Account recovery

How to Recover a Hacked Online Account: A Clear Plan

By Aisha Khan · · 8 min read

If you think an account has been hacked, act in this order: secure your primary email first, then use the service's official recovery flow, set a new unique password, sign out all other sessions, turn on two-factor authentication, and check that nothing has been quietly changed in your settings. Stay calm — these steps work, and rushing leads to mistakes.

First, confirm what is happening

Signs of a compromise include logins you do not recognise, password-reset emails you did not request, messages sent in your name, missing emails, or being suddenly locked out. Before you panic, make sure you are not simply looking at a phishing message designed to make you panic. Genuine alerts will be visible inside the account's own security page — so go there directly by typing the address yourself, never by clicking a link in the alarming message.

Golden rule: always start recovery from the official website or app, reached by typing the address or using a bookmark. Attackers send fake "your account was hacked" emails precisely to lure you onto a lookalike page. Our guide on spotting a fake website shows how to tell the difference.

Step 1: Secure your email first

Your primary email is the master key to your online life, because almost every other account uses it to send password resets. If the hacked account is your email, fix that before anything else. If it is a different account, still check your email is safe, then return to the account in question.

Step 2: Regain access

If you can still log in, change the password straight away. If you are locked out, use the service's "forgot password" or account-recovery option. Major providers also have a dedicated recovery process for cases where the attacker has changed your recovery email or phone number — it may ask for previous passwords or identity checks and can take a little time. Work only through the provider's official help pages.

Step 3: Set a new, unique password

Choose a fresh password that you have never used anywhere else. The easiest way to get a strong one is to create it with our password generator and store it in a password manager so you never have to memorise it. Before you commit, you can paste it into the strength analyser to confirm it lands in the strong range. If this account shared a password with others, change those too — reuse is how one breach becomes many.

Step 4: Sign out every other session

Changing the password is not enough on its own, because an attacker who is already signed in may stay signed in. Look in the security settings for an option such as "sign out of all devices", "active sessions" or "where you're logged in", and end every session you do not recognise. This is the step people most often forget, and it is the one that actually evicts the intruder.

Step 5: Check what they may have changed

Attackers often plant ways to keep access or to siphon off information quietly. Work through these:

  • Recovery email and phone: confirm they are still yours and remove any you do not recognise.
  • Email forwarding and filters: look for rules that auto-forward or delete your messages — a common trick to intercept reset codes.
  • Connected apps and permissions: revoke anything unfamiliar that has access to the account.
  • Profile and security details: check your name, linked accounts and security questions have not been altered.

Step 6: Turn on a second factor

Once you are back in control, add two-factor authentication or a passkey if the account offers it. This means a stolen password alone is no longer enough to log in. An authenticator app or a passkey tied to your device is generally stronger than codes sent by text, though any second factor is far better than none.

Step 7: Tell the right people

If the account was used to message your contacts, let them know so they ignore any scam links sent in your name. For banking, payment or shopping accounts, contact the provider directly using the number printed on your card or statement, and watch your statements for unfamiliar transactions. If money has moved, report it to your bank promptly — many have protections for fraud reported quickly.

Step 8: Learn from it and harden the rest

Once the fire is out, take ten minutes to reduce the chance of a repeat. Give every important account its own long, unique password from your manager, switch on a second factor wherever it is offered, and review your recovery details periodically. If the original break-in came from a reused password, our guide to passwords versus passphrases explains how to build credentials that are both strong and practical.

Frequently asked questions

What should I do first if my account is hacked?

If you can still log in, change the password immediately to a new, unique one and sign out all other sessions. If you are locked out, use the service's official forgot-password or account-recovery flow. Always start from the genuine website or app, never from a link in a suspicious message.

How do I know which account to fix first?

Secure your primary email first, because it can reset passwords for almost everything else. Once your email is safe, work through banking, then any account that shares a password with the one that was hacked.

The attacker changed my recovery email and phone. Can I still get in?

Yes, most major services have a dedicated account-recovery process for exactly this situation. It may ask for past passwords, security questions or identity verification and can take time. Be patient and only use the official help pages of the service.

Do I need to tell anyone?

Let your contacts know if the account may have been used to message them, so they ignore any scam links sent in your name. For banking or payment accounts, contact the provider directly using the number on your card or statement.

How do I stop it happening again?

Use a long, unique password for every account, store them in a password manager, and turn on two-factor authentication or a passkey wherever it is offered. Review your recovery email, phone number and any forwarding rules regularly.

This article is general online-safety education, not professional security advice.