Signs of account compromise include a password or recovery change you did not make, unfamiliar sessions, messages or purchases you did not create, and contacts receiving scams from your profile. Verify alerts inside the provider’s official app or website, then recover the account, revoke other access, and secure the email and phone number used for recovery.

Common signs of account compromise

  • You cannot sign in with the password you know.
  • The provider reports a new device, location, passkey, or recovery method.
  • Messages, posts, files, ads, or purchases appear without your action.
  • Contacts receive links or money requests from your account.
  • Email forwarding rules or filters were added.
  • Connected apps, authorized devices, or API tokens are unfamiliar.
  • Security notifications were deleted or marked as read.
  • The account’s display name, profile, phone number, or email changed.

One unfamiliar location does not prove a hack. Mobile networks, VPNs, and IP geolocation can show a nearby or previous city. Review the device, time, browser, and action together.

Verify a security alert safely

Do not click the alert’s link. Open the provider’s app or type its known address and review the security-event page. A phishing message can imitate a real login warning to steal the password it claims to protect.

If the event appears only in the message and not in the account, report the message as phishing. If the event is present, use the provider’s controls to mark it as unauthorized and start recovery.

If you can still sign in

Change the password to a unique one, then sign out of other devices and sessions. Remove unfamiliar recovery addresses, phone numbers, passkeys, security keys, app passwords, and connected applications. Turn on two-factor authentication and save recovery codes securely.

Check what the intruder did. Review messages, forwarding rules, payment methods, transactions, files, advertising accounts, and privacy settings. Warn contacts if the account sent scams or malicious links.

Preserve evidence before deleting fraudulent content. Save security-alert emails, session details, transaction identifiers, changed settings, and messages sent by the intruder. Avoid storing the only copy inside the compromised account. A provider, employer, bank, or law-enforcement report may require dates and account identifiers.

Check scheduled actions as well as completed ones. An attacker may create email rules, future posts, ad campaigns, automatic payments, or delegated access that remains after the visible session ends.

If you are locked out

Use the provider’s official account-recovery page from a device and location you used before when possible. Supply accurate information and avoid repeated guesses that can delay recovery. Do not pay a stranger who promises access or asks for a one-time code.

Secure the recovery email and mobile-carrier account. If an attacker changed the email address, the provider may have sent a message with a limited-time option to reverse the change.

Protect linked accounts

Change every account that reused the compromised password. Start with email, password managers, banking, payment apps, mobile carriers, cloud storage, and social accounts.

Review “Sign in with Google,” “Sign in with Apple,” Meta Accounts Center, or other identity connections. An attacker may reach linked services through an active session even after one password changes.

Prioritize the account that can recover the others. Secure email and the mobile-carrier account before social or shopping profiles when they control password resets. A compromised password manager requires review of the credentials stored inside it, while a hacked marketplace account calls for checking orders, addresses, and payment methods.

Do not change dozens of passwords from a device that may still contain remote-access software or a malicious browser extension. Use another trusted device until the original one has been reviewed.

Look for malware and stolen sessions

If the account becomes compromised again after recovery, scan the devices and browsers used to sign in. Remove suspicious apps, extensions, profiles, and remote-access tools. Update the operating system and browser.

Changing a password may not invalidate every session automatically. Use the provider’s session-revocation control.

Report financial or identity misuse

Contact the financial institution immediately for unauthorized purchases or transfers. Preserve transaction identifiers and account alerts. Use IdentityTheft.gov when personal information was used to open accounts or impersonate you.

Report the compromised profile and fraudulent messages through the platform. Work accounts should also be reported to the organization’s security or IT team.

How dfndr security can help

Breach Report can alert users when credentials associated with registered email addresses appear in known breach data. Link and antivirus features may identify selected phishing destinations or malicious software. They cannot recover an account or prove that every unfamiliar session belongs to an attacker.

PSafe’s analysis of account takeover

Recovering the account takes more than changing its password. Revoke active sessions and any other access the intruder could use to return, then address fraudulent messages, purchases, or account changes. Review recovery settings and connected apps before considering the incident resolved.

Frequently asked questions

Does a password-reset email mean someone knows my password?

No. Anyone who knows the address may request a reset. Do not use the email link if you did not request it; review the account directly.

Should I delete a hacked account?

Recover and review it first. Deletion can remove evidence or leave linked accounts unresolved. Decide after control is restored.

Can 2FA stop an attacker who is already signed in?

Not by itself. Revoke sessions and connected access, then enable or repair 2FA.

Why does the account show several sessions for one phone?

Different browsers, apps, private windows, and repeated authentication can create separate sessions. Review details and sign out when uncertain.