Emergency Guide

🚨 What To Do If You Think You've Been Hacked (Step-by-Step)

By Sarah Mitchell, Digital Safety Writer, FreeStrongPassword.com · 15 Apr 2026 · 3 min read · 571 words

If you think someone has accessed your account without permission, act quickly but calmly. The faster you respond, the less damage an attacker can do. Follow these steps in order.

Step 1: Change the Password on the Compromised Account

Change the password immediately. Use a device you trust — ideally one you have already scanned for malware. Generate a new strong password using a password manager or our password generator. Make it at least 16 characters and unique to this account.

Important: If you can still log in, change the password before doing anything else. If the attacker changed the password and locked you out, use the "Forgot Password" option to reset it. If the recovery email or phone number has been changed, contact the service's account recovery team directly.

Step 2: Sign Out of All Devices

After changing the password, most services offer an option to "Sign out of all devices" or "Revoke all sessions" in the Security Settings. Use it. This forces any attacker currently logged in to authenticate again — and they will not have the new password.

Do not skip this step. Attackers often maintain active sessions that persist even after a password change. Signing out everywhere ensures those sessions are terminated. The Trusty Password manager companion complements password managers by generating unique credentials for every site.

Step 3: Check Account Recovery Settings

Attackers often change recovery email addresses, phone numbers, and security questions to lock the legitimate owner out. Go to Account Recovery or Security Settings and verify:

If any of these were changed, restore them immediately.

Step 4: Enable Two-Factor Authentication

If you did not have 2FA enabled before, enable it now. Use an authenticator app (TOTP) or a passkey. This prevents the attacker from logging back in even if they somehow obtain your new password. Learn how to set this up in our step-by-step 2FA guide.

Step 5: Check for Unauthorised Activity

Review what the attacker did while they had access:

More Password Security Tools

🔑 SecureKeyGen⚔️ TitanPasswords🛡️ Best Password Generator⚡ Instant Password🗝️ Iron Vault Keys🔑 Random Pwd Tool👨‍👩‍👧‍👦 Safe Pass Builder🛡️ Trusty Password⚙️ StrongPassFactory🔑 SecureKeyGen.org📚 TrustyPassword.org
We use cookies to improve your experience. Learn more

🔗 Recommended Security Tools

We may earn a commission if you purchase through these links — at no extra cost to you.

🔒 Hide My Name VPN