Give an individual a calm, ordered response plan after suspected account or device compromise.
If an attacker may still control a device, email account, phone number, or password manager, recovery order matters. Use a device you reasonably trust, protect the channels that reset other accounts, contain financial harm, end unauthorized sessions, and use each provider’s official recovery route.
Identify the highest-leverage compromise
List evidence: unfamiliar login alerts, changed recovery details, sent messages, payment activity, new forwarding rules, locked accounts, unexpected multi-factor prompts, or device changes. Do not rely on links or phone numbers inside the suspicious alert; navigate independently to providers.
Protect control points first
- Safe device and network for recovery work
- Primary email, phone carrier account, and password manager
- Banks, cards, payment services, tax, benefits, and investment accounts
- Cloud storage, social, shopping, work, and messaging accounts
- Recovery email, phone, passkeys or MFA, app passwords, sessions, and API access
- Evidence, provider case numbers, contacts notified, and remaining follow-up
Choose action by impact
| Signal | Immediate priority | Next evidence |
|---|---|---|
| Money moving | Contact financial provider through known channel | Transactions and case number |
| Email controlled | Use official recovery and secure reset channels | Recovery changes and session list |
| Device behaving oddly | Disconnect if active harm; use trusted device | Security scan and account activity |
Recover in a controlled order
- Move recovery to a trusted device.
- Contact financial and identity providers for active harm.
- Recover and harden primary email and phone.
- Change reused or exposed passwords and end sessions.
- Review rules, devices, apps, recovery details, and transactions.
- Notify affected contacts and monitor for recurrence.
Avoid recovery traps
- Calling a number supplied by the attacker
- Changing passwords on a device that may still be controlled
- Reusing one new password across recovered accounts
- Deleting messages and logs before recording evidence
Keep a private incident timeline
Record first signal, affected accounts and devices, unauthorized changes, transactions, notifications, recovery actions, session termination, provider contacts, report or case numbers, evidence location, monitoring, and unresolved concerns. Store it somewhere the suspected compromised account cannot alter.
Continue with the next decision
Sources and further reading
Primary and contextual sources used to verify definitions or give readers a relevant next resource.
- CISA Secure Our World Official public guidance on account protection, phishing recognition, strong passwords, and software updates.
- IdentityTheft.gov Official U.S. recovery-planning resource for identity theft.