PanicStation.org
us Technology & digital loss

What to do if…
an account’s identity, security, or recovery details are changed without your permission

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Go directly to the provider’s official app or known website and start its account-recovery or security process. From a device you trust, change the password, restore recovery details you control, and end other active sessions.

Do not do these things

  • Do not use links, login pages, or phone numbers in an unexpected account-change message.
  • Do not share your password, verification codes, backup codes, or recovery links with anyone.
  • Do not approve a sign-in or security prompt you did not initiate.
  • Do not use sponsored search results to find account recovery or customer support.
  • Do not remove a recovery method you still control until another method you control is active, unless the provider’s recovery process requires it.
  • Do not pay or give account access to someone who contacts you and promises guaranteed recovery.
  • Do not delete security alerts or records of unauthorized activity while securing the account.

What to do now

  1. Open the provider’s official app or use a bookmark or web address you already know is genuine. For a work or school account, contact the organization’s IT or security team through a known internal route.
  2. If you clicked an unexpected link or opened an attachment, update the device’s security software and run a scan. Use another trusted device for recovery if you are concerned that the first device may be compromised.
  3. Save copies or screenshots of the change notifications and note which details changed. Do not reply to the messages or use their links.
  4. If you can sign in, change the password to a strong password used only for this account. Correct the name, email address, phone number, recovery information, and authentication methods, and remove anything you do not recognize.
  5. Use the provider’s option to sign out of all devices or end other sessions. Then enable multi-factor authentication with a method you control and replace backup codes if the provider offers that option.
  6. If you cannot sign in, use the provider’s official hacked-account or account-recovery process. Follow the provider’s identity checks rather than working with someone who contacts you unexpectedly.
  7. Secure the email account that receives password-reset messages. Change its password, check its recovery details and forwarding rules, end unfamiliar sessions, and enable multi-factor authentication.
  8. Review the affected account for other changes. Check recent sign-ins, devices, messages, posts, forwarding rules, purchases, payment details, payroll details, and other activity relevant to that account.
  9. If the old password was used on another account, change it there too. Start with email, banking, payment, password-manager, mobile-carrier, work, and social media accounts.
  10. If money, payment details, or direct-deposit information may be affected, contact the financial institution or employer promptly through its official app, website, statement, payment card, or known internal contact. Report transactions or changes you did not authorize.
  11. If your personal information may have been used, visit IdentityTheft.gov for a recovery plan. Cyber-enabled fraud can also be reported to the FBI’s Internet Crime Complaint Center.
  12. If the account sent messages, links, or payment requests without your permission, warn affected contacts through another communication method and tell them not to act on those messages.

What can wait

You do not need to identify who made the changes, reconstruct every event, replace every device, close the account, or make a public announcement now. A full review of older activity and decisions about continuing to use the service can wait until access and recovery details are under your control.

Important reassurance

Unauthorized changes are a warning that the account may have been accessed, but they do not by themselves show that every connected account is compromised. Using the provider’s official recovery process, securing the connected email account, and replacing reused credentials can reduce further access.

Scope note

This guide covers immediate account-recovery and damage-limitation steps only. Later decisions may require help from the provider, an employer’s security team, a financial institution, an identity-theft recovery service, or a qualified cybersecurity professional.

Important note

This is general information, not legal, financial, cybersecurity, or other professional advice. Account-recovery procedures vary, so follow instructions shown in the provider’s official app or website and use verified contact routes.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us