Home Self-reliance Digital Life When accounts are compromised

Digital Life · Respond

An account was taken over. Here is what to do first.

This is a recoverable situation. The order you act in matters more than the speed. Start with email.

Take a breath

What this situation is and is not.

An account takeover means someone else has gained access to one of your online accounts, usually by obtaining your password through a data breach, a phishing email, or a reused password that was exposed somewhere else. It does not mean your computer is destroyed, your identity is stolen, or that every account you own is compromised.

Most account takeovers are opportunistic, not targeted. Attackers use automated tools to try leaked passwords across many services at once. If you reuse a password, a breach at one service can unlock others. That is why the recovery sequence below starts with email: it is the account that resets everything else.1

This is not a reason to panic. It is a reason to act methodically in the next hour. The steps below are in the right order. Follow them one at a time.

The first hour

Secure your accounts in this order.

The order matters. Email controls password resets for every other account. Financial accounts hold your money. Everything else comes third.

1

Secure your email account first

Your email is the master key. Password reset links for your bank, your social media, and your shopping accounts all flow through it. If an attacker controls your email, they can reset passwords on everything else.1

Change the password. Use a long, unique password you have never used anywhere else. If you have a password manager, let it generate one.

Turn on two-step verification. This means anyone logging in needs both your password and a code from your phone. In Gmail: Google Account > Security > 2-Step Verification. In Outlook: Account > Security > Advanced security options.2

Check for forwarding rules. Attackers often add a rule that silently forwards a copy of every incoming email to their own address. In Gmail: Settings > See all settings > Forwarding and POP/IMAP. In Outlook: Settings > Mail > Forwarding. Delete any forwarding address you do not recognize.

Sign out all other sessions. Most email providers have a "Sign out of all other sessions" or "Manage devices" option in their security settings. This forces the attacker out immediately.

2

Move to financial accounts

Change passwords on your banking, credit card, and retirement accounts next. Use a unique password for each one. Turn on two-step verification where it is offered.

Check recent transactions for anything you do not recognize. If you see unauthorized charges, call the number on the back of your card or on the bank's website. Do not call a number from an email or text, even if it looks official.

3

Recover the compromised account itself

If you can still log in, change the password and enable two-step verification. Then check for damage:

Recovery email and phone number: have they been changed?

Connected third-party apps: are there apps you did not authorize?

Recent activity: were messages sent from your account?

Purchase history: were orders placed you did not make?

Revoke access for anything you did not authorize and restore your original recovery information.

4

Lock what the attacker might use next

If the compromised account contained personal information (your address, date of birth, Social Security number), the attacker may try to open new accounts in your name. A credit freeze blocks this. Freeze at all three bureaus: Equifax, Experian, and TransUnion. It is free and does not affect your credit score.3

Review login activity on your other major accounts. Most services show recent sign-ins under security settings. If you see a location or device you do not recognize, change that password too.

5

Report and document

Report the takeover to the platform using their official account recovery process. Then file a report at reportfraud.ftc.gov. If money was taken, also report to the FBI at ic3.gov.4

Save screenshots of unauthorized activity, changed settings, and any messages the attacker sent from your account. These may be needed for disputes with your bank or the platform.

If you cannot log in

When the attacker changed the password.

If the attacker has already changed your password and you cannot log in, do not create a new account. Use the platform's official account recovery process instead. Every major service has one.

Email accounts

Gmail: go to accounts.google.com/signin/recovery. Microsoft/Outlook: go to account.live.com/password/reset. Yahoo: go to login.yahoo.com and select "Forgot password." Each will walk you through verifying your identity using your phone number, a backup email, or security questions you set up previously.

Bank and financial accounts

Call the number on the back of your card or on your paper statement. Do not call a number from an email or search result. Your bank can lock the account, reverse unauthorized transactions, and issue new credentials. This is what their fraud department exists for.

Social media accounts

Most platforms (Facebook, Instagram, X) have a "hacked account" flow accessible from the login page. Search "[platform name] hacked account" to find the official recovery page. You may need to verify your identity with a photo ID.

If recovery codes were saved in your household account inventory, now is when they matter. Recovery codes bypass two-step verification when you have lost access to your phone or authenticator app.

Stop the spread

Every account that shared that password.

If the compromised account used a password you have used anywhere else, every account sharing that password is now at risk. This is the most common way a single breach turns into a cascade.1

Change those passwords now, starting with the ones that matter most: email, then financial, then anything connected to your real name or payment information. Use a unique password for each one going forward. A password manager makes this sustainable.

If you do not remember which accounts used that password, check your password manager's breach report. Most major password managers include a feature that flags passwords known to appear in data breaches. If you do not yet use a password manager, this is the moment to start. See Locking Down the Accounts That Matter Most for a plain-language walkthrough.

When it goes further

When this becomes identity theft or financial fraud.

This page covers the first hour: securing your accounts and stopping the immediate damage. If the attacker used your information to open new accounts, file fraudulent tax returns, access medical services, or steal money you cannot recover through your bank, the situation has moved from account takeover into identity theft.

That process has its own steps, its own timeline, and its own reporting requirements. The guide below covers all of it.

If you are unsure whether your situation is an account takeover or identity theft, start with the steps on this page. If you discover unauthorized accounts, credit inquiries, or financial losses beyond the original compromised account, move to the guide above.

Once things are stable

What to do this week.

Once the immediate threat is contained, spend an hour this week on the steps that prevent this from happening again.

Set up a password manager if you have not already.

Let it generate and store a unique password for every account. The time investment is one afternoon. The protection is permanent. Password managers cost $0 to $5 per month.

Turn on two-step verification on every account that offers it.

Start with email and financial accounts. An authenticator app is more secure than text-message codes, but either is far better than a password alone.2

Save your recovery codes.

When you enable two-step verification, most services give you a set of backup codes. Print them or save them in your household account inventory. They are your lockout insurance.

Check your credit reports.

Request your free annual credit reports from annualcreditreport.com. Look for accounts or inquiries you do not recognize. If you find any, the identity-theft response guide has the next steps.

Sources

  1. CISA. "Securing Your Accounts and Devices." cisa.gov
  2. CISA. "Implementing Phishing-Resistant MFA." cisa.gov
  3. FTC. "Credit Freezes and Fraud Alerts." consumer.ftc.gov
  4. FTC. "Report Fraud." reportfraud.ftc.gov
  5. FBI Internet Crime Complaint Center. ic3.gov
  6. NIST. "Digital Identity Guidelines: SP 800-63." nist.gov

This page was last reviewed in July 2026. Digital guidance changes faster than most preparedness topics. If that date is more than a year old, confirm key steps against the sources above before acting on them.

Enough for now

You are prepared enough when...

  • Your email account has a new unique password and two-step verification is on.
  • You have checked for and removed any email forwarding rules you did not create.
  • Every account that shared the compromised password has a new, unique password.
  • Your credit is frozen at all three bureaus.
  • You have reported the incident to the platform and to the FTC.

Review your credit reports within the next 30 days, then again at 90 days.

This guide is part of When Something Looks Off — all the guides for this concern in one place.