A friend texts you: “Did you mean to send me this link?” You did not send anything. Your stomach tightens. Is your account hacked, or is this just spam using your name? That uncertainty is where most people get stuck, so let us answer it directly.
Key takeaways
- Login alerts from unfamiliar places and unexpected password-reset emails are the clearest signs.
- Check your account’s login history and connected devices to confirm before you panic.
- Contacts getting weird messages from you is a strong signal, not always proof.
- When in doubt, treat it as real: change the password and turn on two-factor login.
What are the clearest signs my account was hacked?
Some signs are noise, and some are alarms. Start with the alarms, because they rarely have an innocent explanation.

A sign-in alert from a city or country you have never visited is near the top. So is a password-reset email you did not request, because it often means someone is actively trying to break in right now.
Other loud signals include being suddenly logged out and unable to get back in, settings you did not change (like a new recovery email), or messages in your “sent” folder you never wrote.
The quieter signs worth noticing
- Friends report odd links or money requests coming from you.
- Your antivirus or bank flags unusual activity.
- A service appears in a data breach notification.
- Small settings drift: a changed profile photo, a new linked app.
My friends got a weird message from me. Am I definitely hacked?
Not always, and this trips people up. There are two different problems that look identical from the outside.
If the weird message came from inside the actual app or your real account, that points to a genuine takeover. Check your sent folder or message history: if the message is there, someone is in.
If instead the message came from a lookalike account or a spoofed email address, that is impersonation, not a hack. A scammer copied your name and photo to fool your contacts, but never touched your account. Compare the sender address or username carefully.
Impersonation is annoying but lower stakes. You cannot “recover” an account that was never breached. Instead, report the fake profile to the platform and warn your contacts. A real takeover, by contrast, needs the full lockdown treatment.
How do I actually check, instead of guessing?
Guessing keeps you anxious. Checking gives you an answer in a few minutes.
Most major services keep a security page that shows recent logins and active devices. Look for “recent activity,” “where you’re signed in,” or “security checkup.” Sign-ins from strange places or unknown devices are your confirmation.
Next, check whether your email or password showed up in a known breach. The free tool Have I Been Pwned lets you enter an email address and see which breaches included it. A hit does not always mean this account is compromised, but it tells you which passwords need changing.
Where each service hides the security page
The wording changes from app to app, which is why people give up looking. On Google, it is your account page under “Security,” then “Your devices” and “Recent security activity.” On Apple, it is Settings, your name, then the list of devices signed in with your Apple ID.
On Facebook and Instagram, look under Settings for “Where you’re logged in” or “Login activity.” On your bank, the label is often “Recent activity” or “Manage devices.” If a session shows a device or city you cannot explain, that is your answer.
| What you notice | Hacked or not? | How to confirm |
|---|---|---|
| Login alert from a strange location | Likely hacked | Check recent-activity page |
| Password reset you did not request | Attempt in progress | Do not click; secure the account |
| Friends get spam from a lookalike | Impersonation, not a hack | Compare the exact username |
| You cannot log in at all | Likely hacked | Use official account recovery |
| Email appears in a breach | Password exposed | Change that password everywhere |
What are my first moves if it is real?
If the signs point to a real takeover, do not spiral. Move in a fixed order.
Change the password from a device you trust, then sign out of all other sessions. Turn on two-factor authentication so a stolen password alone is no longer enough. Then check for sneaky changes like new forwarding rules or recovery contacts.
When I checked my mother-in-law’s email after a scare, the real damage was a single hidden forwarding rule quietly copying every message to a stranger. The password change alone would not have caught it. That full sequence lives in our account takeover recovery steps.
The password-reset email you did not request is a trap in two ways. First, it can mean an active break-in. Second, scammers send fake versions to panic you into clicking. Never click the link in that email; open the service directly and change your password there.
How do I stop this from happening again?
Prevention is mostly two habits. Use a unique password for every account, and turn on two-factor authentication on anything that holds money or personal data.
Beyond that, keep alerts on so you hear about a login the moment it happens. The steps in securing your online banking login apply to almost any important account, and they slot into the wider plan in protecting your money and identity online.
Your afternoon checklist
- Open the account’s recent-activity or security page and review every login.
- Check whether the odd message came from your real account or a lookalike.
- Run your email through Have I Been Pwned to spot exposed passwords.
- If confirmed, change the password from a trusted device and sign out all sessions.
- Turn on app-based two-factor authentication.
- Look for hidden forwarding rules and unknown recovery contacts.
- Warn your contacts if impersonation or a takeover reached them.
The scariest part of a possible hack is not knowing. Give it a few minutes of checking instead of a night of worry, and you will know exactly which door to close.