The first thirty minutes
- Use the provider's account-recovery page from a device you trust. Google, Apple, Microsoft, Meta and X all have a dedicated "I can't sign in" flow.
- Once in, change the password, then check recovery email and phone, forwarding rules, connected apps and active sessions. Attackers add their own.
- Turn on two-factor authentication with an authenticator app or a security key, not SMS if you can avoid it.
- Warn your contacts by another channel that messages from the account may be fraudulent.
The next day
- Change the password on every other account that used the same password. Assume the attacker tried them.
- If it was your email, check the accounts that reset via that email (bank, shopping, cloud) for changes.
- Review sent mail and deleted mail for what the attacker did while inside.
Keep this evidence
- Screenshots of unfamiliar sessions, devices and forwarding rules before you remove them.
- The security alerts the provider sent, with timestamps.
Do not
- Do not pay anyone offering to "recover" the account; recovery is free through the provider.
- Do not reuse the old password anywhere.
Who to report to
The provider's recovery flow. Report to police if money was lost or impersonation continues. Find the numbers and portals for your country in the reporting directory.
General guidance, not legal advice. If someone is in immediate danger, call your police emergency number.