PanicStation.org
uk Technology & digital loss

What to do if…
you get a notice that your two-factor authentication method was changed without your permission

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Treat this as a possible account takeover in progress. Open the service directly, not through the alert link, then try to regain control, sign out other sessions, and check every recovery option.

Do not do these things

  • Don’t click “review change” links in the alert email or text if you are even slightly unsure it is genuine.
  • Don’t enter your password into the alert link, a pop-up prompt, or a support page reached from a message.
  • Don’t delay because you are not sure it is serious enough; a changed 2FA method can be used to lock you out.
  • Don’t reuse an old password or a password you use anywhere else.
  • Don’t ignore your email account; if someone controls your email, they may be able to reset other accounts.
  • Don’t pay anyone who contacts you claiming they can recover the account for you.

What to do now

  1. Use a safer login route: Open the service by typing the address yourself, using a saved bookmark, or using the official app. Go to Security, Account, Login, 2-step verification, Two-factor authentication, or Account recovery.
  2. Try to regain control immediately:
    • If you can still log in, change the password to a long, unique one.
    • If you cannot log in, use the provider’s official recovery flow, such as I can’t access my account, Secure my account, or Recover account.
  3. Sign out other access: In account security, use sign out of all devices, log out all sessions, or the closest option. Remove any unknown devices, trusted browsers, connected apps, or app passwords you did not approve.
  4. Put your own 2FA back in place: Restore the second factor to something you control. Use an authenticator app, passkey, or security key where the service offers it. If you must use text messages, make sure the phone number is yours.
  5. Replace recovery routes: Check recovery email addresses, phone numbers, backup codes, recovery keys, and security questions. Remove anything you do not recognise, generate new backup codes, and store them somewhere safe.
  6. Check your email account: If the affected account is your email, check for forwarding, filters, rules, delegated access, and recovery details you did not set. If the affected account is not your email, secure your main email next because it can be used to reset other accounts.
  7. Check for a possible SIM swap: If a new phone number appeared, your mobile signal stopped unexpectedly, or you received SIM-change messages, contact your mobile network through its official number or app. Ask whether there has been an unauthorised SIM swap, number transfer, or account-security change.
  8. Make a brief record if safe and quick: Note the service name, the time of the alert, what changed, and any device or location details shown. Take a screenshot if it is easy, but do not let this slow down securing the account.
  9. Report fraud or immediate danger through the right route: If money was taken, purchases were made, or you were scammed, use Report Fraud if you live in England, Wales, or Northern Ireland. If you live in Scotland, or the crime happened there, contact Police Scotland on 101 for non-emergencies. If there is immediate danger or a crime is happening now, call 999.

What can wait

  • You do not need to work out how it happened right now.
  • You do not need to message everyone immediately; first stop the takeover and secure your email.
  • You do not need to perfect your security setup today. Once you are back in, you can decide whether to upgrade to passkeys, security keys, or a password manager.
  • You do not need to argue with the attacker or reply to suspicious messages.

Important reassurance

This situation can make you feel rushed, especially if the alert looks urgent. The safest first move is usually to slow down, open the service directly, secure access, remove unknown recovery options, and then decide what else needs reporting.

Scope note

These are first steps to regain control and reduce immediate harm. If the account is business-critical, tied to banking, or still cannot be recovered, later decisions may need specialist help from the provider, your bank, your mobile network, or official reporting routes.

Important note

This is general information, not legal, medical, financial, therapeutic, technical, or other professional advice. Processes differ by provider and can change. Use only the service’s official recovery or support channels, and be cautious with anyone claiming they can recover the account for you.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us