
Key Takeaways
Recognizing the Warning Signs
Not every hack announces itself. Common signals include: login alerts from unfamiliar locations, password-reset emails you didn't request, contacts telling you they received strange messages from your account, unfamiliar charges on a linked payment method, or simply being locked out of an account for no apparent reason.
If any of these sound familiar, treat it as a breach until you can confirm otherwise. Acting on a false alarm costs you a few minutes; ignoring a real one can cost far more.
Don't Delay — Act Within Minutes
Every minute an attacker has access to your account, they can lock you out, harvest data, or impersonate you. If you suspect a breach, stop what you're doing and work through these steps immediately. Waiting to "see what happens" dramatically increases the potential damage.
What You'll Need Before You Start
Gather these resources before working through the steps. Having them ready prevents scrambling mid-process, which is when mistakes happen.
What you will need
Two-Factor Authentication (2FA) App
Generates time-sensitive login codes that prevent unauthorized access even when a password is stolen.
Password Manager
Creates and stores unique, complex passwords for every account so you never reuse credentials.
Reputable Antivirus/Anti-Malware Software
Scans your device for malicious programs that may have enabled the breach.
Secondary Device
Allows you to change passwords and contact support safely if your primary device is compromised.
Step-by-Step: Responding to a Suspected Breach
Work through these steps in order. Each one builds on the last, and skipping ahead can leave gaps an attacker can still exploit.
Disconnect the device from the internet
If you suspect your device — not just an account — has been compromised, disconnect it from Wi-Fi or unplug its ethernet cable immediately. This cuts off any active remote access and prevents malware from sending your data elsewhere. Use a separate, trusted device for the remaining steps.
Change your password on the affected account
Using a trusted device, log into the compromised service and change your password immediately. Choose something long, random, and unique to that account — not a variation of anything you've used before. If the attacker has already changed your password, use the service's official "Forgot password" link to trigger a reset via your email or phone.
Enable two-factor authentication (2FA)
Once you've regained access, turn on two-factor authentication if it isn't already active. This requires a second verification step — usually a code from an authenticator app or a text message — before anyone can log in. Even if an attacker obtains your password again, 2FA stops them at the door.
Review active sessions and connected apps
Most major platforms let you see all active login sessions under their security settings. Look for logins from unfamiliar locations or devices and sign them out. Also review any third-party apps that are connected to the account — revoke access for anything you don't recognize or no longer use.
Change passwords on linked accounts
If the compromised account shares a password with others — or if attackers could use it to access your email, which unlocks almost everything else — update those passwords too. Prioritize your primary email, banking, and any accounts that contain payment information. This is especially important if you used the same password in multiple places.
Contact your bank if financial accounts are involved
If you see unfamiliar transactions or your banking credentials may have been exposed, call your bank or card issuer's official customer service number immediately. Request a freeze or replacement card if needed. Most institutions have zero-liability policies for unauthorized charges, but you typically need to report them promptly.
Run a malware scan on your device
Reconnect your device to the internet, then run a full scan using reputable anti-malware software. Some breaches originate from malicious software quietly installed on your machine. A scan can identify and remove programs that may have captured your keystrokes or credentials. If the scan finds something it cannot fully remove, consider seeking help from a qualified technician.
Phishing Emails Exploit This Exact Moment
After a real breach, scammers often send fake "account recovery" emails designed to look official. Before clicking any link, go directly to the service's website by typing the address into your browser — never click a link in an unexpected email, even if it looks legitimate.
After the Immediate Crisis: Closing the Gap
Once your accounts are secured, spend time understanding how the breach likely happened. Common entry points include reused passwords, weak security questions, clicking a phishing link, or malware from a downloaded file. Identifying the cause helps you prevent a repeat.
Review all your accounts for unusual activity over the past several weeks — attackers sometimes sit quietly on access before acting. Update security questions on any account that still uses them; the answers are often guessable from public social media profiles.
Use a Password Manager Going Forward
A password manager generates and stores strong, unique passwords for every account, eliminating the habit of reusing credentials. This single change closes one of the most common paths attackers use to move from one compromised account into others. See our guide to good password hygiene for practical advice on getting started.
For a broader set of habits that keep your accounts resilient over time, see our guide on keeping your apps and accounts secure. Building these routines now means a future breach attempt is far less likely to succeed.
