What to Do If You’ve Been Hacked: A 60-Minute Recovery Plan
If you’ve been hacked, don’t start by changing every password you can remember. Start with the account that controls the others, usually your email, and use a device you have reason to trust. The first hour is about stopping new damage, not proving exactly how the attacker got in.
When you’ve been hacked, the same recovery order covers a compromised email or social account, suspicious phone or computer activity, and financial fraud. If money is moving or someone is impersonating you, treat that as an active incident and contact the bank or platform now.

What should you do first if you’ve been hacked?
Use a clean phone or computer, secure your primary email, end unknown sessions, and check payment activity in that order. A password change alone is not enough if the attacker added a recovery address, created an email-forwarding rule, or still has an active session.
- Contain access. Disconnect a device that is behaving strangely, but don’t wipe it before saving useful alerts or evidence.
- Recover your email. It can reset most of your other accounts.
- Remove persistence. Sign out other sessions and delete unknown devices, recovery methods, app passwords, and connected apps.
- Protect money. Check bank, card, UPI, wallet, advertising, and ecommerce accounts for changes you didn’t make.
- Warn people. Tell contacts to ignore unusual messages, links, payment requests, or password-reset emails from you.

How can you tell if you’ve been hacked?
One odd notification is not proof, but several signs together justify immediate action. The strongest signals are changes that require account access: a password reset you didn’t request, a new recovery number, messages you didn’t send, unfamiliar devices, or payments and ads you didn’t authorize.
- You can’t sign in with a password that worked recently.
- The provider reports a login from a device or location you don’t recognize.
- Your sent, deleted, or archived folders contain messages you didn’t write.
- Email forwarding, filters, delegates, or recovery details changed.
- Friends receive requests for money, gift cards, codes, or urgent help from your account.
- Your phone suddenly loses service, which can indicate a SIM-swap attempt.
Open the service directly from a saved bookmark or by typing its address. Don’t use the link inside the warning email until you have confirmed that the message is genuine. Google’s compromised-account checklist and the FTC’s email and social recovery guide both put account activity and recovery settings near the top of the inspection.
The first 60 minutes: contain the incident
Containment means cutting off the attacker’s path without destroying evidence you may need later. If one laptop is showing pop-ups, remote-control activity, or unknown software, disconnect that laptop from Wi-Fi and Ethernet. Use a different device to recover online accounts.
1. Secure the primary email account
Change the email password to a unique one, then sign out every other session. Review recovery email addresses, phone numbers, passkeys, two-factor methods, app passwords, connected applications, delegates, and forwarding rules. Attackers often leave one of these behind so they can return after the obvious password change.
2. Fix reused passwords next
If the compromised password was reused, assume every account with that password is at risk. Start with banking, domain registration, web hosting, cloud storage, social accounts, and shopping sites with saved cards. A password manager makes unique replacements manageable; changing one reused password into another reused password only resets the same problem.
3. Turn on stronger sign-in protection
Enable multi-factor authentication after removing unknown methods. An authenticator app, security key, or passkey is generally harder to phish than a one-time code sent by SMS. Save recovery codes somewhere that is not inside the same email account.
If you still have access, don’t log out before you confirm that your recovery email and phone number are yours. An attacker may have changed them, and your current session could be the only reliable path back into the account.
Use the provider’s official recovery path
Account recovery works best through the provider’s own workflow. Avoid people who claim they can recover an account for a fee, ask for your one-time code, or want remote access to your device. Those are common second attacks aimed at people who are already under pressure.
| Problem | Official recovery action | Then check |
|---|---|---|
| Google or Gmail | Secure a compromised Google Account | Devices, Gmail forwarding, recovery methods, Google Pay and Ads |
| Microsoft | Recover a compromised Microsoft account | Recent activity, aliases, forwarding, subscriptions |
| Apple | Apple security help | Trusted devices, purchases, payment methods |
| Social account | Open the platform’s help center directly | Messages, connected apps, admins, ad accounts |
What to do when you’ve been hacked and money is involved
Call the bank or card issuer using the number printed on the card or shown inside the official app. Ask them to stop or dispute unauthorized transactions, replace exposed cards, and review changes to your contact details. Save transaction IDs, screenshots, messages, phone numbers, and the time you noticed the fraud.
In India, online financial fraud can be reported through the National Cyber Crime Reporting Portal or the 1930 helpline. Reporting quickly matters because banks and law-enforcement systems have a better chance of tracing or freezing funds before they move again.
Clean the device without guessing
Update the operating system and security tools, scan the device, remove software and browser extensions you don’t recognize, and check whether remote-access tools were installed. A clean scan does not prove the machine is safe. If the attacker had administrator control, the safest route may be a factory reset or clean operating-system installation after backing up essential documents.
A WordPress site needs a separate incident plan. Reset administrator credentials, hosting and database passwords, rotate salts and API keys, inspect administrator users and scheduled tasks, replace modified core files, and restore from a known-clean backup. My cybersecurity practices checklist covers the preventive controls, while the website security hardening service is for cases where the site itself needs professional cleanup.
Prevent the same attack from working twice
Recovery is finished only when the entry path is closed. Unique passwords, software updates, multi-factor authentication, protected recovery codes, and verified backups remove most of the easy repeat routes. Also review what information was exposed so you can watch the accounts that matter, rather than changing random settings for a week.
- Use a unique password for every important account.
- Prefer passkeys, security keys, or an authenticator app where available.
- Turn on login and transaction alerts.
- Keep offline or versioned backups that a compromised account cannot erase.
- Remove apps, browser extensions, and account connections you no longer use.
- Teach anyone with access to the account how recovery codes and phishing work.
Frequently asked questions
Should I change all my passwords after being hacked?
Change the compromised account first, then every account that reused the same password. Prioritize email, banking, domain, hosting, cloud storage, and social accounts. Use a clean device and unique passwords.
Should I disconnect from the internet if I’ve been hacked?
Disconnect a device that shows malware or remote-control activity. Keep a trusted phone or computer online so you can recover accounts and contact providers. Disconnecting every device can make recovery harder.
Can changing my password remove a hacker?
Not by itself. Also sign out other sessions and remove unknown devices, recovery methods, forwarding rules, app passwords, passkeys, and connected applications.
What should I do if my phone number suddenly stops working?
Contact your mobile carrier from another phone and ask whether the SIM or eSIM changed. Then secure email and financial accounts because SMS codes may be reaching someone else.
Where should I report online financial fraud in India?
Report it through cybercrime.gov.in or call the National Cybercrime Helpline at 1930. Contact your bank or payment provider immediately as well.
Should I pay someone on social media to recover my account?
No. Use the platform’s official recovery process. Anyone asking for a one-time code, password, cryptocurrency, gift card, or remote device access may be running a recovery scam.
Regain control before you investigate
After you’ve been hacked, speed matters, but order matters more. Recover the email, end unknown sessions, protect money, clean affected devices, and close the path that let the attacker in. Once those five jobs are done, you can investigate without the incident changing underneath you.
Tell Google you want more of this.
Add Gaurav Tiwari as a preferred sourceOne tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.