An account takeover is when someone else gets into an account and, often, locks you out. It feels alarming, but there is a calm order to getting back in and limiting the damage.
How it happens
Usually it starts with a password that leaked in a breach or was reused, or one you typed on a fake page. Once in, the attacker may change your password and recovery details so you cannot easily return.
Warning signs
- Your password suddenly no longer works, with no reset you requested
- Messages, posts, or emails sent from your account that you did not write
- Login alerts or new-device notifications from places you have never been
- Your recovery email or phone number has been changed
A calm recovery order
Work through this in order. Fixing your email first matters, because it can reset the others.
- Regain your email account first. Use the service’s account-recovery or « forgot password » flow. This is your master key, so get it back before anything else.
- Change reused passwords. Any other account that shared that password is now also at risk. Give each a new, unique password.
- Turn on two-factor authentication (a second proof after your password) on the recovered accounts, so a stolen password alone cannot get back in.
- Check recovery details and sessions. Reset your recovery email and phone to your own, and sign out all other devices.
- Warn your contacts. Let people know the account was compromised, so they ignore any odd messages or money requests sent in your name.
Act now. If a bank or payment account is involved, contact the provider directly using the number on your card or their official app, not any number sent to you in a message.
Once you are back in and 2FA is on, the same account is far harder to take over again. The unpleasant part is temporary, and each step you finish shrinks the problem.
Related in this set. Lock Down Your Accounts · Check your accounts for breaches