Opens in a new tab

What to do if your online accounts are hacked

Person in hoodie at desk facing computer screen with “You have been hacked!” in green text amid code, highlighting account security risks in a dark room.

If you’re online, you will be targeted — period. The question isn’t if, it’s when. So when you see that gut-punch message — “We noticed a login from a new device” or “Your password has been changed” — the worst thing you can do is freeze or think, “I’ll deal with it later.” In cybersecurity, “later” is when the real damage happens.

The aftermath of a hack is ugly: drained bank accounts, wiped-out Instagram businesses, students blackmailed for intimate photos, parents locked out of the email that controls their medical portals and school accounts. Almost none of them thought they’d be targeted, and most waited a little too long to act. So if you’re asking “someone got into my account — what now?”, the answer is: move fast, be methodical, and assume this isn’t one account — it’s potentially your entire digital life at risk. This isn’t a fluffy “change your password and you’re fine” checklist. It’s the crisis playbook.

If You’re Hacked

Immediate recovery and protection steps if someone gets into your account.

  • Lock it down: change the compromised account’s password to a strong, unique one, enable two-factor authentication, and reset security questions.
  • Stop the spread: check other accounts for reused passwords or suspicious activity, log out unknown sessions, revoke unauthorized app access, and reset linked passwords.
  • Report and watch: report the hack to the provider and authorities, follow their recovery steps, and stay alert for phishing.

What to Do If Your Online Accounts Are Hacked

A hacked account isn’t a random glitch — it’s a criminal with a foothold in your life, and treating it as a one-off is the biggest mistake people make. Ignoring a “password changed” email because you assume it’s a scam is exactly how an attacker gets the time to reset your recovery email, turn on their own two-factor authentication, DM your followers with scams, and download years of private messages before you log back in. Platforms sometimes return the account eventually — but reputation and data don’t come back as fast.

So adopt this mindset: assume the attacker may have reached other accounts, may have already downloaded data (photos, messages, contacts, documents), and may come back even after it looks fixed. Think of it like finding an intruder in your house — you don’t just change the front-door lock; you check every room, window, and spare key. Your goals now: lock the attacker out, stop the spread to other accounts, assess what’s been touched or stolen, and report and document it. Start with passwords.

Change Your Passwords

Changing your password sounds basic, but it’s usually done too slowly and too weakly. If an account is hacked, the old password is burned — never reuse it anywhere. The lazy patterns attackers count on are everywhere: “Summer2024!”, pet and kid names, or the same password across email, social media, and banking. They don’t have to be clever; they plug your leaked email and password into automated tools and watch the doors open.

If you still have access: change the password immediately from a trusted device (not one that may be infected), sign out of all active sessions (“log out of all devices”), and update the recovery email and phone if the attacker may have changed them. If you don’t have access: start the “Forgot password?” or account-recovery flow right away, and use the “I think my account was hacked” support options, which are often prioritized. (If your recovery email is the compromised account, that’s exactly why you shouldn’t have one email for everything.)

Insider Tip: The single most important account to secure first is your email. If your email is compromised, attackers can reset passwords to almost everything else. Lock down email first, then everything else.

Use a Password Manager — Yes, You Actually Need One

Making up passwords in your head isn’t a strategy; it’s a liability. A good password is long (at least 14–16 characters), unique to that service, and random — not meaningful words. Humans can’t remember dozens of those, which is why password managers (1Password, Bitwarden, Dashlane) exist: they generate, store, and autofill strong passwords securely. According to Verizon’s Data Breach Investigations Report, about 74% of breaches involve the human element — stolen credentials, phishing, or user error — so offloading password complexity to a manager isn’t cheating; it’s smart risk reduction.

If you’re reading this after a hack, reset all your major passwords now with a manager: email(s), banking and financial accounts, social media, cloud storage, shopping accounts, and anything storing your credit card or personal data. It feels like overkill until you remember that an attacker with one working password may have already tried it everywhere you’ve logged in.

Check Your Other Accounts

If you’ve been hacked once, assume the attacker tried other accounts too — especially if you reused passwords even a couple of times. A hacked Snapchat can turn into a compromised email, which becomes reset access to Amazon, PayPal, and an online school portal, ending in ordered gift cards and attempted downloads of financial-aid tax documents. One weak link, cascading failures.

Triage by value — not all accounts are equal. Prioritize primary email (Gmail, Outlook, school email); banking, PayPal, Cash App, Venmo, and investment platforms; cloud storage; major social and messaging apps; and shopping sites that store payment info. On each: change the password whether or not you think it’s compromised, turn on two-factor authentication, and review recovery options. For parents and teens, apply the same logic to school portals and educational platforms, which quietly hold a lot of data.

Insider Tip: In investigations, a password reused on three or more major services is assumed to mean the attacker has tried them all. The victim never remembers where they reused it — but the attacker’s bot remembers perfectly.

Turn On Two-Factor Authentication

Blunt version: if 2FA is available and you don’t use it, you’re playing on hard mode for no reason. 2FA means that even with your password, an attacker still needs a second factor — a code, an app prompt, or a hardware key — to get in. According to research from Google’s security team, adding SMS-based 2FA blocked 96% of bulk phishing attacks and 76% of targeted attacks, and app-based prompts were stronger still.

Not all 2FA is equal: best are authenticator apps (Authy, Google Authenticator, Microsoft Authenticator); even better are hardware security keys like YubiKey (for high-risk users — activists, journalists, big-platform creators); acceptable but weaker is SMS, which attackers can sometimes hijack via SIM-swaps. On each major account, go to Security settings, turn on 2FA, and save backup codes somewhere secure. If you’re dealing with sextortion, blackmail, or harassment — especially involving teens — turning on 2FA everywhere is non-negotiable.

Insider Tip: Accounts with 2FA via an authenticator app are dramatically less likely to be fully taken over. In platform reviews, almost all seriously hijacked accounts had either no 2FA or SMS-only 2FA.

Check for Suspicious Activity

Once you’ve started locking doors, find out what the intruder did inside. Most platforms let you view recent login locations and devices, see active sessions, and log out ones you don’t recognize. Look for logins from countries you’ve never visited, devices you don’t own, and odd times like 3 a.m. while you were asleep.

On email and social media, also check two stealth moves: forwarding rules (has your email been set to auto-forward to another address?) and third-party app connections (revoke any connected apps or services you don’t recognize). Then scan for messages you didn’t send, posts you didn’t create, password-reset emails you didn’t request, and new contacts or numbers added. A hidden forwarding rule can quietly copy every message to an attacker for months — they’re often patient, gathering information rather than being noisy, which is exactly why this step matters.

Insider Tip: Attackers love playing “quiet parasite” — staying in your account, watching, and stepping in at the perfect moment, like when you’re expecting a bank email or a package. Don’t just fix what’s obvious; hunt for forwarding rules, new recovery methods, and new trusted devices.

Update Your Security Questions

Security questions are the weak backdoor of account protection — outdated, guessable, and still used by plenty of services. When an account is hacked, treat them as compromised even if you never saw them changed, because most are trivially answerable from public information: your high school is on LinkedIn, your mother’s maiden name may be in public records or tagged posts, your first pet’s name is 30 seconds of scrolling away. Attackers have broken into email simply by guessing security answers from someone’s public TikToks and Instagram captions.

Fix them properly: change every answer, and don’t use real, guessable facts. Treat them like extra passwords — make them long and random (e.g., “YellowCrane93!HarborCloud” as the “answer” to “first school”) and store them in your password manager’s notes. The system only checks for consistency, not accuracy.

Insider Tip: Assume every real-life fact about you is public or soon will be. If a login depends on a fact — maiden name, school, pet — replace it with fiction and lock that fiction in your password manager.

Watch Out for Phishing Attempts

Once you’ve been hacked or even just targeted, you’re on the “phishing radar” — criminals share and resell victim lists, and they know you’re scared and likely to click the next email promising a fix. A common one-two punch: a blackmail message, then a fake “Instagram Safety” or “Google Security” email saying “click here to secure your account,” leading to yet another credential-theft page that a panicking victim falls for.

Be hyper-skeptical of messages claiming your account will be deleted “unless…”, urgent links to “secure” or “confirm” your account, requests for verification codes or screenshots of codes, and “support” that only talks through DMs and asks for passwords. Practical rules: never click security links from email — go to the site manually or through the official app; check the sender’s address carefully (support-instagram-security@randomdomain.com is not Instagram); and if you get a password-reset email you didn’t request, don’t panic, but change your password anyway, verify 2FA, and treat it as a sign someone is testing your defenses. For teens, phishing often arrives as weird links in group chats from friends’ compromised accounts.

Insider Tip: After a breach, assume every account-recovery message might be fake. Reverse the flow — you initiate contact with companies through their official channels, never by following a link in a message.

Report the Hack

Reporting isn’t optional or just about recovering your account — it creates a paper trail that matters if money is stolen, your identity is misused, or your content is weaponized. Shame keeps too many people silent, and delay only gives an attacker more time to scale (reusing the same intimate images and threats across multiple platforms, for instance). Report to:

  • The platform — use “Report a hacked account,” and provide when you first noticed, what changed (email, username, phone, posts), and screenshots. Keep the support ticket ID.
  • Your bank — at any sign of financial misuse, ask about card freezes, chargebacks, and monitoring.
  • Local law enforcement — especially for sextortion, blackmail, threats of violence, or identity theft. Get a report number; banks and platforms take you more seriously when there’s an official report.
  • School or workplace — when it involves school platforms, student accounts, or bullying. For minors, loop in the trusted adults in charge.

Insider Tip: No one expects a perfectly documented case, but screenshots, dates, and copies of emails let investigators escalate quickly and link your case to others. The earlier the report, the better.

Conclusion: Treat Hacks Like House Fires, Not Minor Glitches

Treat a hacked account like a minor annoyance and you’re volunteering for a bigger disaster later — hacks are rarely isolated; they’re entry points, tests, and sometimes rehearsals for bigger crimes. Condensed, the playbook is: change your passwords immediately and thoroughly with a manager; check your other accounts (email, banking, cloud, social first); turn on 2FA, ideally with an authenticator app; search for suspicious activity — logins, messages, forwarding rules, new apps; update security questions with fake, strong answers; stay on high alert for phishing; and report the hack to platforms, banks, schools, and law enforcement when needed.

The internet is built for speed and profit, not to coddle you — but you’re not powerless. The people who come out of hacks least damaged aren’t the lucky ones; they’re the ones who act fast, think broadly, and refuse to downplay what’s happening. If you’re in a crisis now, take a breath, then start moving through these steps. If your situation involves sextortion, underage victims, or threats, don’t handle it alone — reach out to trusted adults, professionals, or law enforcement. Silence is the attacker’s best friend; informed, decisive action is yours.

Questions

Who should I contact first if my online account gets hacked? Contact the platform’s support and secure the account immediately.

What immediate steps should I take if someone accessed my account? Change your password, enable two-factor authentication, and review recent activity.

How can I recover access if the attacker changed my login details? Follow the platform’s account-recovery flow, provide the required verification, and contact support for manual help.

I think my account compromise is minor — do I really need to act? Yes. Even minor compromises can escalate quickly and expose your data.

When should I report a hacked account to law enforcement or an employer? When there’s financial loss, threats, or sensitive-data exposure — and notify your employer if work accounts are affected.

Can I recover lost data and prevent identity theft after a breach? Often yes — restore files from backups, reset credentials, and use credit monitoring to limit identity theft.