What to Do If You Were Hacked: Contain, Recover, and Learn
Prioritize the accounts and devices that can reset, impersonate, or move money, then recover methodically and document what happened.
INFORMATION FIELD OFFICEIF / D-10
Research dossier · open collection
An incident becomes easier to manage when the response follows the systems at risk: personal safety, device access, email, phone number, recovery methods, money, identity records, and evidence. These guides help readers contain immediate harm, verify what happened, protect recovery channels, contact the right provider or authority, and document the steps still outstanding.
FIELD NOTES / D-10
Begin with the lead note, then follow the question closest to your next step.
Prioritize the accounts and devices that can reset, impersonate, or move money, then recover methodically and document what happened.
Separate a suspicious message from verified misuse, then act through official channels in order of financial and identity impact.
Prioritize high-harm exposure, remove information at its source where possible, and understand the limits of search suppression and broker opt-outs.
Use a repeatable verification process when a message creates urgency, fear, secrecy, scarcity, affection, authority, or an unexpected payment path.
Match protective action to the data exposed, the account involved, the attacker’s likely next step, and whether misuse has already appeared.
A calm, platform-aware response plan for protecting your device, phone number, accounts, and identity without destroying useful recovery options too early.
A plain-language U.S. guide to choosing, placing, and managing credit freezes and fraud alerts without confusing them with credit locks or card freezes.
Use official account controls to review sessions, recovery methods, connected apps, and unexpected settings after regaining access to a personal account.
Record observed account events, containment actions, and unresolved questions in a clear timeline without delaying recovery or exposing sensitive evidence.
Restrict an exposed cloud link, review direct and inherited access, verify the new permissions, and assess what may already have been copied or shared.
Identify the payment route, contact the real provider promptly, preserve transaction details, and track follow-up without relying on a promised recovery service.
Identify the source of alarming browser alerts, remove unwanted site permissions, and distinguish notification spam from signs that need a wider security review.