# What to Do After an Online Account Is Hacked

Source: https://urbanx.co.za/knowledge-hub/digital-safety-privacy-account-protection/what-to-do-account-hacked

**Answer:** Secure the email or identity account that controls recovery, then use the affected platform’s official recovery page from a trusted device. Change exposed and reused passwords, remove unknown sessions and linked access, repair MFA and recovery details, review payments and messages, and warn affected contacts. Preserve evidence before it disappears.

Part of [Digital Safety, Privacy & Account Protection](https://urbanx.co.za/knowledge-hub/digital-safety-privacy-account-protection) · 12 min read · by UrbanX Knowledge Hub

**Last reviewed: 26 August 2026 · 12 min read**

### First decide whether access is still available

#### You can still sign in

Use the account’s security settings immediately. Do not wait for the attacker to change recovery details.

#### You cannot sign in

Go directly to the platform’s official recovery page. Do not pay a social-media “recovery expert” or give codes to someone claiming private access to platform staff.

#### The email account is also compromised

Recover or secure email first where possible. Email often receives password resets and security alerts for other services.

#### Money or physical safety is at risk

Contact the bank, payment provider or appropriate emergency/law-enforcement service immediately. Account recovery can continue after urgent harm is contained.

### Step 1: Use a trusted device and route

A device may be involved if it contains malware, a malicious extension or unauthorised remote-access software.

Where possible:

- use another updated device;
- type the platform address or use the genuine app;
- avoid links in the suspicious alert;
- do not install tools offered by a stranger; and
- preserve the original message and URL.

If remote control is active, disconnect the affected device from the network and protect priority accounts elsewhere.

### Step 2: Protect the recovery root

Secure the primary email, mobile number and device ecosystem used for recovery.

For email:

- change the password;
- sign out unknown sessions;
- review recovery email and phone;
- inspect forwarding rules, filters and delegates;
- remove unknown app passwords and third-party access;
- enable strong MFA; and
- check sent, deleted and archived folders.

An attacker may create a hidden forwarding rule to regain information after the visible password changes.

### Step 3: Recover through the platform

Follow the official process and provide accurate evidence. Platforms may use:

- prior passwords;
- familiar devices and locations;
- account-creation information;
- recovery email or phone;
- transaction receipts;
- identity verification; and
- linked-platform history.

Google’s official guidance recommends answering recovery questions as accurately as possible and using a familiar device, browser and location where available. Other platforms use their own methods.

Do not repeatedly guess in ways that trigger longer delays. Keep all case references.

### Step 4: Remove the attacker’s persistence

After regaining access:

1. Change the password to a unique generated one.
2. End all other sessions where possible.
3. Remove unknown devices.
4. Revoke unfamiliar apps, tokens and connected services.
5. Delete unauthorised forwarding rules or delegates.
6. Restore recovery information.
7. Replace backup codes.
8. Add strong MFA or a passkey.
9. Review profile and privacy changes.
10. Check that no secondary administrator was added.

Changing the password alone may not revoke every existing session or application token.

### Step 5: Contain password reuse

If the compromised password was used elsewhere, change those accounts in this order:

- primary email;
- password manager;
- banking and payments;
- mobile-network and device accounts;
- cloud storage;
- work or school accounts;
- social and messaging;
- gaming and shopping.

Use a password manager to replace reuse with unique credentials.

### Step 6: Assess what the attacker did

Check:

- recent logins;
- sent messages and posts;
- archived or deleted mail;
- password-reset messages;
- purchases, refunds and stored cards;
- new beneficiaries or payment destinations;
- downloaded or shared files;
- changed privacy settings;
- linked accounts; and
- copied identity or recovery information.

Document dates, device locations as displayed, transaction IDs and case references. Avoid deleting evidence before recording it.

### Step 7: Warn affected people

If the account sent messages, tell contacts through another trusted channel. Keep the warning simple:

> My account was compromised between [time] and [time]. Do not trust links, payment requests or codes sent during that period. I will confirm any genuine request through this channel.

Do not forward the malicious link.

### Step 8: Handle payments and identity exposure

For unauthorised payment activity, contact the bank or provider immediately using a known fraud channel. Preserve statements and transaction references.

If ID documents, addresses, tax information or phone-account data were exposed, assess risks beyond the platform. [What to Do If Your Personal Data Appears in a Breach](/knowledge-hub/digital-safety-privacy-account-protection/personal-data-breach-response) explains data-specific actions.

Where online fraud, threats, identity theft or another crime occurred, use current South African reporting guidance. SAPS advises reporting relevant computer crime, identity theft and commercial scams at a police station.

### Step 9: Check the device

Account compromise can occur through phishing without device malware, but inspect the device when:

- unknown software was installed;
- remote access was granted;
- browser extensions changed;
- security tools were disabled;
- repeated compromise continues after password changes; or
- files or credentials behave unexpectedly.

Update the operating system and security tools, remove unauthorised software and seek trusted technical help. Avoid making the article a network-firewall guide; the priority is endpoint trust and account recovery.

### What not to do

- Do not pay an unofficial recovery service.
- Do not share recovery codes with anyone.
- Do not use the same compromised device for every recovery step if remote access remains possible.
- Do not delete messages before preserving evidence.
- Do not assume a changed password ended all sessions.
- Do not retaliate or attempt to access the attacker’s accounts.
- Do not publicly post identity documents or case evidence.

### Sources

- [Google: Secure a Hacked or Compromised Account](https://support.google.com/accounts/answer/6294825)
- [Google: Tips to Complete Account Recovery](https://support.google.com/accounts/answer/7299973)
- [FTC: Protect Personal Information From Hackers and Scammers](https://consumer.ftc.gov/articles/protect-your-personal-information-hackers-and-scammers)
- [FTC: What to Do If You Were Scammed](https://consumer.ftc.gov/articles/what-do-if-you-were-scammed)
- [SAPS Cybercrime Prevention Tips](https://www.saps.gov.za/alert/cybercrime_prev_tips.php)
- [ISPA: How to Report Online Crime in South Africa](https://ispa.org.za/consumer-support/how-to-report-online-crime/)

### Related guides

- [All Digital Safety, Privacy & Account Protection guides](/knowledge-hub/digital-safety-privacy-account-protection)
- [How Multi-Factor Authentication Protects Online Accounts](/knowledge-hub/digital-safety-privacy-account-protection/multi-factor-authentication-account-protection)
- [Gaming Account Takeovers: Recovery Steps](/knowledge-hub/digital-safety-privacy-account-protection/gaming-account-takeover-recovery)
- [What to Do If Your Personal Data Appears in a Breach](/knowledge-hub/digital-safety-privacy-account-protection/personal-data-breach-response)

## Frequently Asked Questions

**Should I change the email password or hacked account first?**

Protect the account that controls recovery first where possible—often the primary email—then secure the affected service.

**Is changing the password enough?**

No. End unknown sessions, remove connected apps, repair recovery details and replace MFA or backup codes.

**Can someone recover my account for a fee?**

Use only the platform’s official recovery process and verified support. Unofficial recovery offers are frequently scams.

**Should I delete messages the attacker sent?**

Preserve evidence first. Then follow the platform and investigation process, and warn recipients through another channel.

**What if the attacker used my stored card?**

Contact the bank or card issuer immediately through its official fraud channel, then preserve the platform’s transaction records.
