Technology · Cybersecurity

How to Recover a Hacked Account — The Order That Works

Do these in the right order or you will lock yourself out while the attacker stays in. Email first, then sessions, then passwords — plus what to check afterwards that most people miss.

Illustration of a broken padlock being repaired
Advertisement
Advertisement

Part of our guide to How to Spot a Phishing Message Before You Click

The order matters more than the individual steps. Change the password on a social account first and the attacker simply resets it through your email, which they also control. Work outward from the account everything else depends on.

The order

1. Secure your email. 2. Sign out all sessions. 3. Change the password. 4. Turn on two-factor. 5. Undo their changes. 6. Check anything financial. Doing 3 before 1 and 2 is why people find themselves locked out again an hour later.

1. Start with the email account

Almost every account you own resets through email. If the attacker has your inbox, everything else is temporary.

Secure it first: change the password, sign out all sessions, enable two-factor authentication. If you cannot get in, use the provider's official recovery flow before touching anything else.

2. Sign out of every session

This is the step most people skip, and it is the reason a "fixed" account gets taken again.

Changing a password does not always kill sessions that are already logged in. Many services keep them alive. Find the option — usually "sign out of all devices" or "log out everywhere" in security settings — and use it. Do this before or immediately alongside the password change.

3. Change the password to something unique

New, long, and used nowhere else. If it was reused anywhere, every one of those accounts is now at risk too — attackers routinely try leaked credentials across many sites.

This is the moment a password manager pays for itself, because "unique everywhere" is not achievable by memory.

4. Turn on two-factor authentication

If it was off, this is why they got in with a password alone. If it was on, they may have bypassed it via SMS interception or by approving a prompt you did not recognise.

An authenticator app is stronger than SMS. Save the backup codes somewhere safe — see the two-factor authentication guide.

5. Undo what they changed

Attackers usually leave themselves a way back in. Check for:

  • Email forwarding rules — a rule quietly copying your mail to their address. This is extremely common and easy to miss.
  • Recovery email and phone number changed to theirs
  • Connected apps with account access
  • Filters that auto-delete security notifications, so you never see the warnings
  • Delegated access or added account managers
  • Signature changes on business email, sometimes carrying payment details

Go through security settings line by line. The password change is worthless if a forwarding rule is still running.

6. Check anything that touches money

If the account had payment details, a linked card, or access to financial services:

  • Review recent transactions
  • Contact your bank if anything is unfamiliar
  • Watch statements for the next few months, not just the next few days

If identity documents may have been exposed, identitytheft.gov is the official US recovery starting point and produces a personalised plan.

Consider a credit freeze — it is free, does not affect your score, and blocks new accounts being opened in your name. See how to check your credit report.

7. Warn your contacts

Compromised accounts are used to message friends and colleagues with scams that work precisely because the message comes from someone they trust. A short note stops the attack spreading.

If you cannot get back in

Use the service's official recovery process, reached by navigating to the site yourself rather than through a link or a search result.

Be aware of the follow-on scam: searching for "[service] support phone number" surfaces fake numbers run by people who will happily "help" you. Legitimate services rarely offer phone support for free consumer accounts. Use the in-product recovery flow.

Recovery usually asks for evidence you are the owner — old passwords, account creation date, contacts, devices previously used. Answer from memory rather than guessing wildly; repeated failed attempts can slow the process.

How they usually got in

Worth knowing, so the fix holds:

Reused password exposed in someone else's breach. The most common route by a wide margin. Fixed by unique passwords everywhere.

Phishing. You entered credentials into a convincing fake page — see how to spot phishing.

SIM swap. Your number was ported to their SIM, letting them receive SMS codes. This is why app-based two-factor beats SMS.

Malware on a device. If you suspect this, changing passwords from the infected machine achieves nothing — clean the device first.

This is general information, not security or legal advice — see our disclaimer.

Advertisement
Advertisement

Frequently asked questions

What should I do first if my account is hacked?

Secure the email address attached to it before anything else. Almost every other account resets through email, so an attacker holding your inbox can undo every other fix you make.

Why does changing my password not lock the attacker out?

Because existing logged-in sessions often survive a password change. You need to use the "sign out of all devices" option as well, otherwise their session continues working.

How do I know if someone else is using my account?

Most major services list recent logins with device, location and time, plus active sessions. Unfamiliar entries and any forwarding rules or recovery addresses you did not add are the clearest signs.

What if I cannot log in at all?

Use the service's official account recovery flow, which usually asks for identity evidence. Do not search for a support phone number — fake support numbers are a common follow-on scam.

Should I tell my contacts?

Yes, once you are back in control. Compromised accounts are used to message contacts with scams, and a warning stops the attack spreading to people who trust you.

Do I need to change passwords on other sites?

If you reused that password anywhere, yes, and urgently. Credential stuffing — trying a leaked password across many sites — is how a single breach becomes several.

Sources

  1. Federal Trade Commission — Hacked accounts
  2. CISA — Secure our world
  3. FTC — Identity theft recovery
  4. Consumer Financial Protection Bureau — Fraud and scams
Corrections

Found an error? Email us and we will fix it and note the change at the bottom of this article. Hello@daily-atlas.com

Related reading

Illustration of a padlock and a key
Technology

Password Managers — Are They Safe, and How to Start

Putting every password in one place sounds like a bad idea until you compare it with what you are doing now. How the encryption works, what happens if the company is breached, and how to move across without losing a weekend.

13 August 2026 · 4 min read