🚨 What To Do If You Think You've Been Hacked (Step-by-Step)
On this page
- Step 1: Change the Password on the Compromised Account
- Step 2: Sign Out of All Devices
- Step 3: Check Account Recovery Settings
- Step 4: Enable Two-Factor Authentication
- Step 5: Check for Unauthorised Activity
- Step 6: Warn Your Contacts
- Step 7: Scan Your Devices for Malware
- Preventing Future Compromises
If you think someone has accessed your account without permission, act quickly but calmly. The faster you respond, the less damage an attacker can do. Follow these steps in order.
Step 1: Change the Password on the Compromised Account
Change the password immediately. Use a device you trust — ideally one you have already scanned for malware. Generate a new strong password using a password manager or our password generator. Make it at least 16 characters and unique to this account.
Important: If you can still log in, change the password before doing anything else. If the attacker changed the password and locked you out, use the "Forgot Password" option to reset it. If the recovery email or phone number has been changed, contact the service's account recovery team directly.
Step 2: Sign Out of All Devices
After changing the password, most services offer an option to "Sign out of all devices" or "Revoke all sessions" in the Security Settings. Use it. This forces any attacker currently logged in to authenticate again — and they will not have the new password.
Do not skip this step. Attackers often maintain active sessions that persist even after a password change. Signing out everywhere ensures those sessions are terminated. The Trusty Password manager companion complements password managers by generating unique credentials for every site.
Step 3: Check Account Recovery Settings
Attackers often change recovery email addresses, phone numbers, and security questions to lock the legitimate owner out. Go to Account Recovery or Security Settings and verify:
- Recovery email address — is it yours?
- Recovery phone number — is it your number?
- Security questions — were they changed?
- MFA methods — were any new authenticator apps or phone numbers added?
- Email forwarding rules — attackers set these up to intercept password reset emails
If any of these were changed, restore them immediately.
Step 4: Enable Two-Factor Authentication
If you did not have 2FA enabled before, enable it now. Use an authenticator app (TOTP) or a passkey. This prevents the attacker from logging back in even if they somehow obtain your new password. Learn how to set this up in our step-by-step 2FA guide.
Step 5: Check for Unauthorised Activity
Review what the attacker did while they had access:
- Emails sent — Check your Sent folder. Attackers often use compromised email accounts to send phishing messages to your contacts.
- Purchases and transactions — Check recent orders, payments, and transfers.
- API keys and app permissions — Revoke any that were added without your knowledge.
- Social media posts — Check for posts you did not make.
- Connected accounts — Some services let attackers sign in with your compromised account to access other services.
- Your primary email, since it controls password resets for everything else
- Banking and financial accounts
- Social media and shopping accounts
- Any account that reused the breached password
- Logins from unfamiliar locations or devices
- Emails you did not send or messages posted without your knowledge
- Changed recovery email addresses or phone numbers
- Unexpected charges, transfers, or new accounts opened in your name
- Back up important files regularly to a secure location
- Monitor your credit and statements for several months
- Review app permissions and remove anything unfamiliar
Step 6: Warn Your Contacts
If the attacker sent messages from your account, let your contacts know. A simple message — "My account was compromised. If you received a suspicious message from me, please ignore it and do not click any links" — prevents the attack from spreading to people who trust you.
Step 7: Scan Your Devices for Malware
Run a full antivirus scan on all devices you use to access the compromised account. Use a trusted security tool: Windows Defender (built into Windows), Malwarebytes, or Bitdefender. If the attacker gained access through malware on your device, cleaning it prevents recompromise.
Preventing Future Compromises
Once you have secured the immediate breach, take steps to prevent it from happening again: use a password manager, enable 2FA on every account, and avoid common password mistakes that put your accounts at risk.
Here is the HTML (approximately 485 words): ```htmlWhat To Do If You Think You've Been Hacked (Step-by-Step)
Discovering that your account or device may have been compromised is alarming, but acting quickly and methodically can limit the damage. Follow these steps as soon as you suspect something is wrong. The faster you respond, the less time an attacker has to steal data, drain accounts, or reach your contacts.
Step 1: Disconnect From the Internet
Immediately cut off the affected device's connection. Turn off Wi-Fi, unplug the Ethernet cable, or enable airplane mode. This stops attackers from sending data, installing more malware, or controlling your machine remotely while you assess the situation.
Step 2: Change Your Passwords
Using a different, trusted device, change the passwords for your most important accounts first. Prioritize them in this order:
Create long, unique passwords for each service and never reuse them.
Step 3: Enable Two-Factor Authentication
Turn on two-factor authentication (2FA) wherever it is offered. An authenticator app or hardware key is stronger than SMS codes. This adds a second barrier, so even if a hacker has your password, they cannot log in without the additional code.
Step 4: Scan for Malware
Run a full scan using reputable antivirus or anti-malware software. Remove anything flagged as malicious. If the infection persists or your tools cannot clean it, consider backing up your files and performing a complete factory reset of the device.
Step 5: Check for Unauthorized Activity
Review recent activity across your accounts and look for warning signs, including:
Step 6: Notify the Right People
Contact your bank or card issuer if money or payment details are involved, and ask them to freeze or monitor your accounts. Warn friends, family, and colleagues that messages from you may be fraudulent. Report the incident to the relevant platform and, where appropriate, to local authorities or a fraud-reporting agency.
Step 7: Strengthen Your Defenses
Once the threat is contained, take steps to prevent a repeat. Use a password manager, keep your operating system and apps updated, and stay cautious with email links and attachments.
Being hacked is stressful, but a calm, structured response helps you regain control and protect yourself against future attacks.