What to do if…
you get an alert that an unknown passkey was added to your account
Short answer
Treat the alert as possible unauthorised access. Go directly to the service’s official app or website, remove any passkey you do not recognise, then sign out other sessions and secure the linked email account.
Do not do these things
- Don’t tap links in the alert email, text, or push notification to “fix it”; open the official app or type the web address yourself.
- Don’t assume passkeys make account takeover impossible; account security settings can still be changed if someone else gets in.
- Don’t delete the alert before checking the time, device, location, or account named in it.
- Don’t send messages, make payments, or change non-security settings from the account until you have checked the security settings.
- Don’t reuse an old password if the service asks you to set a new one.
What to do now
-
Open the account without using the alert link.
Use the official app, a saved bookmark you already trust, or type the website address yourself. Go to the account’s Security, Sign-in, Passkeys, or Devices area. -
Remove any passkey you do not recognise.
Look for the newest passkey, unfamiliar device name, unknown browser, or location that does not fit. Remove it if the account lets you. -
Sign out other sessions and devices.
Use options such as Sign out of all devices, Log out of other sessions, or Manage devices. End anything unfamiliar. -
Secure the email account linked to this account.
If that email can reset the account password, check the email account now. Look for unfamiliar passkeys, recovery email addresses, phone numbers, trusted devices, recent sign-ins, forwarding rules, filters, or rules that hide security emails. -
Change the password if the account still uses one.
Use a strong, unique password. If you cannot change it, or the account refuses your usual login, use the provider’s official account recovery page. -
Check for other hidden access.
Look for unfamiliar authorised apps, app passwords, tokens, linked accounts, backup codes, recovery options, or login approvals. Remove anything you did not set up. -
Check recent account activity.
Look for messages sent, orders placed, payment details changed, files shared, or security settings changed around the time of the alert. -
If it is a work or school account, contact IT or security now.
Use your organisation’s normal internal channel, not a reply to the alert. Ask them to review sign-in logs, remove unfamiliar passkeys, and force sign-out if needed. -
If the account can move money, reduce the risk immediately.
For banking, cards, shopping, payment, or crypto accounts, use any official in-app freeze or lock feature if available. Then contact the provider using its official website, app, or the number on the back of your card, and check recent transactions. -
Report fraud or cyber crime if money is missing, you are locked out, or there is ongoing unauthorised activity.
In England, Wales, and Northern Ireland, use Report Fraud. In Scotland, contact Police Scotland by calling 101 for non-emergencies.
What can wait
- You do not need to work out exactly how someone got in before you secure the account.
- You do not need to wipe devices or reinstall apps immediately unless there are clear signs of malware or repeated re-compromise.
- You do not need to close the account today if you can regain control and remove the unfamiliar access.
- You can report a suspicious email or text after the account is secure, unless money is missing, you are locked out, or unauthorised activity is still happening.
Important reassurance
This alert is worrying, but it can also give you a chance to stop the problem early. Removing the unfamiliar passkey, signing out other sessions, and securing the linked email account can cut off access quickly.
Scope note
These are first steps only, to help you regain control and reduce immediate harm. Later decisions, such as recovery disputes, fraud reports, workplace investigations, or device checks, may need help from the account provider, your bank, your organisation, or a cyber security professional.
Important note
This is general information for urgent first actions, not legal, financial, technical, therapeutic, or professional advice. Follow the official recovery process for the account provider, and use official UK reporting routes if fraud or cyber crime has occurred.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.