The password stopped working. Then the “you changed your email” notice arrived, except you did not change anything. That sinking, stomach-drop moment is account takeover, and the next 30 minutes matter more than anything you do later.
The good news: accounts are recoverable more often than people fear. Attackers rarely delete an account, because they want to use it. That gives you a window to fight back, if you work in the right order.
Key takeaways
- Work in order: regain access, lock out the intruder, then clean up the damage.
- Change the password from a device you trust, then sign out all other sessions.
- Turn on two-factor login immediately so the attacker cannot walk back in.
- Your email account is the master key; secure it before anything else.
First, contain the fire
Before you chase every notification, stop the bleeding. If you can still log in, act fast while you have the chance.

Change the password to something new and unique that you have never used elsewhere. Then look for a setting usually called “sign out of all devices” or “manage active sessions” and use it. That single click kicks the attacker out of every session they opened.
If the password already fails, use the “forgot password” flow. This is where your recovery email and phone number earn their keep, so hope you set those up before trouble found you.
Do not reuse your old password with a “2” on the end, and do not set the new one to something you use on another site. If this breach came from a leaked password, a small variation is exactly what the attacker will try next.
Secure your email before anything else
Your email inbox is the skeleton key to your whole digital life. Every “reset my password” link lands there. If an attacker controls your email, they can reset everything else no matter how strong those other passwords are.
So even if the takeover hit your bank or a shopping site, secure the connected email account in the same session. Change its password, sign out all sessions, and turn on two-factor login.
Our full walkthrough on securing your online banking login covers the money side, and it fits inside the bigger plan in protecting your money and identity online.
The recovery checklist, step by step
Work top to bottom. Each step assumes you have done the one above it.
Regain and lock down access
- Log in if you can, or start the password reset if you cannot.
- Set a brand-new, unique password stored in a password manager.
- Sign out of all other devices and sessions.
- Turn on two-factor authentication, ideally with an app rather than text messages.
- Check and remove any recovery email or phone number you do not recognize.
Undo the intruder’s changes
- Review account settings for changed names, addresses, or linked payment methods.
- Check email filters and forwarding rules; attackers add rules to hide reset emails.
- Look at connected apps and third-party access, and revoke anything unfamiliar.
- Review recent activity or login history to see where and when they got in.
Hidden email forwarding rules are the sneakiest part. An attacker sets your inbox to secretly forward or auto-delete security messages, so you never see the alerts. In Gmail check Settings then Filters and Forwarding; in Outlook check Rules. Delete anything you did not create.
Clean up the blast radius
One compromised account rarely stays alone. If you reused that password anywhere, treat every site with the same password as also compromised.
Make a short list of your most valuable accounts: email, banking, primary shopping, and social media. Change the password on each to something unique. This is tedious, and it is also the step that stops a single break-in from becoming a chain reaction.
| Account type | Priority | Why it matters |
|---|---|---|
| Primary email | Do first | Resets every other account’s password |
| Banking and cards | High | Direct access to your money |
| Password manager | High | Holds every other credential |
| Social media | Medium | Used to scam your contacts |
| Shopping accounts | Medium | Stored cards and addresses |
If money moved or a card was added, dispute it immediately using our guide on how to dispute a fraudulent charge and win. And if you are not certain the account was actually breached, our questions-and-answers on telling whether your account was hacked can help you confirm before you spend an afternoon on cleanup.
Report it and watch for round two
Report the takeover to the service through their official help center, not a link from an email. Many platforms have a dedicated “my account was hacked” recovery path that is stronger than the normal reset.
If you are completely locked out
Sometimes the attacker changes the password, the recovery email, and the phone number, and the normal reset fails. Do not give up. Most large services keep a separate account-recovery form for exactly this case, where you prove ownership with older passwords, a linked device, or a billing detail.
Fill it out from a device and network you have used with the account before, since that history helps prove you are the real owner. Be patient: these reviews can take a few days, but they are designed to return the account to the person who can prove the longest relationship with it.
Then stay alert for a week or two. Attackers who lose access often try again using the same stolen data. If the account was tied to identity theft or financial loss in the United States, the FTC’s IdentityTheft.gov can generate a personalized recovery plan and the official reports you may need.
Your afternoon checklist
- Change the compromised account’s password to something new and unique.
- Sign out of all other devices and active sessions.
- Turn on app-based two-factor authentication.
- Secure your primary email the same way, right now.
- Delete any recovery contacts, forwarding rules, or connected apps you do not recognize.
- Reset passwords on every account that shared the old password.
- Report the takeover through the service’s official recovery page.
- Set a reminder to recheck the account settings in one week.
Takeover feels like losing control, but the fix is a sequence, not a panic. Get access back, slam the door, then sweep the room. Work it in that order and you come out with a stronger account than you had before.