Clear, practical technology insights
Act promptly35 minute route

An account may be compromised

Contain unauthorized access from a trusted device, protect the email and recovery chain, revoke attacker sessions and document what changed.

Quick answer

The safest way to start

Use a trusted device to secure the primary email account first, revoke unknown sessions and rotate credentials in dependency order.

Quick answer

Use a trusted device to secure the primary email account first, revoke unknown sessions and rotate credentials in dependency order.

Best first action

From a trusted device, change the email password, enable strong MFA and verify recovery methods before changing dependent services.

What not to do

Do not change passwords from a device that may still be infected or ignore the primary email account that can reset other services.

When to stop

Contact the service, bank, employer or law enforcement promptly when money moved, identity documents were exposed, business systems were accessed or the recovery information was replaced.

Expected result

Recovery email, phone, MFA and passwords are controlled by you.

1 · Triage

Quick checks before changing anything

Use these checks to narrow the problem and avoid applying an unrelated fix.

Identify evidence of compromise

Look for unfamiliar sign-ins, changed recovery details, sent messages, purchases, forwarding rules or MFA prompts you did not initiate.

Check whether the device is trustworthy

If the device may contain malware or remote-access software, use another updated device before changing credentials.

Determine the account’s reach

A compromised email or password manager can reset many services, while a single low-impact account may have a narrower scope.

2 · Stabilize

Safe first actions

Mark actions as you complete them. Progress is stored only in this browser.

3 · Diagnose and resolve

Step-by-step route

Continue only when the result of the current step supports the next one.

  1. 1

    Contain access

    Use official account recovery, trusted devices and known URLs rather than links in security-alert messages.

    Expected resultThe attacker loses active sessions and recovery control.
  2. 2

    Replace exposed credentials

    Change reused passwords across affected services, starting with email and password manager.

    Expected resultA stolen credential cannot be reused elsewhere.
  3. 3

    Check devices and payment impact

    Scan devices, remove remote-access tools and review transactions or identity exposure.

    Expected resultThe source and financial consequences are addressed.
  4. 4

    Notify and monitor

    Warn contacts about fraudulent messages, report unauthorized transactions and watch sign-in alerts.

    Expected resultSecondary victims and repeated access are reduced.

Stop and escalate when

  • Contact the service, bank, employer or law enforcement promptly when money moved, identity documents were exposed, business systems were accessed or the recovery information was replaced.
4 · Verify

How to know the problem is resolved

  • Recovery email, phone, MFA and passwords are controlled by you.
  • Unknown sessions, forwarding rules and connected applications are removed.
  • Affected devices and financial activity have been reviewed.
5 · Build the skill

Recommended learning route

Open these lessons in order when you need more detail or want to prevent the issue from returning.

Lesson 1

Respond to a suspected compromise

Use a clean device, change credentials, revoke sessions and review account activity.

Online Security · Backup and Incident Response
Lesson 2

Prepare account recovery

Update recovery email, phone and backup codes for important accounts.

Online Security · Backup and Incident Response
Lesson 3

Use built-in malware protection

Review protection status and scan suspicious files without installing multiple conflicting tools.

Online Security · Protect Your Devices
Lesson 4

Set up a password manager

Store and generate passwords while protecting the main vault account.

Online Security · Secure Your Accounts
6 · Practice and reference

TipsMake tools and guides

Related routes

Continue with a connected problem

Common questions

FAQ

Should I change the password on the possibly infected device?

Use another trusted, updated device when possible. Changing a password on a device with malware or remote access can immediately expose the new credential.

Why secure email before other accounts?

Email commonly receives password-reset links and security alerts. If an attacker controls it, changes to other accounts can be reversed or intercepted.