ScamsIdentity theftHacked email or social account? The recovery steps, in order
High

Hacked email or social account? The recovery steps, in order

Locked out, or watching a stranger post as you? An account takeover spreads fast — to your contacts, your other logins, your money. Here is the recovery sequence in order: regain access, kick the intruder out, lock the door, and report.

Sources checked:FTCCISA

An account takeover doesn’t stay put. The moment someone controls your email or a social account, they can reach your contacts, reset your other logins, and impersonate you to the people who trust you. So speed and order matter. Here’s the recovery sequence, step by step — drawn straight from FTC and CISA guidance.

1. Regain access

Your first goal is control of the account itself.

  • If you can still log in: change the password immediately, the FTC advises — and “if you use similar passwords for other accounts, change them, too.” Reused passwords mean one breach is really several.
  • If you’re locked out: “follow the provider’s account recovery instructions,” the FTC says. Every major email and social platform has a recovery flow for hijacked accounts. Start it from the provider’s official site or app — never from a link in a message.

Then update your recovery information — the backup email and phone number on file — because attackers often change these to keep you out. Getting them back to yours slams that door.

2. Evict the intruder

Regaining the password isn’t the end — a careful attacker leaves ways back in. The FTC says to look for the traces:

  • Email auto-forwarding rules you didn’t create. Hackers add these so a copy of every email you receive quietly flows to them — including password-reset codes. Delete any you don’t recognize.
  • Activity you didn’t do. On social accounts, check “for messages the hacker posted or sent, or for new friends you don’t recognize,” and delete and undo what you find.
  • Sign out everywhere. Use the “log out of all sessions/devices” option, and review the list of connected apps and devices, removing anything unfamiliar.

It’s also worth scanning your device: the FTC recommends updating or installing security software from a company you trust and removing anything flagged, in case malware is what leaked your password.

3. Lock the door so they can’t return

This is the step that turns a one-time scare into lasting protection — Lock the Front Door. Turn on multifactor authentication (MFA) on the account and your other important logins. CISA’s number is striking: “the use of MFA on your accounts makes you 99% less likely to be hacked.” Stronger still, CISA recommends phishing-resistant options — an authenticator app, or best of all a physical security key. With MFA on, a stolen password by itself is no longer enough to get in.

Be aware that if your second factor is a text-message code, a SIM-swap attack can intercept it — which is why an app or a security key is safer. And never read a login code back to anyone: that’s its own verification-code scam.

4. Report and clean up the fallout

Tell your contacts the account was compromised so they ignore any scammy messages sent in your name. And if you believe personal information was exposed, the FTC points you to IdentityTheft.gov to “report it and get a personalized recovery plan” — the same Freeze & Report step used after any identity incident. If the breach started with a leaked password from somewhere else, our guide on what to do after a data breach covers the wider cleanup.

For more, see the named defense moves or test your eye on the 60-second quiz.

Warning signs
  • You're suddenly locked out, or your password no longer works and your recovery email/phone was changed.
  • Contacts receive messages you didn't send, or your profile posts things you didn't write.
  • You get alerts about logins, password changes, or new devices you don't recognize.
Defense move — Lock the Front Door
  • If you can still log in, change the password now — and change it anywhere you reused it. If you can't, use the provider's account-recovery flow.
  • Kick the intruder out: check for email auto-forwarding rules you didn't set, unfamiliar "new friends," and posts or messages sent as you.
  • Turn on multifactor authentication — ideally an authenticator app or a security key. CISA says MFA makes you 99% less likely to be hacked.
  • If personal information was exposed, get a recovery plan at IdentityTheft.gov.
Editor's note

The thing people underestimate is how fast one hacked account becomes five. Your email is the master key — it’s where every other account sends its ’reset your password‘ link — so an intruder in your inbox is really an intruder reaching for your bank, your social media, your everything. That’s why the order matters: regain the email first, evict them, then bolt on MFA. And the unglamorous prevention truth is the strongest one I know in this whole field: turning on multifactor authentication does more to protect you than almost anything else you can do in five minutes.

Frequently asked

I can still log in. What do I do first?

Move fast while you have access. The FTC says to "change your account password" right away — and "if you use similar passwords for other accounts, change them, too." Then "update your account recovery information," making sure the email address and phone number on file are yours and correct, since attackers often change these to lock you out. Getting your recovery details back under your control is what stops them from simply walking back in.

The hacker changed my password and I'm locked out. Is it lost?

No. The FTC's guidance is to "follow the provider's account recovery instructions" — every major email and social platform has a dedicated account-recovery flow for exactly this. Start it from the provider's real site or app (not a link someone sends you). Be ready to verify your identity; it can take time, but locked-out accounts are routinely recovered.

I got back in — how do I make sure they're really gone?

Hunt for what they left behind. The FTC warns to check for "auto-forwarding rules in your email account that you didn't set up," which secretly copy your mail to the attacker, and to check social media "for messages the hacker posted or sent, or for new friends you don't recognize." Also sign out all devices/sessions, and scan your device with security software. Then turn on MFA so a stolen password alone can't get them back in.

RY
Ryon — Founder & Editor
Consumer-safety advocate · Scamblare

Scamblare researches scams every day so you don't have to. Every article is checked, claim by claim, against primary sources like the FTC and FBI IC3 under our published editorial standard. How we fact-check ›