If you have been hacked, secure the affected account, end every active session, and replace any exposed or reused passwords. Then inspect other accounts and protect your credit if personal information could support identity theft. Start with email because it can receive password-reset links for other services. If the affected device may also be compromised, clean it before completing account recovery.
Table of Contents
- Lock the attacker out
- Check what the attacker changed
- Replace exposed and reused passwords
- Choose a credit freeze or fraud alert
- Look for signs of identity theft
Lock the attacker out
If you suspect malicious software on your computer, update its security software, run a scan, remove anything suspicious, and restart. Then use the account provider's official recovery process.
Once you regain control: These steps matter most for email accounts because an attacker could use the inbox to reset passwords elsewhere. The FTC's hacked-account guidance recommends securing recovery details as well as changing the password.
- Change the account password.
- Sign out every device or active session.
- Enable two-factor authentication.
- Verify the recovery email addresses and phone numbers.
- Remove any recovery option you do not recognize.
Check what the attacker changed
Recovery does not reveal everything the attacker did. In email, review forwarding rules plus the sent and deleted folders. Delete any forwarding rule or setting you did not create.
For a social account, inspect recent posts, private messages, and account settings. Look for messages containing links, requests for money, or other activity you do not recognize. Warn contacts that the account was compromised. Tell them not to trust unexpected links or payment requests that appeared to come from you, even if those messages use familiar names or past conversation details.
Replace exposed and reused passwords
Change an exposed password immediately on the breached service. If you used the same or a similar password elsewhere, change it on every affected account; the FTC warns that attackers try stolen credentials on other services.
Every replacement should be unique and hard to guess. Two passwords remain similar when they reuse the same recognizable base with a small change, such as "RiverDog1" and "RiverDog2." If you create a password manually, the FTC recommends at least 15 characters. The agency also identifies authenticator apps and security keys as stronger two-factor options than codes delivered by text or email.
Choose a credit freeze or fraud alert
A credit freeze blocks prospective creditors from accessing your credit file, which can prevent someone from opening new accounts in your name. You must contact Equifax, Experian, and TransUnion separately. A freeze is free, does not affect your credit score, and must be lifted before you apply for new credit. A fraud alert is less restrictive.
It requires creditors to verify your identity before opening new credit, issuing another card, or increasing a credit limit. An initial alert lasts up to one year unless you remove it. The practical choice depends on the protection you need. A freeze directly restricts access to your credit file, while an alert leaves access available with added identity checks, as explained in the Consumer Financial Protection Bureau's comparison.
Look for signs of identity theft
Obtain free credit reports from all three nationwide credit bureaus. Review each report for accounts or transactions you do not recognize, since the bureaus may hold different information.
If identity theft occurred, IdentityTheft.gov can create an Identity Theft Report and a recovery plan. Contact each company holding an affected account and ask it to close or freeze that account.
