The First-Hour Checklist for Regaining Control
By the end of this lesson, you'll understand:
The speed and order of your response in the first hour after discovering a compromised account meaningfully affects how much damage occurs and how easily you can undo it. Having a clear checklist ready removes the need to think clearly under stress, which is exactly when it's hardest to do.
If you still have access, change the password immediately from a trusted device, sign out of all other active sessions (most email, banking, and social platforms have this option in security settings), and enable two-factor authentication if it wasn't already active.
What to check: Change the password on any other account where you reused the same or a similar password, since a compromise often spreads through exactly this pattern.
If an attacker has already changed your password or contact information, use the platform's official account recovery process, which often requires identity verification through a backup email, phone number, or government ID. Avoid any "account recovery service" found outside the platform's official channels, since these are commonly fraudulent.
What to check: Have backup recovery information (a secondary email, a phone number) set up on your important accounts now, before you ever need it, since recovery is significantly harder without it.
Review recent account activity for unauthorized transactions, changed settings (a forwarding rule added to email, a new payment method added to a shopping account), and any messages sent from the account without your knowledge, which could indicate the compromise is being used to target your contacts as well.
What to check: Pay particular attention to email accounts specifically, since email is often used as the recovery method for other accounts, a compromised email can cascade into a compromise of everything connected to it.
A single compromised account is sometimes an isolated incident, but it can also indicate malware on your device, a broader data breach affecting a password you reused, or a successful phishing attempt that could have captured more than one credential. Take the opportunity to run a security scan and review your overall password hygiene, not just fix the one affected account.
What to check: If you're not sure how the compromise happened, treat it as a prompt to review your broader account security (FPS108) rather than assuming it was an isolated, unrelated event.
Opening his email, Kai notices a "password successfully changed" notification he didn't request, followed by being unable to log in. Using the recovery option tied to his backup phone number, he regains access within minutes and immediately signs out of all other active sessions.
Reviewing recent activity, he discovers a forwarding rule had been added, silently sending copies of his incoming email to an unfamiliar address, including messages from his bank. He removes the forwarding rule, changes his email password and enables two-factor authentication, then changes his banking password as a precaution given the potential email exposure, closing the loop before any financial account was actually accessed.
Once I change my password back, the account is fully secure again.
A compromise can leave behind changes beyond just the password, forwarding rules, new authorized devices, altered recovery information, that continue causing harm even after the password is reset. A full review of account settings is necessary, not just a password change.
As immediately as possible, the window between compromise and your response is when the most damage typically occurs, so treat it with real urgency rather than waiting to fully understand what happened first.
Once you've regained control, send a follow-up message to your contacts letting them know the account was compromised and to disregard any suspicious messages sent during that window.
If financial information or a significant amount of personal data was exposed, it's worth reporting to the FTC as well, covered in more detail in the reporting lesson ahead in this course.
Confirm you have backup recovery information set up on your email and banking accounts today, before you ever need to use it.
With account recovery covered, the next lesson, FPS118: Responding to Identity Theft, addresses the broader, more serious version of this situation, when your identity itself, not just one account, has been misused.
That's where Financial Confidence becomes your personal account recovery checklist.
Financial Confidence can help you confirm backup recovery information is set up, walk through a first-hour response checklist, flag unauthorized account setting changes, and track related accounts that may need a precautionary password change.
Explore More LessonsLet us know if this lesson was useful, it helps us know what to keep improving.
Thanks for letting us know!