Account hacked: the first 30 minutes

Someone else is in your account – or you have been locked out. The order of your next steps decides whether you get it back cleanly or keep losing ground.

Do this now, in this order
  1. Secure your email account first – it is the key to everything else.
  2. Change the password from a device you trust.
  3. End all active sessions – a password change alone does not log the attacker out.
  4. Turn on two-factor authentication.
  5. Check for mail forwarding and filter rules you did not create.

An account takeover feels like losing control, and the instinct is to change the password and hope. That is exactly the step that gets undone: as long as the attacker’s session is open or a forwarding rule is running, they simply take the account back.

Why the order matters

A password is not a door lock, it is an entry ticket. Once someone is inside, they hold a session that stays valid independently of the password. Most services keep that session alive even after the password changes.

So the sequence is: end sessions → change password → enable 2FA. Any other order leaves a window open.

Step by step

Reclaiming the account

  • 1. Use a clean device. If you suspect malware on your computer, do this from another one.
  • 2. Email account first, then banking, then everything else.
  • 3. Change the password to something long and unique, stored in a password manager.
  • 4. End all sessions – look for “devices”, “where you’re logged in” or “sign out everywhere”.
  • 5. Enable two-factor authentication, ideally with an app rather than SMS.
  • 6. Review connected apps and revoke anything you do not recognize.
  • 7. Save recovery codes somewhere safe and offline.
The trick almost everyone misses Attackers who reach an inbox routinely set up a silent forwarding rule or a filter that auto-archives messages from your bank. That way they keep reading even after you change the password. Check forwarding, filters, recovery address and recovery phone number before you consider the account clean.

Then: everywhere the password was reused

This is the part people skip, and it is the reason incidents repeat. If the compromised password was used anywhere else, those accounts are already exposed – attackers automate exactly this.

  • Change it everywhere it was used, starting with anything holding money or personal data.
  • Move to unique passwords per service with a password manager .
  • Check whether your address appears in a known breach, and expect more targeted phishing for a few weeks afterwards.

If you cannot get back in

Use the provider’s official account recovery process – never a “recovery service” that contacts you offering help for a fee. Those are a second scam aimed at people who have just been hit by the first.

Be ready to prove ownership: previous passwords, approximate creation date, frequent contacts, devices and locations you normally use. Doing this from a device and network you have used with the account before genuinely improves your chances.

The test that matters

The account is only secure once all three are true: no session you do not recognize, no forwarding or filter rule you did not create, and a second factor switched on. A new password on its own proves nothing.

Preventing the next one

Frequently asked questions

I changed my password. Isn't that enough?

No. An existing session usually stays logged in even after a password change. You have to end all sessions as well – only then is the attacker actually out.

Which account should I secure first?

Your email account, always. It is the master key: whoever controls it can trigger a password reset almost everywhere else. Secure it before banking, shopping or social media.

The attacker changed my recovery email. What now?

Use the provider’s account recovery flow, which usually asks for details only the real owner knows – old passwords, contacts, creation date, devices used. Do this from a device you have used with that account before; it improves your chances.

Topics: Emergency, Accounts