Getting hacked feels like an emergency, and the instinct is to flail. Don't. Almost every compromise is contained the same way: work outward from your email β the account that can reset all the others β then lock the affected accounts, then check what the attacker touched. Speed helps, but doing it in the right order helps more. Here's that order, for the situations that actually happen.
An account's been taken over
- Get back in through official recovery. Use the service's own "forgot password" / account-recovery page β type the address yourself, never follow a link from a message.
- Change the password and turn on two-factor so the attacker is locked out even if they knew the old one.
- Sign out all other sessions and devices β most accounts have a "log out everywhere" or active-sessions list. Kick everyone off.
- Undo what they changed. Check your recovery email/phone, mail forwarding rules, connected/authorized apps, and any new "trusted" devices β attackers plant these to get back in.
- Fix every place you reused that password β and stop reusing (a password manager makes this easy).
- Warn your contacts if the account sent scams or messages in your name.
Your data's in a breach
What it means
A company you have an account with got hacked, and customer data leaked β at minimum your email, often a password or other details. You'll usually hear via a notification or the news. Reputable breach-notification services can tell you which of your accounts have appeared in known leaks.
What to do
- Change the password on the breached service β and anywhere you reused it.
- Turn on two-factor there if you haven't.
- Expect targeted phishing β criminals use leaked details to sound convincing. Be extra wary of messages referencing that company.
- If financial info leaked, watch your statements, and consider freezing your credit (the Debt & Credit kit explains how).
Lost or stolen phone
- Use "find my device" from another device or computer to locate, lock, and β if it's gone for good β remotely erase it.
- Sign out remotely from your accounts, and change passwords for anything important that was logged in on it.
- Call your carrier to suspend the SIM so no one can use your number (and your SMS codes).
- Report it stolen if it was theft. Then make sure your replacement has a lock screen and encryption on (see the next guide).
SIM-swap
A SIM-swap is when an attacker convinces your carrier to move your number to their device β so your calls and text-message codes go to them. It's exactly why app-based two-factor beats SMS.
- The warning sign: your phone suddenly loses all service for no reason and you can't call or text.
- Act fast: contact your carrier from another phone to reclaim the number, then secure your email and bank.
- Then move your two-factor off SMS to an authenticator app, and ask your carrier for a port-out PIN or freeze to prevent a repeat.
Response checklist
When something's compromised.
The close
A hack or a breach is frightening, but it's rarely the catastrophe it feels like in the first ten minutes β if you move in order. Lock your email, because it's the key to the rest. Recover accounts through their official doors, not the panic-link in a scary message. Sign everyone else out, undo the quiet changes an attacker leaves behind, and clean up any password you'd reused. Do that and you've turned a break-in into an inconvenience. The calm, ordered response is the one that wins.