What to do if an account is compromised
A calm, step-by-step guide to recovering a hacked email, social media, hosting, or other business account — and locking down everything else.
- Difficulty
- Intermediate
Realizing that someone has gotten into your account is genuinely unsettling. Please take a breath. You can recover from this. The key is to act systematically rather than in a panic, and to work through the steps in the right order.
This guide applies to any account: email, social media, your hosting account, your domain registrar, and more.
Quick summary
If an account is compromised: get back in as quickly as possible (use account recovery if needed), change the password immediately, turn on 2FA, check for any settings changes the attacker made, then scan related accounts. Email is the most critical account to secure first — it's how everything else resets.
Signs that an account has been compromised
- You receive a login notification for a device or location you don't recognize
- You're suddenly locked out of an account
- Colleagues, customers, or followers report receiving strange messages from you
- You find emails in your sent folder that you didn't send
- Your social media account is posting things you didn't post
- Your account settings, payment details, or email address have been changed
Your first priority: regain access
If you've been locked out, go through the official account recovery process immediately. Don't delay.
- Email (Google/Gmail): accounts.google.com/signin/recovery
- Email (Microsoft/Outlook): account.live.com/acsr
- Facebook: facebook.com/hacked — Facebook asks you to do this on a device you have logged in from before
- Instagram: instagram.com/hacked — Instagram's own advice is to open this in a desktop or mobile browser
- For other accounts: look for "Forgot password" or "Can't sign in" on the login page
If the attacker changed your recovery email or phone number, account recovery can take longer. Most platforms have a process for this — it usually involves verifying your identity through other means.
Step 1: Change your password immediately
Once you're back in, change the password to something strong and unique — use your password manager to generate one. See How to create strong passwords.
Step 2: Enable two-factor authentication right now
If 2FA wasn't on before, turn it on now before doing anything else. This is what stops the attacker from getting back in even if they still have your password.
See How to set up two-factor authentication.
Step 3: Check and reverse any changes the attacker made
Attackers often make changes to maintain access even after you change your password. Check everything:
Review account settings. Look for any changes to your recovery email, phone number, name, or contact information. Change anything suspicious back.
Check for email forwarding rules. In Gmail: Settings → See all settings, then the Forwarding and POP/IMAP tab (on some accounts it is just called Forwarding). In Outlook: Settings → Mail → Rules. Delete any rules you didn't create — especially ones that forward all your email to an outside address.
Check connected apps and sessions. Most accounts show you what apps have access and what devices are currently logged in. Revoke access for anything you don't recognize.
Review recent activity. Look at sent messages, posted content, or activity logs for anything you didn't do. Note the approximate times — this helps you understand what was accessed.
Check payment methods. If the account has payment information attached (hosting, domains, advertising accounts), verify it hasn't been changed.
Step 4: Secure related accounts
If the compromised account is your email, this is especially urgent. Email is used to reset passwords for every other account. An attacker with access to your email may have already used it to gain access to other accounts.
Work through your most important accounts:
- Your password manager (if you use one)
- Your website and hosting account
- Your domain registrar
- Financial accounts (banking, Stripe, PayPal)
- Social media accounts
- Cloud storage (Google Drive, OneDrive, Dropbox)
Check each one for unusual activity. Change passwords anywhere you used the same password as the compromised account.
Step 5: Check devices for malware
If an attacker had access to your email, they may have used it to send you a malicious email that installed malware. Or the account may have been compromised through malware on your device.
Run a malware scan on any device you use for that account. See Malware & your website explained.
Step 6: Tell the people who need to know
Depending on what was accessed, you may need to notify:
- Your team — especially if the account was a shared one or if they received suspicious messages from you
- Customers or contacts — if the attacker sent messages from your account to your contacts
- Your bank or payment processor — if financial information was potentially exposed
- A data protection authority — if customer personal data was involved (this may be legally required — consult a lawyer)
Financial fraud: act within hours
If any financial account was accessed or if fraudulent transfers occurred, call your bank immediately. Fraud reversals are time-sensitive — hours matter.
Specific guidance by account type
Email is the highest-priority account because it controls everything else. After regaining access:
- Check forwarding rules and delegated access
- Look at your sent folder for messages you didn't send
- Check whether the attacker used your email to reset passwords elsewhere
- Enable 2FA if it wasn't already on
- Review devices with access to your account and sign out unfamiliar ones
Common questions
How did this happen?
Common causes: a phishing email that captured your password, a data breach at another site where you reused this password, malware on your device, or a weak/guessable password. The most important thing now is to secure the account — you can investigate how it happened after.
How do I know everything is now secure?
You can't be 100% certain, but you've significantly reduced the risk if you've: changed the password, enabled 2FA, revoked unrecognized sessions, removed forwarding rules, and checked for malware. Monitor the account for unusual activity over the coming weeks.
Should I close the account and start fresh?
Usually not — recovery is preferable to losing the account's history and contacts. The exception is if the account was so thoroughly compromised that you can't trust anything about it, or if recovery options have been exhausted.
Related guides
- Two-factor authentication, explained
- How to set up two-factor authentication
- What to do if your site is hacked
- How to recognize phishing attempts
- Your business security checklist
- I got a suspicious email — what now?
- What to do if you lose admin access
- I can't log in to my site
Need a hand?
Learn more
Last updated
What to do if your site is hacked
A calm, step-by-step guide to recovering your website after a hack — what to do first, how to clean up, and how to prevent it happening again.
Security terms, explained simply
Plain-English definitions for every security term you might encounter — from 2FA and brute force to VPN and zero-day.