Recovering a hacked account is mostly a question of sequence. People lose accounts they could have saved because they change the obvious password first and leave the attacker’s access route untouched, so they get locked out again an hour later. This is the order that works, and why each step comes where it does.
Written September 2026. If money has moved, contact your bank first. Nothing below is more urgent than stopping a payment.

Start with email, whatever was actually breached
Your email account is the master key. It can reset almost everything else, so if an attacker has it, fixing any other account is pointless: they will simply reset it again. Even if the hacked account appears to be a shopping or social login, secure the email first.
- Sign in to your email and change the password to something long and unique.
- Sign out all other sessions. Every major provider has this: look for “security”, then devices or active sessions. This is the step people skip, and it is the one that ejects the attacker.
- Check recovery settings for anything you do not recognise: alternate email addresses, phone numbers, security questions.
- Check filters and forwarding rules. This is the most commonly missed step of all. Attackers frequently add a rule that quietly forwards or deletes mail so you never see the reset messages. Delete anything you did not create.
Then work outward from the hacked account
With email secured, deal with the rest in order of what an attacker can do with them. Financial accounts first, then anything holding payment details, then identity and social, then everything else.
- Change passwords, not just the one. If the compromised password was reused anywhere, every one of those accounts is compromised too. Reuse is how a single breach becomes a bad week.
- Revoke connected apps. Check the third-party apps authorised on each account and remove anything unfamiliar. An authorised app keeps access after a password change.
- Sign out everywhere, everywhere. Do the active-sessions step on each significant account, not just email.
- Turn on two-factor or a passkey. A password change alone restores the situation that got breached. Adding a second factor changes it.
If you are locked out completely
When the attacker has already changed the password and recovery details, you need the provider’s account recovery process rather than the login form. A few things materially improve your odds:
- Use a device and network you have used before with that account. Providers weight familiar devices and locations heavily in recovery decisions.
- Answer from memory rather than guessing precisely. Approximate answers are usually accepted; wildly wrong ones hurt.
- Give the oldest information you can recall, such as the original recovery email or the month you created the account.
- Do not spam the form. Repeated failed attempts from an unfamiliar device look exactly like an attack and can make things worse.
Be extremely wary of anyone offering to recover your account for a fee. Account recovery services advertised on social media are overwhelmingly a second scam aimed at people who have just been robbed. No legitimate service can bypass a provider’s recovery process.
Contain the damage while you work
A compromised account is often used against the people who trust you. Tell contacts not to act on messages from you until you say otherwise, especially any request for money or urgency. If the account was used to post publicly, say what happened plainly once it is back.
Check what the attacker may have taken as well as what they did. Look at sent mail, deleted items, and any downloads or exports. If identity documents or a password list were in there, that widens the problem considerably.
Afterwards, close the door properly
Recovery is not finished when you can log in again. Three things prevent a repeat, and none of them takes long.
- Unique passwords everywhere. A password manager makes this practical rather than aspirational.
- A second factor on anything that matters. Passkeys are the strongest option where supported, because they cannot be phished.
- Recovery codes stored offline. Printed and kept somewhere physical, so a future lockout is an inconvenience rather than a loss.
Most compromises start with a convincing message rather than clever hacking, so it is worth knowing how to spot a phishing email well enough to catch the next one.
How to tell you have a hacked account in the first place
Compromises are often quieter than people expect. An attacker who wants ongoing access has every reason not to announce themselves, so the giveaways tend to be small administrative details rather than anything dramatic.
- Password reset emails you did not request. One is worth noticing. Several is someone working through your accounts.
- Sign-in alerts from unfamiliar places. Treat these seriously even if the location looks plausible, since VPNs make location unreliable in both directions.
- Mail that has been read before you read it. Messages already marked as read, or missing from the inbox but present in the archive.
- Contacts mentioning messages you did not send. Often the first sign, and often dismissed as spoofing when it is not.
- New devices in your account’s device list. Worth checking monthly on your email and banking accounts regardless.
- Small unexplained transactions. Card testing usually starts with a trivial amount to see whether the card is live.
If two or more of these appear together, work through the recovery sequence above rather than waiting for confirmation. Acting early on a false alarm costs you ten minutes; acting late on a real one can cost a great deal more.
Check whether your details are already public
Large breaches are catalogued, and you can look yourself up. Have I Been Pwned will tell you which known breaches included your email address, and which categories of data were exposed. If a password of yours appears there and you still use it anywhere, that is the first thing to change, whether or not you have seen anything suspicious.
If it was a work account
Tell your IT or security team immediately, before you start fixing anything yourself. A hacked account on a company system is not just your problem: it is a route into shared drives, internal mail and customer data, and the response needs to be coordinated. Well-meaning independent cleanup can destroy the logs that show what the attacker actually reached, which makes the investigation harder and can turn a contained incident into a reportable breach.
Common questions
What should I do first with a hacked account? Secure your email account before anything else, and sign out all other sessions. Email can reset every other account, so fixing anything else while the attacker still has your inbox achieves nothing.
Why check email forwarding rules? It is the most commonly missed step. Attackers add a rule that forwards or deletes incoming mail so you never see password reset messages, which keeps them in control even after you change the password.
Can I get an account back if the attacker changed everything? Often yes, through the provider’s account recovery process. Use a device and network you have used before, and give the oldest details you can remember. Never pay a third party claiming they can recover it for you.
Do I need to change passwords on other sites? Yes, on any site where you used the same or a similar password. Credential reuse is how one breach turns into several compromised accounts.
Sources and further reading
Where the figures and rules above come from, so you can check them:
- Official guidance on recovering compromised accounts: UK NCSC
- Checking whether your details appear in a known breach: Have I Been Pwned
Join the discussion