Secure the email or identity account that controls recovery, then use the affected platform’s official recovery page from a trusted device. Change exposed and reused passwords, remove unknown sessions and linked access, repair MFA and recovery details, review payments and messages, and warn affected contacts. Preserve evidence before it disappears.
Last reviewed: 26 August 2026 · 12 min read
First decide whether access is still available
You can still sign in
Use the account’s security settings immediately. Do not wait for the attacker to change recovery details.
You cannot sign in
Go directly to the platform’s official recovery page. Do not pay a social-media “recovery expert” or give codes to someone claiming private access to platform staff.
The email account is also compromised
Recover or secure email first where possible. Email often receives password resets and security alerts for other services.
Money or physical safety is at risk
Contact the bank, payment provider or appropriate emergency/law-enforcement service immediately. Account recovery can continue after urgent harm is contained.
Step 1: Use a trusted device and route
A device may be involved if it contains malware, a malicious extension or unauthorised remote-access software.
Where possible:
- use another updated device;
- type the platform address or use the genuine app;
- avoid links in the suspicious alert;
- do not install tools offered by a stranger; and
- preserve the original message and URL.
If remote control is active, disconnect the affected device from the network and protect priority accounts elsewhere.
Step 2: Protect the recovery root
Secure the primary email, mobile number and device ecosystem used for recovery.
For email:
- change the password;
- sign out unknown sessions;
- review recovery email and phone;
- inspect forwarding rules, filters and delegates;
- remove unknown app passwords and third-party access;
- enable strong MFA; and
- check sent, deleted and archived folders.
An attacker may create a hidden forwarding rule to regain information after the visible password changes.
Step 3: Recover through the platform
Follow the official process and provide accurate evidence. Platforms may use:
- prior passwords;
- familiar devices and locations;
- account-creation information;
- recovery email or phone;
- transaction receipts;
- identity verification; and
- linked-platform history.
Google’s official guidance recommends answering recovery questions as accurately as possible and using a familiar device, browser and location where available. Other platforms use their own methods.
Do not repeatedly guess in ways that trigger longer delays. Keep all case references.
Step 4: Remove the attacker’s persistence
After regaining access:
- Change the password to a unique generated one.
- End all other sessions where possible.
- Remove unknown devices.
- Revoke unfamiliar apps, tokens and connected services.
- Delete unauthorised forwarding rules or delegates.
- Restore recovery information.
- Replace backup codes.
- Add strong MFA or a passkey.
- Review profile and privacy changes.
- Check that no secondary administrator was added.
Changing the password alone may not revoke every existing session or application token.
Step 5: Contain password reuse
If the compromised password was used elsewhere, change those accounts in this order:
- primary email;
- password manager;
- banking and payments;
- mobile-network and device accounts;
- cloud storage;
- work or school accounts;
- social and messaging;
- gaming and shopping.
Use a password manager to replace reuse with unique credentials.
Step 6: Assess what the attacker did
Check:
- recent logins;
- sent messages and posts;
- archived or deleted mail;
- password-reset messages;
- purchases, refunds and stored cards;
- new beneficiaries or payment destinations;
- downloaded or shared files;
- changed privacy settings;
- linked accounts; and
- copied identity or recovery information.
Document dates, device locations as displayed, transaction IDs and case references. Avoid deleting evidence before recording it.
Step 7: Warn affected people
If the account sent messages, tell contacts through another trusted channel. Keep the warning simple:
My account was compromised between [time] and [time]. Do not trust links, payment requests or codes sent during that period. I will confirm any genuine request through this channel.
Do not forward the malicious link.
Step 8: Handle payments and identity exposure
For unauthorised payment activity, contact the bank or provider immediately using a known fraud channel. Preserve statements and transaction references.
If ID documents, addresses, tax information or phone-account data were exposed, assess risks beyond the platform. What to Do If Your Personal Data Appears in a Breach explains data-specific actions.
Where online fraud, threats, identity theft or another crime occurred, use current South African reporting guidance. SAPS advises reporting relevant computer crime, identity theft and commercial scams at a police station.
Step 9: Check the device
Account compromise can occur through phishing without device malware, but inspect the device when:
- unknown software was installed;
- remote access was granted;
- browser extensions changed;
- security tools were disabled;
- repeated compromise continues after password changes; or
- files or credentials behave unexpectedly.
Update the operating system and security tools, remove unauthorised software and seek trusted technical help. Avoid making the article a network-firewall guide; the priority is endpoint trust and account recovery.
What not to do
- Do not pay an unofficial recovery service.
- Do not share recovery codes with anyone.
- Do not use the same compromised device for every recovery step if remote access remains possible.
- Do not delete messages before preserving evidence.
- Do not assume a changed password ended all sessions.
- Do not retaliate or attempt to access the attacker’s accounts.
- Do not publicly post identity documents or case evidence.
Sources
- Google: Secure a Hacked or Compromised Account
- Google: Tips to Complete Account Recovery
- FTC: Protect Personal Information From Hackers and Scammers
- FTC: What to Do If You Were Scammed
- SAPS Cybercrime Prevention Tips
- ISPA: How to Report Online Crime in South Africa
