Account hacked: the first 30 minutes
Someone else is in your account – or you have been locked out. The order of your next steps decides whether you get it back cleanly or keep losing ground.
- Secure your email account first – it is the key to everything else.
- Change the password from a device you trust.
- End all active sessions – a password change alone does not log the attacker out.
- Turn on two-factor authentication.
- Check for mail forwarding and filter rules you did not create.
An account takeover feels like losing control, and the instinct is to change the password and hope. That is exactly the step that gets undone: as long as the attacker’s session is open or a forwarding rule is running, they simply take the account back.
Why the order matters
A password is not a door lock, it is an entry ticket. Once someone is inside, they hold a session that stays valid independently of the password. Most services keep that session alive even after the password changes.
So the sequence is: end sessions → change password → enable 2FA. Any other order leaves a window open.
Step by step
Reclaiming the account
- 1. Use a clean device. If you suspect malware on your computer, do this from another one.
- 2. Email account first, then banking, then everything else.
- 3. Change the password to something long and unique, stored in a password manager.
- 4. End all sessions – look for “devices”, “where you’re logged in” or “sign out everywhere”.
- 5. Enable two-factor authentication, ideally with an app rather than SMS.
- 6. Review connected apps and revoke anything you do not recognize.
- 7. Save recovery codes somewhere safe and offline.
Then: everywhere the password was reused
This is the part people skip, and it is the reason incidents repeat. If the compromised password was used anywhere else, those accounts are already exposed – attackers automate exactly this.
- Change it everywhere it was used, starting with anything holding money or personal data.
- Move to unique passwords per service with a password manager .
- Check whether your address appears in a known breach, and expect more targeted phishing for a few weeks afterwards.
If you cannot get back in
Use the provider’s official account recovery process – never a “recovery service” that contacts you offering help for a fee. Those are a second scam aimed at people who have just been hit by the first.
Be ready to prove ownership: previous passwords, approximate creation date, frequent contacts, devices and locations you normally use. Doing this from a device and network you have used with the account before genuinely improves your chances.
The test that matters
The account is only secure once all three are true: no session you do not recognize, no forwarding or filter rule you did not create, and a second factor switched on. A new password on its own proves nothing.Preventing the next one
- A password manager, so one breach cannot cascade: Password managers explained .
- Two-factor authentication on email, banking and anything with money attached: How to set it up .
- Regular checks of who is logged in: Check active sessions .
- Recognizing the message that started it: How to spot phishing .
Frequently asked questions
I changed my password. Isn't that enough?
No. An existing session usually stays logged in even after a password change. You have to end all sessions as well – only then is the attacker actually out.
Which account should I secure first?
Your email account, always. It is the master key: whoever controls it can trigger a password reset almost everywhere else. Secure it before banking, shopping or social media.
The attacker changed my recovery email. What now?
Use the provider’s account recovery flow, which usually asks for details only the real owner knows – old passwords, contacts, creation date, devices used. Do this from a device you have used with that account before; it improves your chances.