On this page
Being able to sign in again is an important recovery step. It does not, by itself, tell you which devices remain connected, which apps have permission to read information, or whether the account’s recovery settings were changed. Those are separate questions to review through the provider’s official controls.
This guide is a follow-up for a personal account you own and can access. For a workplace or managed school account, contact the responsible administrator and follow the organization’s incident process. If you still cannot sign in, begin with the provider’s account-recovery route rather than changing unrelated device settings or trusting an unsolicited recovery service.
Start from a trusted route
Open the service using its known app or an address you enter yourself. Do not use a password-reset link from an unexpected message simply because you are already worried about the account. If the device you are using may itself be compromised, use a trusted alternative and get appropriate help with the suspect device.
Keep a short recovery record: the date, which account was affected, the official recovery action completed, and any unresolved observation. Do not write passwords, one-time codes, recovery codes, or complete payment details in that record. It is a reminder of what remains to check, not a new collection of credentials.
Avoid treating every unfamiliar label as proof of an intruder. Provider screens summarize activity, and those summaries need context. Equally, do not ignore a device or change you cannot explain. Use the provider’s own security review and sign-out controls when something remains uncertain.
Check the account’s recovery foundation
The FTC’s account-recovery guidance recommends a new strong password, signing out devices, enabling two-factor authentication where available, and confirming recovery contact details. It also recommends checking for unauthorized forwarding rules and messages and warning contacts if the account sent a scam.
Work through those checks in the account’s official settings. Confirm that the recovery email and phone belong to you and remain accessible. Review available sign-in methods and follow the provider’s instructions for any method you do not recognize. Save any newly issued recovery material using an appropriate secure method, separate from ordinary notes.
If a recovery method is unfamiliar and you cannot change it, record the problem and return to official support. Repeatedly resetting the password without resolving a recovery setting can leave the central uncertainty untouched. Do not delete the only working method before a replacement has been verified.
Interpret device and session lists carefully
Providers differ in what a password change invalidates. Review the documented sign-out controls instead of assuming the reset ended every connection. Check currently connected devices and sessions, including old phones, shared computers, or devices you no longer own.
For example, Google explains its device and session view as more than a list of physical devices. Several sessions can belong to one device. The displayed activity time can include background synchronization, and a location may be approximate. These details help interpret an entry; they do not prove that an unexplained session is safe.
Inspect the available details and sign out sessions you do not recognize using the provider’s instructions. If a device name appears more than once, review the corresponding sessions rather than assuming one selection covers every entry. Recheck the account after the action and retain any unresolved security alert for official support.
Review connected applications separately
An app connection is a different relationship from an open browser session. A calendar service, document tool, or other application may have been granted account access. Review the name, purpose, and permissions shown by the account provider, not just whether the app icon looks familiar.
Google’s guidance on third-party connections explains how these links can be reviewed and changed. Removing a link can affect the connected app’s features, and it does not necessarily remove data that the app already received. The relevant action depends on whether you are ending access, deleting the app’s stored data, or both.
Remove access you do not recognize or no longer need through the official controls. For a service you still use, understand which connection is required and whether a separate sign-in method is available. Do not approve a new access request merely because an old connection stopped working during the review.
Separate observations from conclusions
Use a small checklist to keep each issue attached to evidence and a next step. The following examples describe a review method, not a universal account interface.
| Observation | What it establishes | Next question |
|---|---|---|
| Password change confirmed | The provider accepted a new password | Which sessions and sign-in methods remain? |
| Unknown recovery address appears | Recovery details do not match your expectations | Can the provider’s secure process correct it? |
| Old phone still appears | The provider retains an entry for that device or session | Is it signed out, active, or recently used? |
| Connected app is unfamiliar | A permission relationship needs review | What data can it access and can the link be removed? |
| Security alert follows recovery | Another event requires interpretation | Is it your recovery action or a separate unexplained event? |
This format helps avoid both premature reassurance and an expanding list of guesses. Write down what the screen actually says and when you checked it. Redact private details before sharing a screenshot with legitimate support, and use the provider’s supported channel.
Consider related accounts when the evidence points there
If the affected account receives password-reset messages for other services, review important linked accounts for unexplained changes. If the old password was reused, replace it on those accounts with unique credentials. Prioritize based on the access involved and any alerts you have actually received.
In an illustrative situation, a person regains an email account and finds an unfamiliar recovery address plus a notice of a password change on another service. Those are two separate tasks: secure the email account’s recovery settings and use the other service’s official process to investigate its change. Closing the email issue should not silently close the second task.
For financial transactions, identity misuse, or a compromised organization account, use the relevant provider or responsible organization promptly. An account-settings checklist cannot establish the extent of access or undo information already exposed.
Finish with a defined follow-up
Record what you verified and what remains uncertain. A useful closeout might say that known devices were reviewed, unwanted connections removed, recovery methods confirmed, and one provider inquiry remains open. It should not say that no one accessed information unless there is evidence supporting that conclusion.
Keep security notifications enabled where available and review new unexplained events through the same official route. Account recovery becomes more dependable when the password change is followed by a deliberate review of the remaining access paths, with unresolved issues kept visible until the provider or responsible administrator can address them.
Sources and further reading
Primary and contextual sources used to verify definitions or give readers a relevant next resource.
- FTC: Recover your hacked email or social media account After recovery, the FTC recommends securing credentials, signing out devices, reviewing recovery details and unauthorized settings or messages, and warning affected contacts.
- Google Account Help: Devices with account access Google distinguishes sessions from devices; multiple sessions can be legitimate, activity can include background communication, and displayed locations can be approximate.
- Google Account Help: Manage links with other apps Google provides separate controls for reviewing and changing third-party account connections; removal can affect the connected service and does not automatically delete data already shared.