If you've just discovered you've been hacked, the order you act in matters more than how fast you type. Recover your email before your bank, change passwords from a clean device rather than the infected one, and lock your credit before the attacker uses what they found. This guide walks that sequence step by step. It's the same containment logic security teams use, scaled down to one person.
Getting hacked is also common, and it usually isn't personal. The FBI's 2025 Internet Crime Report logged over a million complaints and $20.9 billion in reported losses in a single year. Verizon's 2026 Data Breach Investigations Report found stolen credentials involved in 39% of breaches, more than any other attack component. Most hacks begin with a password that leaked from some unrelated service and got reused — not with a genius attacker targeting you personally.

First: confirm you've actually been hacked
Common signs, roughly in order of how definitive they are:
- You're locked out of an account and the password-reset emails go to an address you don't recognize.
- Password-reset or verification-code emails you didn't request, especially several in a burst.
- Login alerts from unfamiliar locations or devices, or active sessions you don't recognize in the account's security page.
- Messages you didn't send in your sent folder, or contacts asking about strange texts and DMs "from you."
- Money movement you didn't authorize. Watch for small "test" charges under a few dollars; card thieves probe before they spend.
- On a phone: rapid battery drain, a device that runs hot at idle, data usage spikes, apps you didn't install, or a device admin or configuration profile you didn't set up. Any one of these alone can be innocent. Several together usually aren't.
- Your credentials appear in a breach. Check your email address at Have I Been Pwned. If a service you use was breached, treat that password as public everywhere you reused it.
If two or more of these are happening, or you're locked out entirely, assume compromise and work the steps below in order.
Step 1: Contain the device before touching accounts
If you suspect the device itself is compromised, and not just one account, changing passwords on it hands the attacker your new passwords too. Disconnect it from Wi-Fi, run a full antivirus scan, and do your account recovery from a different, known-clean device. If nothing about the device seems off and only one online account is affected, you can skip ahead.
Step 2: Take back your email first
Email comes first because whoever controls it can reset every other password you own. Recover it before anything else, using the provider's official account-recovery flow (Google, Microsoft, and Apple each have one). Once you're back in, change the password, sign out all other sessions, and check the three places attackers plant a way back in: forwarding rules, recovery email and phone, and app passwords or connected apps. Delete anything you didn't set up.
Step 3: Change passwords and turn on two-factor authentication
Work outward from email: banking, then any account that stores a card, then social media, then the rest. Every new password unique, ideally generated by a password manager. Turn on two-factor authentication as you go. An authenticator app or passkey beats SMS codes, which can be intercepted by SIM-swapping. If a hacked account offers "sign out everywhere," use it, because password changes don't always kill existing sessions.
Step 4: Check for changes the attacker left behind
In each recovered account, review linked payment methods, saved addresses, connected third-party apps, forwarding and auto-reply rules, and recently added "trusted" devices. Attackers routinely add a quiet backdoor so they can return after you change the password.
Step 5: Contact the organizations that hold your money
If financial accounts are involved, or a payment method was stored in any hacked account, call your bank and card issuers on the number printed on the card. Dispute unauthorized charges, ask for new card numbers, and flag the account for fraud review. Federal law caps your liability if you report promptly: $50 on a credit card, and $50 on a debit card if you report within two business days of noticing. Debit protections weaken sharply 60 days after the statement showing the fraud, so don't sit on it.
Step 6: Freeze your credit
If the attacker had access to your Social Security number, financial accounts, or enough personal data to open accounts in your name, place a credit freeze with all three bureaus (Equifax, Experian, TransUnion). It's free by federal law, takes minutes online, and blocks new accounts from being opened until you lift it. A fraud alert is the lighter-weight option if you only suspect exposure.
Step 7: Report it
File at IdentityTheft.gov if personal information was misused; the FTC generates a recovery plan and an official report you'll need for disputes. Report the hack itself at ic3.gov. If your device or accounts are tied to your workplace, tell your IT team immediately. One compromised personal login is a common front door into an employer.
Step 8: Warn your contacts
Attackers use hacked accounts to phish the people who trust you: "I'm stranded, can you send money," or a malicious link "from" you. A short message to your contacts ("My account was compromised; don't click anything I sent recently") blunts that second wave. It's an awkward message to send and everyone survives it.
Step 9: If the device was infected, wipe it
Antivirus catches most commodity malware, but if a device showed real signs of compromise (especially remote access), the only certain fix is a factory reset and clean reinstall, restoring data, not apps, from a backup made before the trouble started. On phones, also check for unknown configuration profiles (iOS) or device-admin apps (Android) before you conclude you're clean without a wipe.
Step 10: Close the holes so it doesn't happen again
Recovery is finished when the way in is gone, not when you're back in your accounts:
- Keep the unique passwords and 2FA from Step 3 in place. Backsliding into password reuse quietly undoes the whole cleanup.
- Update the device and apps. Most malware gets in through a patch you haven't installed yet.
- Watch for aftershocks. Attackers who lose access often try again with what they learned. Expect targeted phishing that quotes real details about you, and treat "your account was hacked again" emails as probable phishing.
- Shrink your public footprint. The details that made you targetable (your phone number, address history, relatives, old passwords paired with your email) circulate in breach dumps and get republished by data broker and people-search sites. We screenshot those sites' funnels constantly for our opt-out guides, and the free preview pages alone on sites like Spokeo will show a stranger your age, your relatives' names, and your past cities. That's most of what a caller needs to pass your carrier's security questions in a SIM-swap, and it's what scareware quotes to sound credible. Start with our guide to removing your personal information from the internet.
How long does recovery take?
The account-recovery core, Steps 1 through 4, is usually an evening. Bank disputes and credit freezes add a few phone calls over the following days. The monitoring tail runs a few months: keep an eye on statements, credit reports (free weekly at AnnualCreditReport.com), and login alerts. If something new appears, run the same sequence again.