Your Account Was Hacked. Do These 5 Things First.
The first 30 minutes after discovering an account takeover are critical. Here is the exact sequence of actions that preserves evidence, limits damage, and gives you the best chance of recovery.
Your Account Was Hacked. Do These 5 Things First.
You've just discovered that someone else is in your account. Maybe you got a login alert from an unfamiliar location. Maybe a friend messaged you asking why you sent them something strange. Maybe you tried to log in and your password no longer works.
Whatever the trigger, the next 30 minutes matter more than most people realise. Here's exactly what to do — in order.
Why the First 30 Minutes Are Critical
Account takeovers follow a predictable pattern. The attacker gains access, changes the recovery credentials (email, phone number, backup codes) to lock you out, and then uses the account for their purposes — whether that's sending phishing messages to your contacts, accessing linked accounts, or simply monitoring your communications.
Every minute you wait is a minute they have to entrench themselves. But acting in the wrong order can make things worse — including destroying evidence you may need later.
Step 1: Document Everything Before You Touch Anything
Before you change a single password or click a single button, take screenshots.
Screenshot:
- The login alert or notification that alerted you
- Any messages sent from your account that you didn't write
- Any changes to your account settings you can see
- Any unfamiliar devices listed in your account's active sessions
This documentation may seem unnecessary in the moment, but if you later need to report the incident to law enforcement, pursue a civil case, or demonstrate to a platform that your account was compromised, this evidence is invaluable. Once you start the recovery process, some of this information disappears.
Step 2: Attempt Account Recovery Immediately
Most platforms have an account recovery flow accessible from the login page. Use it now, before the attacker has time to change your recovery options.
Common recovery paths:
- Email-based recovery — a reset link sent to your registered email
- Phone-based recovery — a code sent to your registered phone number
- Backup codes — if you set these up when you enabled two-factor authentication
- Identity verification — some platforms allow you to verify your identity with a government ID
If the attacker has already changed your recovery email and phone number, you'll need to escalate to the platform's account recovery team. This process can take days. Start it immediately.
Step 3: Secure Your Email Account First
Your email account is the master key to everything else. If the attacker has access to your email, they can reset the passwords on every other account you own.
Before focusing on the compromised account, verify that your email account is secure:
- Check your email's recent login activity for unfamiliar sessions
- Review your email's forwarding rules — attackers often set up silent forwarding to monitor your incoming mail
- Check for any filters that might be hiding security alerts from you
- Change your email password from a device you trust
If your email account is also compromised, prioritise securing it above everything else.
Step 4: Revoke All Active Sessions
Once you've regained access to the compromised account, immediately revoke all active sessions. This logs out every device currently connected to the account — including the attacker's.
Most platforms have this option in their security settings under "Active Sessions," "Devices," or "Where You're Logged In."
After revoking sessions:
- Change your password to something strong and unique
- Enable two-factor authentication if it wasn't already active
- Review and remove any third-party apps that have access to your account
Step 5: Audit Connected Accounts and Notify Your Contacts
Account takeovers rarely stop at one account. Check which other services you've connected to the compromised account — apps that use "Login with [Platform]," services that have access to your account data, and any accounts that share the same password.
Change passwords on all connected accounts. Assume that any account sharing a password with the compromised one is also compromised.
Then notify your contacts. If the attacker sent messages from your account, your contacts may have clicked links or received requests that put them at risk. A brief message explaining that your account was compromised and asking them to disregard any unusual messages protects them and limits the attacker's reach.
When to Get Professional Help
If any of the following apply, a professional forensic investigation is warranted:
- You cannot regain access to the account through standard recovery
- You believe the attacker had access for an extended period
- Sensitive personal, financial, or professional information was accessible through the account — see our full investigation services for the scope of what we can document
- You suspect the attack is targeted rather than opportunistic
- You need documentation for legal proceedings
A forensic investigation into account takeovers can establish exactly when access occurred, what was accessed, and in some cases, identify the attacker. That information is often critical for legal action and for understanding the full scope of the breach.
The most important thing: don't wait. Every hour of delay makes the investigation harder and the evidence harder to recover.
Explore Topics
Written by
CaeliVault
Content creator and writer sharing insights and stories.