On this page
After an account compromise, several events can blur together: a warning email, a failed sign-in, a changed recovery address, a password reset, and messages sent without permission. A concise timeline helps you explain what is known, coordinate support, and avoid repeating steps that have already been completed.
Do not delay urgent containment to create a perfect record. Use the provider's recovery process from a trusted device and follow your organization's incident procedure for work accounts. Capture evidence when it is safe and practical, then improve the timeline as the account becomes more secure.
Create one controlled record
Use a private document or incident system that the suspected attacker cannot access. If the compromised account controls the document's storage, choose an approved alternative. For a work account, ask the responsible security or support team where evidence belongs.
Give the record a clear account identifier without including the password or recovery codes. A partial email address or internal reference may be enough for a shared working note, while the authorized support process can hold the full details.
Limit access to people who need the information. Screenshots of account settings can reveal phone numbers, addresses, other accounts, or active access links. Keep originals protected and use redacted copies when a broader audience needs a summary.
Start with the first observation, not an assumed start time
Record when you first noticed something unusual and what it was. A message received at a particular time proves that you saw or received that message then; it does not necessarily identify when unauthorized access began.
Separate the event time reported by the service from the time you observed it. If a security page shows a sign-in at one time and you inspected the page later, preserve both when they matter. Include the time zone or state that it is unknown.
Avoid writing “attacker entered at 09:00” when the evidence is only an alert delivered at 09:00. A more accurate note describes the alert and the event time it claims. That precision helps the provider or incident responder interpret the record without inheriting an unsupported conclusion.
Distinguish facts, reports, and hypotheses
Use plain labels for what you directly observed, what another person reported, and what you suspect. A friend saying they received a strange message is a useful report; a saved copy of that message provides additional evidence. Neither automatically identifies who sent it.
A device or location you do not recognize deserves review, but it is not always a reliable identity or physical-location finding. Sessions, network routing, and provider labels can complicate interpretation. Follow the provider's account review guidance instead of treating a map pin as proof about a person.
The identity theft warning-sign guide addresses related signals. Keep the timeline focused on this account's evidence and route broader concerns through the appropriate recovery process.
Capture the events that change the response
Prioritize unauthorized recovery-information changes, password changes, unfamiliar sessions, messages or posts you did not create, connected applications you did not authorize, and transactions or settings that affect other people. Record the relevant identifier and evidence location.
For email, also check the provider's guidance about forwarding rules, filters, and connected access. A password change may not by itself explain every mechanism that allowed information to leave the account. Do not make destructive changes to evidence on a work account without coordinating with the responsible team when circumstances allow.
You do not need to copy every ordinary sign-in into the main narrative. Preserve useful records through the approved process and summarize the events that inform containment and recovery decisions.
Record your own containment actions
For each action, write what you did, when you did it, and what result you observed. “Changed password from a trusted device; provider confirmed the change” is more useful than “secured account.” If a remote sign-out was requested, distinguish requesting it from verifying the session list afterward.
Include recovery-information corrections, authentication changes, revoked application access, provider support contacts, and warnings sent to affected contacts where relevant. Never put new passwords, backup codes, or one-time verification codes in the timeline.
The access review after a password reset gives a wider checklist for checking remaining access. Link to the evidence of each completed step rather than relying on a single reassuring status word.
Use a table that preserves uncertainty
An illustrative timeline can use the following fields. Adapt it to the provider's records and the needs of the authorized responder.
| Field | Purpose |
|---|---|
| Event time and zone | When the event reportedly occurred |
| Observation time | When you learned about it |
| Event description | What happened, in neutral language |
| Evidence reference | Where the relevant record is stored |
| Confidence or limitation | What is verified or still uncertain |
| Response and result | What action followed and what it established |
If you cannot determine a time, write “unknown” and provide the available range or sequence. Do not invent minute-level precision from memory. Relative order can still be useful when exact timestamps are unavailable.
Keep a separate list of unresolved questions
A timeline explains events; an action list explains what remains to be done. Keep the two connected but distinct. Questions might include whether an unfamiliar session is still active, whether a recovery address was restored, or whether a payment provider needs a report.
Assign an owner and next checkpoint for each consequential item. A provider support case should have its case reference and the date of the last response. Avoid repeated submissions through multiple channels unless the provider directs you to do so, because fragmented cases can make coordination harder.
Do not mark the entire incident resolved simply because sign-in works again. Restored access is one milestone. Reviewing unauthorized activity, securing recovery routes, and addressing effects on other people may remain.
Share the minimum useful evidence
When contacting the provider, use its established recovery or support channel and follow its requested evidence format. A short factual summary with key times and identifiers is often more useful than a large unorganized archive.
Do not send the same sensitive bundle to strangers who offer recovery services in direct messages or comments. Do not give remote access, passwords, or codes to someone merely because they claim to represent the platform. Verify the support route independently.
If a work account or other people's information is involved, let the responsible organizational team decide the wider notification and evidence-handling process. Requirements depend on the circumstances and jurisdiction; a personal timeline is not a substitute for that assessment.
Preserve revisions without rewriting history
As new evidence arrives, correct mistakes transparently. Add a note explaining that an earlier time was in a different time zone or that a suspicious session was later recognized as legitimate. Do not silently erase an earlier observation that influenced the response.
Keep conclusions proportionate. “No unfamiliar sessions were visible during the review” is narrower and more supportable than “nobody else can ever access the account.” State the date and scope of the check so the record remains useful later.
Use the data breach response guide if the event extends beyond one account into a broader information exposure. The finished timeline should help the next responsible person understand the evidence, the actions already taken, and the questions still open without having to reconstruct the incident from scattered messages.
Sources and further reading
Primary and contextual sources used to verify definitions or give readers a relevant next resource.
- FTC: Recover a hacked account Account recovery includes provider recovery steps, stronger authentication, session review, recovery-information checks, and attention to unauthorized activity.
- Google: Secure a compromised account Google provides security-event and device reviews as part of its account recovery and protection process.
- Google: Devices with account access Account device listings describe sessions and recent activity, which require context when interpreting unfamiliar entries.