Realising an account's been hacked is a gut-punch, but panic wastes the time that matters. Work the checklist in order — it's designed to lock the attacker out and limit the damage.
Do these in order
- Secure your email first — it controls password resets for everything else.
- Change the password on the hacked account and anywhere you reused it.
- Turn on two-factor authentication.
- Check for changes the attacker made — recovery email, forwarding rules, connected apps.
- Log out all other sessions if the platform allows it.
Contain the spread
- Warn contacts if the account may message them with scams.
- If money's involved, contact your bank and freeze cards.
- Watch for follow-up phishing that uses stolen details.
Prevent the next one
Once you're back in control, read how to create safer passwords so it doesn't happen again.
Watch for the mistakes that let them back in
Locking the attacker out once is not the same as keeping them out. Most people regain access, breathe out, and then get hijacked again a day later because they skipped a step. The reset itself has to be clean.
- Reusing a variation of the old password. If your leaked password was Summer2024!, then Summer2025! is already guessed. Pick something completely unrelated.
- Leaving old sessions alive. A new password does not always kick out devices that are already logged in. Find "log out all devices" or "active sessions" and end them all.
- Forgetting the recovery details. Attackers quietly add their own recovery email or phone number so they can reset your password later. Check and remove anything you do not recognise.
- Ignoring email forwarding rules. A common trick is a hidden rule that auto-forwards your mail or sends security alerts to trash. Open your filters and delete any you did not create.
How to know it actually worked
Do not assume you are safe just because you can log in. Spend ten minutes confirming it. Log out everywhere, then log back in and check the active-sessions list shows only your own devices. Confirm two-factor is on and tied to your phone or an app, not the attacker's number. Send yourself a test email and make sure it arrives without being forwarded. Then leave it a day and watch for password-reset emails you did not request — those mean someone is still probing.
Check the money last, but do check it
If the account touches payments — shopping, a marketplace, anything with a saved card — review recent orders and remove stored cards. A refunded fraudulent order can still leave your address and details exposed to whoever placed it.
What it realistically takes
For a single email or social account you caught early, the whole clean-up is usually 30 to 60 minutes and costs nothing. Where it drags is when the hacked account was your recovery account — the email everything else resets through. Then you are unpicking a chain, and it can take a few days because some providers make you wait out a security hold before returning access. If money moved, contact your bank the same day; card fraud is usually reversible, but only if you flag it quickly.