets thrown out too.
Isn't changing my password enough?
No. On most services an existing session stays valid after a password change. You need to end all sessions as well, otherwise an attacker simply keeps their access.
I see an unfamiliar location. Have I been hacked?
Not necessarily. Locations are derived from IP addresses and are often inaccurate, especially on mobile networks or through a VPN. Be suspicious of an unfamiliar device type, a different country, or a time when you were definitely offline.