Start on another trusted phone or computer. If infection is possible, disconnect the suspect device from the network and do not enter new passwords on it. This list does not replace instructions from your bank, employer, or authorities.
Stop the access
- I record the current time and the first symptom I noticed
- I open the service from my own bookmark or a manually entered official domain, not a link in a message
- I choose “sign out all devices” or end sessions I do not recognise
- I change the password to a new, unique one; if the old password was reused, I immediately change it on those accounts too, starting with email and accounts that can recover other services
- I review and remove unknown passkeys, security keys, MFA apps, and devices
- I generate new recovery codes and invalidate the old ones where the service permits it
Rebuild recovery
- I check the backup email, phone number, recovery questions, and trusted contacts
- In email, I inspect forwarding rules, filters, delegated access, and apps connected to the account
- I secure the primary email before accounts that can be recovered through it
- If I cannot sign in, I use the provider’s official recovery process and keep the case number
Limit the effects
- I call the bank on an official number if the account, card, payment code, or payment details may have been exposed
- I review transfers, new payees, cards in digital wallets, and bank alerts
- I warn contacts if messages were sent from the account and ask them not to open links or send money
- I report the takeover to the social platform and inspect active adverts and payment methods
- For a work account, I contact IT or security before deleting possible evidence myself
Record a timeline
- I record the times of alerts, password changes, session revocation, bank calls, and case numbers
- I keep screenshots of alerts and device lists without publishing codes, identity documents, or full card details
- I note which device opened the suspect file or page
- After containing the problem, I review the accounts again the next day
If a live session leaked, a new password alone may not end access — Session theft explains why. After entering a code or password on a fake page, also use The first minutes after a code or a password. For an event involving a business, several accounts, or data loss, move to the fuller incident response checklist, identify who owns the decisions, and consider incident response support.