Digital Safety & Privacy

What to Do If You Were Hacked: Contain, Recover, and Learn

Prioritize the accounts and devices that can reset, impersonate, or move money, then recover methodically and document what happened.

What this guide helps you do

Give an individual a calm, ordered response plan after suspected account or device compromise.

If an attacker may still control a device, email account, phone number, or password manager, recovery order matters. Use a device you reasonably trust, protect the channels that reset other accounts, contain financial harm, end unauthorized sessions, and use each provider’s official recovery route.

Identify the highest-leverage compromise

List evidence: unfamiliar login alerts, changed recovery details, sent messages, payment activity, new forwarding rules, locked accounts, unexpected multi-factor prompts, or device changes. Do not rely on links or phone numbers inside the suspicious alert; navigate independently to providers.

Protect control points first

  • Safe device and network for recovery work
  • Primary email, phone carrier account, and password manager
  • Banks, cards, payment services, tax, benefits, and investment accounts
  • Cloud storage, social, shopping, work, and messaging accounts
  • Recovery email, phone, passkeys or MFA, app passwords, sessions, and API access
  • Evidence, provider case numbers, contacts notified, and remaining follow-up

Choose action by impact

SignalImmediate priorityNext evidence
Money movingContact financial provider through known channelTransactions and case number
Email controlledUse official recovery and secure reset channelsRecovery changes and session list
Device behaving oddlyDisconnect if active harm; use trusted deviceSecurity scan and account activity

Recover in a controlled order

  1. Move recovery to a trusted device.
  2. Contact financial and identity providers for active harm.
  3. Recover and harden primary email and phone.
  4. Change reused or exposed passwords and end sessions.
  5. Review rules, devices, apps, recovery details, and transactions.
  6. Notify affected contacts and monitor for recurrence.

Avoid recovery traps

  • Calling a number supplied by the attacker
  • Changing passwords on a device that may still be controlled
  • Reusing one new password across recovered accounts
  • Deleting messages and logs before recording evidence

Keep a private incident timeline

Record first signal, affected accounts and devices, unauthorized changes, transactions, notifications, recovery actions, session termination, provider contacts, report or case numbers, evidence location, monitoring, and unresolved concerns. Store it somewhere the suspected compromised account cannot alter.

Continue with the next decision

Harden the account that resets others. Email recovery and forwarding controls deserve immediate attention.

Separate a breach notice from confirmed takeover. Exposure risk and active compromise require related but different actions.

Sources and further reading

Primary and contextual sources used to verify definitions or give readers a relevant next resource.

  • CISA Secure Our World Official public guidance on account protection, phishing recognition, strong passwords, and software updates.
  • IdentityTheft.gov Official U.S. recovery-planning resource for identity theft.
IE

Prepared and reviewed by

Infortified Editorial Team

Research-led guides with explicit scope, source checks where facts require them, and an independence review before publication.

Search Infortified

Find a practical answer

Start typing to search all guides.

Open full search