Skip to content
← All guides

Urgent Action

Someone has taken over my account

What to do in the first hour when someone else is inside your email, social or bank account, and how to work out how they got in.

5 min read

If this is happening right now, start with the steps below. The explanations underneath can wait.

The first hour

  1. Move to a device you trust

    If you think a computer might be infected, use a phone, or someone else's device. Changing a password on a compromised machine just hands over the new one.

  2. Change your email password first

    Make it long and unique to that account. If you reuse it anywhere, this will happen again.

  3. Sign out of all other sessions

    Most services have this buried in security settings, worded as "sign out of all devices" or "active sessions". A password change alone does not always end a session someone else already has open.

  4. Turn on two-factor authentication

    An app that generates codes is stronger than SMS, because phone numbers can be moved to another SIM. Save the backup codes somewhere that is not the account itself.

  5. Check what they changed, not just whether you are back in

    Recovery email, recovery phone, forwarding rules, filters, connected apps, and any app passwords. Undo anything you do not recognise.

  6. Then work outwards

    Once email is secure, do the same for anything valuable: bank, then the account that was actually taken, then everything sharing that old password.

Why email comes first

Your inbox is not one account among many. It is the master key. Every "forgot password" link on every other service you use arrives there, which means whoever controls it can reset anything else you own, at any time they choose. Securing your Instagram while someone still reads your email is running up a down escalator.

The setting almost everyone misses

Mail forwarding rules and filters survive a password change. They are a setting on the account, not a session, so resetting your password does nothing to them.

This is the single most common way people get quietly re-compromised weeks later. Someone sets a rule that forwards a copy of everything to an address they control, or one that silently files any email containing the word "security" or "code" straight into archive so you never see the alerts. You get your account back, you feel safe, and they keep reading.

How they probably got in

It matters, because the fix is different for each and the wrong fix leaves the door open.

  • A reused password. It leaked in some unrelated company's breach years ago, and someone tried it against your email. This is by far the most common cause and it has nothing to do with how careful you are.
  • A convincing fake login page. You typed your details into something that looked exactly like the real site.
  • Malware on a device, often an infostealer bundled into pirated software, a game mod, or a cracked download. It reads saved passwords straight out of your browser.
  • A stolen session token. Malware or a malicious browser extension copies the file that says "this person is already signed in".

If you cannot get back in

Every large platform has an account recovery process for exactly this, and it is usually slow, automated and frustrating. Some things that help:

  • Use the official recovery form, reached by typing the company's address into your browser yourself. Never through a link in an email or a search advert.
  • Submit from a device and connection you have used with that account before. It is a signal in your favour.
  • Give the oldest information you can prove: an old password, the month you created the account, an original recovery address.
  • Expect to wait, and expect to submit more than once. Persistence genuinely works here.
I had two-factor authentication switched on. How did they get in?

Most likely they never entered your password. Malware or a malicious browser extension can copy the session token from your browser, which is the piece of data that says you are already signed in and have already passed the two-factor check. Using it needs no code. This is why you should sign out of all sessions rather than only changing your password, and why it is worth scanning the device you normally sign in from.

Should I pay someone who offers to recover my account?

No. Account recovery is handled by the platform itself and is free. Anyone who approaches you offering to do it for money is targeting you precisely because they know you have just been hacked and are willing to try anything.

How long should I keep watching?

Give it a few weeks of light attention. Check your forwarding rules and filters again after a week, since that is the setting people forget. Watch for password reset emails you did not request, because those mean someone still has enough of your details to be trying. If nothing unusual happens in a month, you are almost certainly clear.

One last thing. Being hacked is not evidence that you were careless. The single most common cause is a password that leaked from a company you trusted with it, which was never in your control at all.

Need to report this?

Where to report cyber crime in your country, and where to find support.

Get help

This happened to them too

First-hand accounts from people who went through the same thing.

Related guides