Use a trusted device to secure the primary email account first, revoke unknown sessions and rotate credentials in dependency order.
An account may be compromised
Contain unauthorized access from a trusted device, protect the email and recovery chain, revoke attacker sessions and document what changed.
The safest way to start
Use a trusted device to secure the primary email account first, revoke unknown sessions and rotate credentials in dependency order.
From a trusted device, change the email password, enable strong MFA and verify recovery methods before changing dependent services.
Do not change passwords from a device that may still be infected or ignore the primary email account that can reset other services.
Contact the service, bank, employer or law enforcement promptly when money moved, identity documents were exposed, business systems were accessed or the recovery information was replaced.
Recovery email, phone, MFA and passwords are controlled by you.
Quick checks before changing anything
Use these checks to narrow the problem and avoid applying an unrelated fix.
Identify evidence of compromise
Look for unfamiliar sign-ins, changed recovery details, sent messages, purchases, forwarding rules or MFA prompts you did not initiate.
Check whether the device is trustworthy
If the device may contain malware or remote-access software, use another updated device before changing credentials.
Determine the account’s reach
A compromised email or password manager can reset many services, while a single low-impact account may have a narrower scope.
Safe first actions
Mark actions as you complete them. Progress is stored only in this browser.
Step-by-step route
Continue only when the result of the current step supports the next one.
- 1
Contain access
Use official account recovery, trusted devices and known URLs rather than links in security-alert messages.
Expected resultThe attacker loses active sessions and recovery control. - 2
Replace exposed credentials
Change reused passwords across affected services, starting with email and password manager.
Expected resultA stolen credential cannot be reused elsewhere. - 3
Check devices and payment impact
Scan devices, remove remote-access tools and review transactions or identity exposure.
Expected resultThe source and financial consequences are addressed. - 4
Notify and monitor
Warn contacts about fraudulent messages, report unauthorized transactions and watch sign-in alerts.
Expected resultSecondary victims and repeated access are reduced.
Stop and escalate when
- Contact the service, bank, employer or law enforcement promptly when money moved, identity documents were exposed, business systems were accessed or the recovery information was replaced.
How to know the problem is resolved
- Recovery email, phone, MFA and passwords are controlled by you.
- Unknown sessions, forwarding rules and connected applications are removed.
- Affected devices and financial activity have been reviewed.
Recommended learning route
Open these lessons in order when you need more detail or want to prevent the issue from returning.
Respond to a suspected compromise
Use a clean device, change credentials, revoke sessions and review account activity.
Online Security · Backup and Incident ResponsePrepare account recovery
Update recovery email, phone and backup codes for important accounts.
Online Security · Backup and Incident ResponseUse built-in malware protection
Review protection status and scan suspicious files without installing multiple conflicting tools.
Online Security · Protect Your DevicesSet up a password manager
Store and generate passwords while protecting the main vault account.
Online Security · Secure Your AccountsEnable multi-factor authentication
Prefer authenticator apps or security keys and store recovery codes safely.
Online Security · Secure Your AccountsTipsMake tools and guides
Continue with a connected problem
FAQ
Should I change the password on the possibly infected device?
Use another trusted, updated device when possible. Changing a password on a device with malware or remote access can immediately expose the new credential.
Why secure email before other accounts?
Email commonly receives password-reset links and security alerts. If an attacker controls it, changes to other accounts can be reversed or intercepted.