Start From A Device And Route You Trust
If possible, use a familiar device, browser, and location that the service already recognizes. Before entering new credentials, update the device, scan it with trusted security tools, and remove unknown extensions or remote-access software. If the original device may be infected, use another known-clean device for recovery while preserving the suspect device for professional help.
Open the service through a saved bookmark, known address, or official application. Do not use recovery links, phone numbers, or support accounts sent in an unexpected message. Scammers advertise paid recovery services and impersonate staff; legitimate providers do not need your password or verification code.
Record the timeline: last known good access, alerts, changed details, messages sent, purchases, and devices observed. Capture screenshots without exposing secrets. If the account controls work systems, finances, health information, or other people’s data, notify the appropriate organization immediately.
Regain Control Through The Provider’s Official Process
If you can still sign in safely, change the password to a unique generated value and protect the session. If you cannot, use the provider’s account-recovery page. Google, for example, recommends answering recovery questions from a familiar device and location. Provide accurate information and avoid repeated random attempts that may complicate risk checks.
Secure the primary email account first when it can reset the compromised service. Also protect the password manager, mobile carrier account, and any identity provider used for “Sign in with” access. If the old password was reused, assume every reuse is exposed and change those accounts from highest impact downward.
Use the model in Passwords Are a System, Not a Memory Test to create unique credentials and enroll stronger MFA or passkeys. Save fresh recovery codes securely and invalidate old ones.
Remove The Attacker’s Ways Back In
Review active sessions and devices, then sign out unfamiliar ones—or all other sessions when the service supports it. Revocation matters because changing a password does not always invalidate every existing token. CISA guidance includes revoking or reissuing compromised session tokens as an eviction measure.
Inspect recovery email, phone, security questions, passkeys, MFA devices, API keys, application passwords, OAuth grants, delegates, and connected apps. Remove anything you did not establish. In email, check forwarding addresses, filters, rules, blocked senders, signatures, and automatic replies; an attacker may preserve access to messages without an obvious login.
Review recent security events, profile changes, sent and deleted items, cloud-file sharing, and marketplace purchases. Save evidence before deleting malicious rules where investigation or reimbursement may be required. If the attacker added encryption or recovery keys, replace them according to provider guidance.
| Recovery step | Why order matters | Verify |
|---|---|---|
| Use a trusted device | A compromised device can steal the new secret | Updates, scans, extensions |
| Secure primary email | It resets other accounts | Password, MFA, recovery methods |
| Revoke sessions | Tokens may survive password change | Active-device list |
| Remove persistence | Rules and app grants provide alternate access | Forwarding, OAuth, keys |
| Inspect downstream harm | The identity may have reached other services | Transactions, messages, shared data |
Protect People And Services The Account Could Reach
Warn contacts if the account sent messages, payment requests, or malicious links. Use another channel for high-risk recipients. Do not forward the dangerous link while warning them. The response method in the phishing guide helps them verify without repeating the compromise.
Review financial transactions, stored payment methods, account credits, ad campaigns, cloud resources, subscriptions, and orders. Contact banks or providers through official channels about unauthorized activity. If identity documents or sensitive personal information were exposed, follow local identity-theft reporting and monitoring guidance.
Check accounts that receive password resets at the compromised email and accounts that used the same credential. Rotate API keys and application secrets if a developer or business account was affected. For organization-managed identities, administrators may need to reset tokens, review logs, and contain devices.
If files were altered or deleted, preserve versions and restore from a known point. A broader malware or ransomware event requires the isolated recovery approach in ransomware-resilient backups.
Rebuild The Account So The Same Path Fails Next Time
Identify the most likely entry route without blaming the victim: reused password, phishing, malicious extension, stolen session, weak recovery, shared device, or support manipulation. Close that path and document remaining uncertainty. Update all relevant devices and applications through the controlled patch routine.
Enable sign-in alerts, review sessions periodically, store backup codes safely, and register a second trusted authenticator. Remove dormant connected apps and accounts. Keep recovery contacts current and make sure they are protected independently.
For a business incident, retain logs and run a structured review with owned actions. For a personal account, keep a concise recovery inventory so the next device loss or alert is not improvised. Recovery is finished when access is clean, connected harm is addressed, and the original route no longer works.
Common Account-Recovery Questions
Is Changing The Password Enough?
No. Revoke sessions and inspect recovery methods, MFA devices, forwarding, app grants, and connected accounts.
Should I Pay An Account-Recovery Service?
Avoid services claiming special access. Use the provider’s official recovery process and never share passwords or verification codes.
Why Use A Familiar Device And Location?
Providers may use established device and location signals to evaluate a recovery attempt, improving the chance of verifying the legitimate owner.




