All resources

Guide · For individuals

Your account's been hacked. Do this first — in the next hour.

No panic, just order of operations. Most account takeovers are recoverable if you move fast and move in the right sequence — and most of the damage people cause happens after the hack, by rushing the wrong steps first. This is the calm version: what to check, what to lock down first and why, and exactly how to get back into Google, Microsoft, Apple, or a bank account when you're shut out.

~9 min read Updated July 2026 Do this in the first hour

Hi 👋 First: take a breath. Getting locked out of your own account, or watching it do things you didn't do, is one of the more unsettling things that can happen online — but it is also one of the most fixable. The accounts that get permanently lost are almost always the ones where someone either freezes for a day deciding what to do, or moves fast in the wrong order. Here's the right order.

Is this actually a hack? The 60-second check

Before you do anything, make sure you're solving the right problem. A few genuine signs of compromise:

  • You're locked out — your password no longer works and you didn't change it.
  • You get a sign-in alert for a device, browser, or location you don't recognize, and it wasn't you (new phone, new city, a browser you don't use).
  • Settings changed that you didn't touch — a new recovery email or phone number, a new forwarding address on your inbox, new apps with access to your account.
  • People you know tell you they got a strange message, DM, or email “from you” that you never sent.
  • Activity you didn't do — sent messages, posts, purchases, or deleted items you don't recognize.

And two common false alarms worth naming, so you don't burn an hour on nothing:

  • A “we hacked you, pay up” email that quotes an old password of yours as “proof.” That password almost always comes from an old, unrelated data breach — not from anyone actually being inside your account today. It's a scam email, not a hack. (You should still change that password if you're still using it anywhere — see the traps section below.)
  • A single “new sign-in” notification right after you used a new browser, cleared cookies, or traveled. That's usually just the platform doing its job. If you can still sign in normally and nothing else looks wrong, it's probably you.

If you're genuinely locked out, or you can see activity you didn't do — keep going.

Part 1 — The first hour, whatever platform you're on

This order matters. Each step protects the one after it.

Step

Move to a device you trust

If the device you're on might be infected — that's often how accounts get taken over in the first place — do the rest of this from your phone or another computer instead, and run your device's built-in security scan (Windows Security or macOS's built-in protections both do a real job today) on the suspect device before you use it again.

Step

Lock down the recovery email and phone first — before the password

This is the step people skip, and it's the one that matters most. If an attacker added their own recovery email or phone number to your account, changing your password alone doesn't remove them — they can just reset it right back the moment you leave. Before anything else, check the recovery contact info on the account and remove anything you don't recognize. If the account in question is your main email, this step is doubly important: your inbox is the reset path for almost everything else you own.

Step

Change the password — and don't reuse one you already have

Generate a brand-new, unique password (a password manager will do this for you — see the full setup in the passwords & 2FA guide if you don't have one yet). The single most common mistake here: reusing an old password “just to get back in quickly.” If that password was compromised once, reusing it anywhere just hands the attacker a second way in.

Step

Turn on two-factor authentication if it isn't already on

A password reset alone doesn't stop someone who's already inside — 2FA does, because it demands something only you have. If you saved backup recovery codes when you first set this up, now's exactly when they earn their keep.

Step

Sign out of every other session

Almost every major platform has a “sign out everywhere” or “manage devices” option in its security settings. Use it — it's the single fastest way to kick out anyone who's still logged in, even after you've changed the password.

Step

Hunt for the quiet backdoors

This is the step that separates “recovered” from “actually secure.” Check:

  • Forwarding rules or filters on the inbox (a classic move — an attacker forwards a silent copy of everything to themselves, so they keep reading your mail long after you've “recovered” the account).
  • Connected apps and third-party sign-ins you don't recognize — remove anything unfamiliar.
  • Trusted devices listed on the account that aren't yours.
Step

If people talk to you through that account, tell them it was compromised

A quick heads-up — “hey, my account was hacked, ignore anything weird from me in the last day” — stops a scam message sent in your name from working on someone who trusts you.

Part 2 — Recovering the accounts that matter most

The steps above apply everywhere. These three (plus a note on banking) are worth knowing by name, because they're the accounts most people actually get locked out of, and each has its own recovery flow.

Google

If you can still sign in, start at Google's own Security Checkup (myaccount.google.com/security-checkup) — it walks you through recent security activity, devices, and app access in one place. If you're locked out, Google's account recovery page is at accounts.google.com/signin/recovery (the shortcut g.co/recover takes you to the same place). It'll ask questions only you'd know — old passwords, approximate account creation date, recovery email or phone. Try it sooner rather than later: the more of your normal account history is still fresh, the easier it is for Google to confirm it's really you.

Microsoft / Outlook

If you still have access, go to account.microsoft.com and open Security — change your password there and review recent sign-in activity, connected accounts, and mail forwarding rules while you're in. If you're locked out entirely, Microsoft's dedicated account-recovery form walks you through identity verification (previous passwords you remember, folder names, typical contacts) — give it as much detail as you honestly can, since vague answers are the most common reason recovery requests get rejected.

Apple ID (Apple Account)

Start at iforgot.apple.com to reset your password. If the password's already been changed by whoever got in and that doesn't work, Apple moves you into its account-recovery process automatically. Apple builds in a waiting period there on purpose — it's a safeguard so an attacker can't use the same “recovery” path to lock you out for good, not a sign that anything's gone wrong. Once you're back in, go to account.apple.com and check Devices for anything you don't recognize, and confirm every phone number and email address listed on the account is actually one you control.

Banking and financial accounts

Don't Google a support number and don't call one from a text or email about “suspicious activity” — that's one of the most common scams going, and the numbers in those messages route straight to the attacker. Call the number printed on the back of your physical card, or the one on a genuine paper statement. Every bank handles “I think my account was compromised” calls constantly; ask them to freeze the card or account and walk through recent transactions with you. If it goes beyond one account — new accounts opened in your name, unfamiliar credit inquiries — that's identity theft, and the FTC's own recovery tool at identitytheft.gov (US) will give you a free, personalized recovery plan.

Mistakes people make under panic

  • Reusing the compromised password somewhere else “just for now.” The moment a password's been exposed, it's done — everywhere, permanently. There's no “temporarily” safe reuse.
  • Fixing the password but leaving the backdoor open. A new password means nothing if a forwarding rule or a stranger's recovery email is still attached to the account. Do step 6 above; don't skip it because the password change felt like the finish line.
  • Trusting whoever calls or emails offering to “help recover” your account. A fake recovery flow is itself a phishing move — codes and passwords only ever go into a page or app you opened yourself. (Full breakdown of these tells in how to spot a phishing email.)
  • Waiting to see if it blows over. Every hour an attacker keeps access is an hour they can do more — reset other accounts, message your contacts, drain a linked payment method. Speed is the whole advantage you have.
  • Only fixing the one account. If you reused that password anywhere else, it's compromised there too, silently, until you change it. This is exactly what the free Security Starter Kit and the passwords & 2FA guide are for — closing that door for good, not just this once.

The first-hour checklist

  • Moved to a device I trust, and scanned it if unsure
  • Recovery email/phone checked — anything unfamiliar removed
  • Password changed to something brand-new, never reused
  • 2FA turned on (or confirmed already on)
  • Signed out of every other session/device
  • Forwarding rules, filters, and connected apps reviewed for anything I didn't add
  • Contacts given a heads-up, if the account talks to other people
  • Bank called using the number on my card — not one from a message
  • Old compromised password fully retired, everywhere it was reused
The one-line version

Recovery contact info first, then the password, then 2FA, then sign out everywhere, then hunt for anything the attacker quietly left behind. In that order, most accounts come back clean within the hour.

Quick answers

Do I need to file a police report?

For a single hacked account with no money lost, usually not — the platform's own recovery flow is what actually gets you back in. If money or identity theft is involved (new accounts opened in your name, funds taken), file at identitytheft.gov (US); it produces documentation you can hand to banks and credit bureaus.

What if the platform's recovery process says it can't verify me?

Answer with everything genuinely true, even approximate details (roughly when you created the account, other addresses you've used, anyone you email often) — vague or rushed answers are the most common reason recovery gets denied. If the first attempt fails, most platforms let you try again with more detail rather than giving one shot.

Should I warn people even if I'm not sure anything was sent from my account?

If in doubt, a short heads-up costs you nothing and protects everyone who trusts messages from you. It's the same instinct as the family “safe word” idea in the phishing guide — a quick verification step that a scammer impersonating you can't fake.

Keep going

Fire's out. Now fireproof the house.

Recovering one account fixes today's problem. The free Security Starter Kit and the full passwords & 2FA setup fix the next one — a password manager, two-factor authentication, and the ten moves that make this guide something you never need again. One evening, done right.

Unsubscribe anytime. Explore more guides and resources.

Scroll to Top