What to do if…
an account’s identity, security, or recovery details are changed without your permission
Short answer
Treat the account as potentially compromised. Use the provider’s official app or website to secure or recover it, protect the linked email account, and contact your bank immediately if financial details or money may be at risk.
Do not do these things
- Do not use links or telephone numbers in an unexpected change notification.
- Do not approve sign-in prompts or provide security codes you did not request.
- Do not send passwords, recovery codes, identity documents, or one-time codes to someone who contacts you.
- Do not pay anyone claiming they can recover the account.
- Do not delete relevant alerts, emails, or messages before making a basic record.
- Do not assume changing one password protects other accounts where that password was reused.
- Do not confront a suspected person through the affected account.
- Do not delay protecting money at risk while trying to work out who made the changes.
What to do now
-
Open the provider’s official app or type its known website address into your browser. Check the security, account-details, or recent-activity page without following links in the alert.
-
If you can still sign in, change the password to a new, unique password. Check and correct the account name, email address, phone number, recovery methods, two-step verification settings, passkeys, authorised apps, forwarding rules, and trusted devices where those options exist.
-
Use the provider’s option to sign out of other devices or end active sessions. Remove any device, application, passkey, or recovery method you do not recognise.
-
Secure the email account linked to the affected account. Check its password, recovery details, forwarding rules, recent activity, and active sessions. Turn on two-step verification if it is available.
-
If you cannot sign in, use the provider’s official account-recovery or hacked-account process. Follow the instructions on its own website or app rather than using a recovery service offered by a third party.
-
Change any identical or similar password used on another account. Start with email, banking, payment, shopping, cloud-storage, mobile-network, and social-media accounts.
-
Save the change notifications and note what changed, when you noticed it, any unfamiliar activity, and any support reference number. Take screenshots where useful, but do not delay securing the account to collect them.
-
Check for actions taken through the account, such as sent messages, purchases, altered payment methods, deleted files, forwarding rules, new administrators, or public posts. Warn relevant contacts through a separate trusted channel if messages or payment requests may have been sent in your name.
-
Contact your bank or payment provider immediately through its official app, website, the number on your card, or a statement if financial information may have been exposed or you notice an unfamiliar payment.
-
If you have lost money or the account was used for fraud, report it to Report Fraud if you are in England, Wales, or Northern Ireland. In Scotland, contact Police Scotland on 101. Call 999 anywhere in the UK if there is an immediate danger or a crime is happening now.
-
If this is a work, school, or organisation-managed account, contact its IT or security team through a separate trusted route. Tell them which details changed and whether the account was used to access other systems.
-
Install available security updates on devices used for the account. If you installed unfamiliar software or opened a suspicious attachment, use the device’s built-in or trusted security scan before entering new passwords where practical.
What can wait
You do not need to identify who did this, rebuild every account, replace every device, contact every organisation, or decide whether to close the account now. First regain control, secure the linked email account, protect any money at risk, and record the basic facts.
Important reassurance
Changed security or recovery details do not necessarily mean every account or device you use has been accessed. Securing the affected account, protecting the linked email account, ending unknown sessions, and replacing reused passwords can limit the immediate risk.
Scope note
This guide covers immediate first steps after unauthorised identity, security, or recovery changes. Later decisions about data loss, identity fraud, complaints, financial recovery, employment systems, or legal action may require help from the provider or an appropriate specialist.
Important note
This is general information, not legal, financial, cybersecurity, or other professional advice. Account-recovery options differ between providers, so follow the current instructions in the provider’s official app, website, or support pages.
Additional Resources
- National Cyber Security Centre — Recovering a hacked account
- National Cyber Security Centre — Top tips for staying secure online
- National Cyber Security Centre — Phishing scams: how to spot and report them
- Stop! Think Fraud — What to do if you’ve been hacked - Stop! Think Fraud GOV.UK
- Stop! Think Fraud — What to do if you’ve shared personal information - Stop! Think Fraud GOV.UK
- Police.uk
- Police.uk — How to report
- Information Commissioner's Office — Identity theft
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.