How to Recover a Compromised Account
How to Recover a Compromised Account
When an online account is compromised, recovering it methodically helps you regain control, secure it, and limit the damage. Whether you are locked out or still have access, there is a clear process to follow. This guide explains how to recover a compromised account, step by step, in plain terms.
First Steps: Regaining Access
The first goal is regaining control:
If you still have access: Log in immediately and secure the account before the attacker locks you out (see securing steps below).
If you are locked out: Use the service's account recovery process — most services have a "forgot password" or dedicated "hacked/compromised account" recovery flow.
Use account recovery options: Recovery typically uses your recovery email, phone, or identity verification. Follow the service's process to verify your identity and regain access.
Act promptly: The sooner you act, the better, to limit the attacker's time with your account.
Securing the Account After Regaining Access
Once you have access, secure the account thoroughly:
Change the password: Set a new, strong, unique password not used anywhere else.
Enable 2FA: Enable 2FA (ideally app-based or a security key) to block the attacker and secure the account.
Fix recovery options: Check and correct your recovery email, phone, and security settings, which the attacker may have changed to maintain access.
Remove unauthorized changes: Undo changes the attacker made — settings, profile, and especially (for email) forwarding rules they set up to secretly copy your emails.
Review connected apps: Revoke access for unfamiliar or untrusted connected apps.
Sign out all sessions: Sign out all other devices/sessions to remove the attacker's access.
Limiting the Damage
A compromised account can have wider effects:
Secure related accounts: If you reused the password, change it on other accounts. If your email was compromised, secure other accounts it can reset, since email is the key to them.
Watch for fraud and misuse: Monitor for unauthorized activity, especially on financial accounts, and address any fraud.
Warn your contacts: If the account was used to message your contacts (with spam or scams), warn them.
Check for data access: Consider what information the attacker may have accessed, and take appropriate steps.
Reporting the Compromise
Reporting helps you and others:
Report to the service: Report the compromise to the service, which can help with recovery and securing the account.
Report fraud to authorities: If there was fraud or financial loss, report to relevant authorities and financial institutions.
Document it: Keep records of the compromise and your actions.
Preventing Future Compromise
After recovering, prevent it from happening again:
Use strong, unique passwords: A unique password for every account (a password manager helps), defeating credential stuffing.
Enable 2FA everywhere important: 2FA blocks takeover even if a password is stolen.
Secure your email especially: Since email can reset other accounts, secure it strongly.
Beware phishing: Log in directly, and be cautious with credential requests.
Keep devices secure: Keep devices malware-free, since malware can steal credentials.
Frequently Asked Questions
How do I recover an account I'm locked out of?
Use the service's account recovery process — most services have a "forgot password" or dedicated "hacked/compromised account" recovery flow. Recovery typically uses your recovery email, phone, or identity verification, so follow the service's process to verify your identity and regain access. Act promptly to limit the attacker's time with your account. Once you regain access, immediately secure the account: change to a new strong password, enable 2FA, fix recovery options the attacker may have changed, remove unauthorized changes (including email forwarding rules), revoke unfamiliar connected apps, and sign out all other sessions.
After recovering my account, how do I make sure the attacker is locked out?
Thoroughly secure the account: change to a new, strong, unique password and enable 2FA (which blocks the attacker even if they know the old password). Critically, fix recovery options (email, phone, security settings) the attacker may have changed to maintain access, remove unauthorized changes — especially email forwarding rules attackers set up to secretly copy your emails — revoke access for unfamiliar connected apps, and sign out all other sessions/devices to remove any active access. Checking and undoing the attacker's changes to recovery options, forwarding rules, and connected apps is essential, since attackers use these to regain access even after a password change.
My email was hacked — what else do I need to secure?
Since your email is the key to your other accounts (password resets go through it), securing other accounts is essential after your email is compromised. After recovering and securing your email (new password, 2FA, fixed recovery options, removed forwarding rules, revoked connected apps, signed-out sessions), secure the other accounts your email can reset — especially important ones like financial accounts — by changing their passwords and enabling 2FA, since the attacker may have used your email to access them. Also watch for fraud, warn your contacts if your email sent spam or scams, and consider what information the attacker may have accessed in your email.
Conclusion
When an online account is compromised, recovering it methodically helps you regain control, secure it, and limit the damage. First, regain access: log in and secure the account immediately if you still can, or use the service's account recovery or "hacked account" process if locked out, acting promptly. Once you have access, secure the account thoroughly: change to a new strong password, enable 2FA, fix recovery options the attacker may have changed, remove unauthorized changes (especially email forwarding rules), revoke unfamiliar connected apps, and sign out all sessions. Limit the damage by securing related accounts (especially if you reused the password or your email was compromised), watching for fraud, warning your contacts, and checking what data was accessed. Report the compromise to the service and, for fraud, to authorities. Finally, prevent future compromise with strong, unique passwords, 2FA on important accounts, a strongly secured email, phishing caution, and secure devices. By following this process — regaining access, securing the account thoroughly, limiting the damage, reporting, and preventing recurrence — you can recover a compromised account and protect your accounts going forward.