
Key Takeaways
Understanding What Happened — and Why It Matters
Account compromises typically originate from one of three sources: a data breach at the service itself, credential stuffing (attackers testing username-password pairs stolen from other breaches), or phishing (tricking you into entering your credentials on a fake login page). Less commonly, malware installed on your device can capture keystrokes or session cookies directly. Knowing the likely cause helps you plug the right gap.
Understanding what happens after a company data breach can clarify how your credentials may have ended up in the wrong hands — and what broader risks to your identity may follow. Meanwhile, a strong password alone is often not enough: attackers have techniques that bypass even well-constructed passwords, which is why layered defenses matter.
What you will need
Step-by-Step Recovery
Follow these steps in order. Each action builds on the previous one — skipping ahead can leave gaps an attacker can exploit. The entire process typically takes between 20 and 45 minutes depending on how many connected accounts need attention.
Act From a Trusted Device
If you suspect your primary computer or phone is compromised by malware, do not use it to recover your account. Log in from a different, trusted device — such as a family member's laptop or a library computer — before changing credentials. Recovering access through the same device an attacker may control can hand them your new password immediately.
Confirm the compromise and stay calm
Look for concrete signs before acting: unfamiliar login alerts, password-change emails you didn't request, messages sent from your account that you didn't write, or unusual account activity in your history. A single suspicious email isn't proof — verify through the platform's official security or login-activity page directly, not through any link in that email.
Secure your recovery path first
Before changing anything on the hacked account itself, verify that the recovery email address and phone number linked to it are still under your control. If an attacker has changed these, you'll need to use the platform's account recovery flow — typically a form requiring identity verification — before you can proceed.
Change your password immediately
Create a new password that is long (at least 16 characters), random, and unique to this service. Avoid any variation of the old password. Use your password manager to generate one if possible. Once changed, the platform will typically invalidate the attacker's current session automatically on most services.
Enable two-factor authentication
Two-factor authentication (2FA) requires a second proof of identity — usually a time-sensitive code from an authenticator app or a hardware key — in addition to your password. Even if your new password were stolen, 2FA prevents login without that second factor. Enable it immediately in the account's security settings. An authenticator app is more secure than SMS-based codes, which can be intercepted through SIM-swapping attacks.
Revoke all active sessions and audit connected apps
Most platforms offer a "Sign out all other devices" or "Active sessions" option in security settings. Use it to terminate any sessions the attacker may still be using. Then navigate to the account's list of connected third-party applications and revoke access to any you don't recognize or no longer use. Attackers sometimes grant themselves API access through a connected app specifically to maintain a foothold after a password change.
Check for damage and notify affected parties
Review sent messages, posts, and account activity from the period of compromise. If the attacker sent phishing links or requests for money to your contacts, notify those people directly so they know not to interact with those messages. Check whether any personal data — address, payment method, date of birth — was exposed or altered, and correct it.
Audit other accounts that shared the same password
Search your password manager (or your memory) for any other service where you used the same or a similar password. Change each one to a unique credential immediately. Use a service like Have I Been Pwned to check whether your email address has appeared in other data breaches that may have contributed to the initial compromise. Understanding the source can prevent a repeat.
Use a Password Manager Going Forward
A password manager generates and stores long, unique passwords for every service you use, making credential reuse a non-issue. Most managers also flag if any of your saved passwords have appeared in a known data breach. Setting one up after a hack is one of the most protective things you can do. See our guide to organizing your digital life for broader account hygiene tips.
After Recovery: Preventing the Next Incident
Once you've regained control, shift from reactive to proactive. The same vulnerabilities that allowed this breach likely exist on other accounts. A full security review — checking every account's password strength, 2FA status, and connected app permissions — transforms a stressful incident into an opportunity to substantially improve your overall security posture.
Our complete online safety audit checklist walks through exactly that process, covering weak passwords, outdated permissions, and privacy gaps across all your accounts and devices. Treat it as the natural follow-up to this immediate response plan.
Don't Reuse Passwords Across Accounts
Attackers routinely use a set of stolen credentials to attempt logins on dozens of other services in a process called credential stuffing. If the hacked account's password was shared with your email, bank, or other services, those accounts are now at risk too. Change every account that shared the compromised password as a priority.
