An email you don't recognize, a post you didn't make, a friend asking about a strange message that came from your account. These are classic signs someone has broken into one of your accounts — and the first few hours matter most for whether you get control back quickly or things get messier.

Here's what to watch for, and what to do the moment you spot it.

Signs you shouldn't ignore

  • Unknown login alerts. An email or notification about access from a device or location that isn't yours.
  • A "reset your password" email you didn't request. Usually the first step of someone trying to take control before you do.
  • Your contacts receive strange messages or links that you didn't send.
  • Posts, likes or messages appear that you don't remember making.
  • Your usual password no longer works.
  • You receive two-factor codes you never requested.

What to do in the first 24 hours

The sooner you act, the less room you give whoever got in. Order matters:

  • Change the password immediately, from another device you know is safe if possible.
  • Review and close every active session from the account's security settings.
  • Turn on two-factor authentication if you didn't already have it.
  • Check connected devices and apps on the account and remove anything you don't recognize.
  • Warn your contacts if your account was used to send messages, so they don't fall for it.

Why a deeper review is worth it

Changing the password treats the symptom, not always the cause. If the access came from phishing, malware on your phone, or a reused password leaked elsewhere, the problem can come back within weeks if the real entry point isn't identified.

A breach diagnosis and lockdown review doesn't just close the access — it identifies exactly how they got in, so it doesn't happen again.

Is this happening right now?

Tell me what happened and in a video call we'll figure out how they got in and shut down access.

Write now →