Guide

What to do if your account is hacked

Finding that you cannot get into your account, or seeing messages you never sent, is alarming. In moments like that, order matters as much as speed: taken in the right sequence, the right steps usually limit the damage.

Short answer

The first four steps are these: change the password immediately, sign out of every device, turn on two-factor authentication, and start the platform's recovery or reporting process. After that, check your recovery details, connected apps and any other accounts using the same password.

The signs: what to look for

The typical signs of an account takeover are these: your password suddenly not working, sign-in notices from devices or locations you do not recognise, messages and posts you did not make, altered profile or recovery details, and emails in your inbox marked as read that you never opened.

Some takeovers are silent: to avoid being noticed, the attacker changes nothing and merely watches. That is why glancing at the “recent sessions” list on your accounts' security page from time to time is a good habit.

The most valuable of these signs are the security emails the services send themselves: “a new device has signed in”, “your password was changed”, “your recovery number was updated”. Do not delete these unread; if you did not do it, each one is an alarm bell, and the “if this wasn't you” link inside the message is often the quickest way to intervene.

Steps 1–2: password and sessions

If you can still get into the account, changing the password comes first: choose one that is long, unique and never used anywhere before — the strong password guide covers the method. If you cannot get in, start the platform's “forgotten password” or account recovery process at once.

Once the password is changed, use the “sign out of all devices” option in the security settings. This step is critical: even after a password change, the attacker's open session can stay active, and ending sessions is what actually throws them out.

Steps 3–4: verification and reporting

The third step is to enable two-factor authentication; if it is already on, check that the verification method — phone number, app — still belongs to you, because attackers may have added devices of their own. Generate new backup codes and invalidate the old ones.

The fourth step is to tell the platform: most large services have a dedicated process for “my account has been hacked”. Reporting both opens extra recovery options for you and creates a record in case your account is used for fraud. If the account relates to banking, do not hesitate to telephone the bank.

Reporting processes differ from platform to platform, but the logic is shared: the help or security pages carry a specific route for compromised accounts, and you are asked to verify your identity. Making that report on the day you notice matters; time works in your favour both for the chance of recovery and for separating responsibility for anything done through your account.

The clean-up: recovery details and connected apps

Attackers leave doors behind so they can return. Check each of these: the recovery email address and phone number (delete any entry you do not recognise), forwarding and filter rules created in your email (they may be passing incoming messages to the attacker), and third-party apps and API access connected to the account (remove anything unfamiliar).

If it is an email account that was taken over, the job is bigger: that account is the recovery key to all the others. Once your email is secure, renew the passwords of the important accounts attached to it as well.

Afterwards: other accounts and the people around you

If you used the same password on other accounts, change them all; trying a captured password automatically on other services is standard practice for attackers. Taking the opportunity to move to a password manager prevents a repeat at the root.

Finally, tell the people around you: the attacker may have sent your friends messages asking for money or containing links. A short note — “my account was hacked, please ignore those messages” — protects the next links in the chain. Watch your account activity and sign-in notices closely for a few days.

Do not neglect the financial side either: if a card is saved on the compromised account, or purchases can be made through it, check your card activity and start a dispute with your bank if you see anything suspicious. Looking at the order and invoice history on subscription services, to see whether the attacker bought anything with your payment method, is part of the same check.

Checklist

  • Change the password immediately (or start recovery if you cannot sign in)
  • Sign out of every device
  • Turn on two-factor authentication and check the methods
  • Review the recovery email, phone number and email rules
  • Clear out connected third-party apps
  • Update other accounts using the same password
  • Report it to the platform and warn the people around you

Frequently asked questions

I cannot get into my account at all; is it over?

No. The large platforms have identity-based account recovery processes: with evidence such as a registered email address, phone number, previous passwords and identity verification, accounts can usually be recovered. The earlier you start, the better the odds.

Which account should I secure first?

Email. Password reset links for other accounts go to your email, so if that is not secure the other changes will not hold. The order is: email, banking, social media, then the rest.

How might the attacker have got in?

The most common routes are a shared password exposed in a breach elsewhere, details entered on a phishing page, and malware on the device. Even if you never learn the exact cause, guarding against all three (unique passwords, two-factor authentication, an up-to-date device) largely prevents a repeat.

Should I report it to the police or the authorities?

If there is financial loss, blackmail or misuse of your identity, yes; you can apply to the prosecutor's office or to law enforcement. Keep evidence such as screenshots and transaction records rather than deleting it.

This guide draws on the official account recovery processes of major online platforms and on the incident response advice of cyber security bodies.

First published: 2026-08-12Last reviewed: 2026-08-12Editorial status: working editionReport an error