Blog-Artikel

Hacked? What to Do Next and How to Stop It Happening Again

A practical recovery plan after a hack, including account lockdown, device checks, evidence gathering, and steps to reduce the risk of another breach.

readytools

September 28, 2026

10 Min. Lesezeit

Hacked? What to Do Next and How to Stop It Happening Again

Image source: images.unsplash.com

Teilen

If an account or device has been hacked, the first priority is not finding the attacker. It is stopping further access. Use a device you trust, change the password for the affected account and any account that reused it, sign out other sessions, secure the email account behind it, and turn on multifactor authentication. Then check recovery settings, connected apps, financial activity, and the device itself.

A single password reset may close one door while leaving several others open. A complete recovery treats the incident as a chain: the attacker may have a password, an active session, access to an email inbox, a recovery method, a connected application, or control of the device used to sign in. The steps below help identify and close those paths in a sensible order.

First, decide what kind of compromise occurred

“Hacked” can describe several different situations, and the right response depends on which one occurred. A social account posting messages without permission is different from a stolen email password, a lost phone, or malware on a computer.

  • Account takeover: The password, session, recovery email, phone number, or multifactor method may have been changed or misused.
  • Email compromise: An intruder may be able to reset other passwords, read private messages, or create forwarding rules that hide security alerts.
  • Device compromise: Malware, a malicious browser extension, or an untrusted application may capture credentials even after passwords are changed.
  • Financial or identity fraud: Payment details, identity documents, tax information, or other sensitive records may have been exposed.
  • Phone number takeover: An attacker may have moved a mobile number to another SIM or persuaded a provider to transfer it.

If the exact cause is unclear, assume that the affected account and any reused credentials need attention. Avoid guessing that the problem is fixed simply because the visible symptom has stopped.

What to do immediately after an account is hacked

1. Use a clean device and a trusted connection

If there is any reason to suspect malware on the usual computer or phone, use a different device for the first recovery steps. A trusted device might be a personal phone or computer that is updated, protected with a screen lock, and not shared with someone else.

Do not enter new passwords into a device that may be recording keystrokes or controlling the browser. If no alternative device is available, remove suspicious applications and browser extensions, install pending security updates, and run the security checks provided by the operating system before changing sensitive credentials.

2. Secure the email account first

Email often sits behind password resets for other services. If an email account may be affected, secure it before moving through less critical accounts.

  1. Change the email password to a new, unique password.
  2. Sign out of unfamiliar sessions and devices.
  3. Check the recovery email address and phone number for changes.
  4. Review forwarding rules, filters, delegated access, and automatic replies.
  5. Inspect sent mail, deleted mail, and recent account activity for messages or changes that were not made by the account owner.
  6. Turn on multifactor authentication using an available method that is not controlled by the attacker.

Forwarding rules deserve special attention. An attacker who adds a rule that silently forwards security messages may continue monitoring the account even after the password changes.

3. Change passwords in the right order

Start with the email account, then protect financial services, cloud storage, password managers, work accounts, social networks, and other accounts containing personal information. Use a different password for every important service.

A password manager can create and store unique passwords, but it should also be treated as a high-value account. Secure it with a strong unique master password and multifactor authentication where available. If the password manager itself may have been exposed, follow its account recovery guidance and review the stored credentials that need to be replaced.

Do not reuse a new password on several accounts just because the old one was not reused. Reuse allows one future breach to spread across services.

4. End active sessions and remove unfamiliar devices

Password changes do not always remove every existing login. Open sessions, remembered browsers, mobile applications, and access tokens may remain active depending on the service.

Use the account’s security or device-management page to sign out of other sessions. Remove devices that are unfamiliar or no longer in use. If the service offers a “sign out everywhere” option, use it after changing the password. Review connected applications and revoke access for anything unrecognized, unnecessary, or no longer used.

Pay attention to applications that can read messages, access files, publish content, or manage an account. A legitimate application can retain access even after the main password is changed.

5. Check recovery settings and multifactor authentication

Attackers may change recovery information so they can return later. Confirm that the recovery email, phone number, authenticator app, security keys, backup codes, and trusted devices belong to the account owner.

Multifactor authentication reduces the value of a stolen password, but it is not a guarantee that an account cannot be taken over. Choose a method supported by the service and suitable for the risk. An authenticator app or security key can be preferable to text messages when available, although any additional factor is generally better than relying on a password alone.

Generate new backup codes if there is a possibility that old codes were viewed or copied. Store them somewhere private and accessible during recovery, not in a public note or an unsecured shared document.

Protect money and identity before investigating further

If the compromised account could expose payment information, contact the bank, card issuer, payment service, or other relevant provider using an official app, website, or phone number. Do not use contact details delivered in a suspicious message.

Review recent transactions, saved payment methods, new recipients, transfers, purchases, and changes to account details. Report activity that was not authorized. The provider can explain the available steps for freezing, replacing, or monitoring the affected account.

If identity documents, tax records, health information, or other sensitive data may have been exposed, record what was involved and contact the relevant organization. The correct response depends on the country, service, and type of information. Keep copies of messages, case numbers, and dates so later follow-up does not depend on memory.

Preserve evidence before deleting everything

Evidence can help a service provider understand what happened and can support a dispute or formal report. Save screenshots of suspicious login alerts, changed settings, unauthorized messages, payment activity, device lists, and account-recovery notices. Record approximate times, affected services, and the actions already taken.

Do not forward suspicious messages to other people. Preserve the original message where possible, including its headers or report function, and avoid clicking additional links. If a work account, customer data, or company device is involved, notify the organization’s designated security or support team rather than attempting an independent cleanup that could destroy useful evidence.

Evidence should not delay urgent containment. If money is leaving an account or an attacker is actively using it, secure the account and contact the relevant provider first.

Check the device that was used to sign in

Account recovery is incomplete if the device remains compromised. Check for unfamiliar applications, browser extensions, profiles, remote-access tools, new administrator accounts, and unusual security settings. Remove software that was not intentionally installed, but be careful not to delete information needed for an investigation.

Install operating system, browser, application, and firmware updates from their official update mechanisms. Run the security tools included with the device or a reputable security product. If suspicious behavior continues, use the manufacturer’s recovery process or seek qualified technical help.

A factory reset may be appropriate for a personal device with persistent malware concerns, but it has trade-offs. It can remove local evidence and does not automatically secure online accounts. Before resetting, preserve necessary files, confirm that backups are safe, and change important passwords from a clean device. Do not restore unknown applications or settings without reviewing them.

Look for signs that the attacker still has access

After the immediate reset, review each affected service for changes that are easy to overlook:

  • New email forwarding rules or filters
  • Unknown recovery addresses or phone numbers
  • New multifactor devices or backup codes
  • Unfamiliar logged-in devices and active sessions
  • Connected applications and third-party permissions
  • New payment methods, beneficiaries, or shipping addresses
  • Messages, posts, profile changes, or files that were not created by the account owner
  • New administrator accounts or remote-access tools on a device

Check again after the first cleanup. A delayed review can reveal changes made before the password reset or settings that were missed during the initial response.

How to reduce the chance of another compromise

Use unique credentials for important accounts

At minimum, protect email, banking, cloud storage, work accounts, social networks, and password-manager accounts with passwords that are not used anywhere else. Long, unique passwords matter more than changing the same short password repeatedly.

Turn on multifactor authentication

Enable it for accounts that support it, starting with email and financial services. Keep backup codes in a private location and review the enrolled devices occasionally. Treat unexpected multifactor prompts as a warning. Repeated prompts can indicate that someone has the correct password and is trying to get approval.

Reduce the number of places that can reset an account

Keep recovery email addresses and phone numbers current, but remove old ones. Review trusted devices and third-party applications. An unused account or abandoned application can become an overlooked route back into a more important service.

Separate sensitive activity from casual browsing

Use updated software, install applications only from trusted sources, and check browser extensions regularly. Be cautious with unexpected attachments, urgent payment requests, login warnings, and messages that ask for a verification code. A familiar logo or a message from a known account does not prove that the request is legitimate.

Protect the phone number without relying on it for everything

Ask the mobile provider which account protections are available, such as an account PIN or transfer lock. Keep the provider account secure and watch for sudden loss of mobile service, unexpected SIM notices, or password-reset messages that were not requested. A phone number can help with recovery, but it should not be the only protection for a high-value account.

Maintain backups that an attacker cannot easily change

Keep more than one copy of important files and verify that backups can actually be restored. A backup that is permanently connected to the same account or device may be affected by ransomware or account takeover. Store sensitive backup information securely and limit who can access it.

Common mistakes after a hack

  • Changing only the visible account password: Email access, active sessions, recovery settings, or connected applications may remain exposed.
  • Using the same replacement password elsewhere: The replacement can become the next shared point of failure.
  • Clicking a “security” link in an unexpected message: The message may be part of the attack or a second phishing attempt.
  • Deleting all evidence immediately: Screenshots and activity records can help with recovery, disputes, and investigation.
  • Resetting a device without securing accounts: A clean device does not undo stolen credentials or active sessions.
  • Ignoring accounts that appear unaffected: Reused passwords and shared recovery channels can connect an affected account to others.
  • Relying on multifactor prompts without checking them: Approving an unexpected request can hand an attacker the final step of a login.

When to report the incident

Report the compromise to the affected service through its official recovery or security channel. Contact financial providers promptly for unauthorized transactions. A workplace, school, or organization may have its own reporting process, especially if company data, shared accounts, or customer information could be involved.

Law enforcement or a relevant national cybercrime reporting service may also be appropriate, particularly when there is financial loss, extortion, identity theft, threats, or exposure of other people’s information. Keep the timeline and evidence organized so the report describes what happened, what changed, and which actions have already been taken.

A practical recovery checklist for ReadyTools readers

The most useful change after a hack is replacing a one-time password reset with a repeatable account review. Use this sequence:

  1. Move recovery work to a trusted device.
  2. Secure the primary email account.
  3. Change reused passwords, starting with high-value accounts.
  4. Sign out other sessions and remove unknown devices.
  5. Review recovery methods, multifactor settings, and backup codes.
  6. Revoke unfamiliar application access.
  7. Check forwarding rules, payments, messages, files, and profile changes.
  8. Inspect and update the device used for the compromised login.
  9. Preserve evidence and report financial or identity-related harm.
  10. Schedule another account review after the initial cleanup.

A compromise is not fully resolved when the attacker disappears from view. It is resolved when the likely access paths have been checked, sensitive accounts have separate protection, devices are trustworthy, and recovery settings belong to the right person. Start with email and active access, then work outward through money, devices, applications, and every account that shared the original password.


Schneller aufbauen mit ReadyTools

Entdecke ReadyTools: die ultimative Produktivitätssuite für Creator. Wunderschöne Linksy-Seiten, smarte Lara-KI, Projektmanagement, sicherer Cloud-Speicher und alles andere, was du brauchst – vereint an einem Ort. Starte noch heute deine 7-tägige kostenlose Testphase.

ReadyTools erkunden

Inhaltsverzeichnis

First, decide what kind of compromise occurredWhat to do immediately after an account is hacked1. Use a clean device and a trusted connection2. Secure the email account first3. Change passwords in the right order4. End active sessions and remove unfamiliar devices5. Check recovery settings and multifactor authenticationProtect money and identity before investigating furtherPreserve evidence before deleting everythingCheck the device that was used to sign inLook for signs that the attacker still has accessHow to reduce the chance of another compromiseUse unique credentials for important accountsTurn on multifactor authenticationReduce the number of places that can reset an accountSeparate sensitive activity from casual browsingProtect the phone number without relying on it for everythingMaintain backups that an attacker cannot easily changeCommon mistakes after a hackWhen to report the incidentA practical recovery checklist for ReadyTools readers

Weiterlesen

Ähnliche Artikel

Alle Artikel anzeigen

Top-Werkzeuge

WorkspaceLinksySEO-AnalyzerChromoQR-Code-Generator

ReadyTools

KarriereKontaktWerkzeuge
Preise7 Tage gratis
SupportSicherheitAnleitungenDocsBlogUpdatesLaraVault

Sprache wählen

Thema wählen

ReadyTools

© 2026 ReadyTools. Alle Rechte vorbehalten.