Realising an account's been hacked is a gut-punch, but panic wastes the time that matters. Work the checklist in order — it's designed to lock the attacker out and limit the damage.

Do these in order

  1. Secure your email first — it controls password resets for everything else.
  2. Change the password on the hacked account and anywhere you reused it.
  3. Turn on two-factor authentication.
  4. Check for changes the attacker made — recovery email, forwarding rules, connected apps.
  5. Log out all other sessions if the platform allows it.

Contain the spread

  • Warn contacts if the account may message them with scams.
  • If money's involved, contact your bank and freeze cards.
  • Watch for follow-up phishing that uses stolen details.
💡

Prevent the next one

Once you're back in control, read how to create safer passwords so it doesn't happen again.

Watch for the mistakes that let them back in

Locking the attacker out once is not the same as keeping them out. Most people regain access, breathe out, and then get hijacked again a day later because they skipped a step. The reset itself has to be clean.

  • Reusing a variation of the old password. If your leaked password was Summer2024!, then Summer2025! is already guessed. Pick something completely unrelated.
  • Leaving old sessions alive. A new password does not always kick out devices that are already logged in. Find "log out all devices" or "active sessions" and end them all.
  • Forgetting the recovery details. Attackers quietly add their own recovery email or phone number so they can reset your password later. Check and remove anything you do not recognise.
  • Ignoring email forwarding rules. A common trick is a hidden rule that auto-forwards your mail or sends security alerts to trash. Open your filters and delete any you did not create.

How to know it actually worked

Do not assume you are safe just because you can log in. Spend ten minutes confirming it. Log out everywhere, then log back in and check the active-sessions list shows only your own devices. Confirm two-factor is on and tied to your phone or an app, not the attacker's number. Send yourself a test email and make sure it arrives without being forwarded. Then leave it a day and watch for password-reset emails you did not request — those mean someone is still probing.

💡

Check the money last, but do check it

If the account touches payments — shopping, a marketplace, anything with a saved card — review recent orders and remove stored cards. A refunded fraudulent order can still leave your address and details exposed to whoever placed it.

What it realistically takes

For a single email or social account you caught early, the whole clean-up is usually 30 to 60 minutes and costs nothing. Where it drags is when the hacked account was your recovery account — the email everything else resets through. Then you are unpicking a chain, and it can take a few days because some providers make you wait out a security hold before returning access. If money moved, contact your bank the same day; card fraud is usually reversible, but only if you flag it quickly.

Written by Niharika Parashar

Frequently asked questions

How did they get into my account if I never shared my password?
Usually not by guessing you specifically. Passwords leak in bulk when a company gets breached, then get tried across other sites — so if you reused that password anywhere, all those accounts are exposed. Other common routes are a fake login page you typed into, or malware on a device. It rarely means you were personally targeted.
Should I delete the hacked account and start fresh?
Almost never as a first move. Deleting can wipe evidence, lock you out of linked services, and free up your username for someone else. Secure it instead: change the password, end all sessions, turn on two-factor, and clean the recovery settings. Only consider deletion if you genuinely cannot regain control and the provider cannot help.
What do I do if I can't get back in at all?
Use the provider's official account-recovery form, not a random support number you searched for — fake support lines are a scam in themselves. Have details ready: old passwords, rough account-creation date, contacts, or a linked device. If it's tied to money, tell your bank now rather than waiting for access. Expect it to take days, not minutes.
Do I really need to tell my contacts?
Yes, if the account can message people as you. Hackers often use a trusted account to send scam links or fake "I'm stuck, send money" pleas, and your friends are far more likely to click because it's from you. A quick heads-up — "I was hacked, ignore anything odd from me" — stops the damage spreading.
How do I stop this happening again?
Give every important account its own unique password, ideally stored in a password manager so you don't have to remember them. Turn on two-factor everywhere it's offered, preferring an app over text messages. And check your main email's forwarding rules and recovery settings now and then — that's the account everything else depends on.

People also ask