Active Incident? 24/7 Response →
SleuthX

For Individuals & Families

Account Compromise Recovery

Hacked Google, Facebook, email, or bank account? Forensic account compromise recovery — we find how they got in, lock the attacker out, and document everything.

What this service does

When your email, Google, Facebook, or bank account is hacked, getting back in is only half the job.

We do the other half: trace exactly how the attacker got in, find what they reached and whether they still have a foothold — planted forwarding rules, OAuth tokens, a changed recovery phone — and lock them out for good.

You get the account back and a written record of what happened, so a password reset is never the end of the story.

Engagements are confidential and structured to begin within 48 hours of the consultation.

Some service tracks are offered at a fixed fee; complex investigations are billed hourlywith a clear scope, milestone updates, and a cap agreed up front.

Quinn (Founder and CEO) sets the methodology every engagement runs under and reviews case findings before they leave the practice; the practitioner team executes the technical work under her methodology.

What this means for you

Google, Facebook, or Gmail account hacked?

Platform-native recovery flows stop at giving you the account back — they do not tell you how the attacker got in, what they read, or whether they still have a foothold.

Our account takeover recovery work answers exactly that, then hardens the account so it does not happen again. Common follow-on vectors we check: SIM swap attack recovery when your phone number was hijacked, and identity theft investigation when exposed data started showing up in new accounts.

And when the person who got in is someone you know — a partner or ex who knew your passwords and had your phone — the safe recovery order is different: what to do if someone has access to your phone.

Prove who accessed your account — for a police report, insurance claim, or restraining-order case

When the compromise is part of something larger — stalking or harassment, an insurance claim, a divorce or a restraining-order matter — the question stops being "how do I get back in" and becomes "can I show who reached my account, and when."

We reconstruct the account-access timeline from the login, device, and IP records the platforms retain, preserve it under a documented chain of custody, and write it up as forensic documentation designed to support your police report, your insurance claim, or your attorney's filing.

We do not promise to name the individual behind an anonymized login — attribution to a specific person usually needs subpoena power we do not have — but we produce the evidentiary record that the people who do have it can act on.

How an engagement begins

  1. Confidential consultation. NDA-protected. 30-60 minutes. Direct conversation, no sales process.
  2. Scoped engagement. Written proposal with defined deliverables and pricing — fixed fee where it applies, hourly with milestone caps for open-ended investigations.
  3. Investigation and findings. Documented methodology and chain of custody so findings can withstand courtroom scrutiny. Written report you can act on.

Why this work matters

Quinn holds 9 active certifications across GIAC — a methodology informed by her own work as a contractor inside Fortune 50 enterprise environments and built to hold up under litigation scrutiny.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Certified Expertise

GIAC

Frequently asked about account compromise

What should I do right now if my account was just compromised?
First — if you can still access the account, change the password from a clean device, enable two-factor authentication using an authenticator app (not SMS), and review recent sign-in activity to identify the unauthorized session. Second — sign out of all sessions everywhere. Third — call us. Most account-compromise cases involve more than the password (recovery email or phone changed, OAuth tokens issued to attacker apps, mailbox forwarding rules planted), and a password reset alone does not actually evict the attacker. The earlier the forensic audit happens, the more recoverable evidence we capture.
How is forensic recovery different from a password reset?
A password reset blocks the attacker from logging in with the stolen password. A forensic recovery does much more: identifies which sessions were active and from where, lists OAuth-authorized apps the attacker may have granted themselves, finds inbox forwarding rules and filters that exfiltrate future mail, audits recovery email and phone for unauthorized changes, examines metadata to determine what the attacker accessed, and produces a written report you can act on (insurance, law enforcement, civil litigation). Without that audit, attackers commonly retain access through OAuth tokens and forwarding rules even after a password change.
Can you find out who the attacker was?
Sometimes — depending on what artifacts the platform retained, whether the attacker used a VPN or anonymization, and whether there is law-enforcement or subpoena leverage. We can usually identify IP addresses, device fingerprints, geographic patterns, and timing of access. Attribution to a specific named individual typically requires either a clear pattern (e.g., a known person with means and motive — common in domestic situations) or law-enforcement escalation. We are honest about what attribution is and is not realistic in your specific case.
How much does account-compromise recovery cost?
You have two ways to work with us. Run the investigation yourself in the SleuthX tool for $995 once — lifetime access, with usage metered from a prepaid balance you top up anytime. Or have our team do it for you in a done-for-you device package: $3,000 for one device, $7,000 for three, $12,000 for five, each including the $995 lifetime license. Multi-account or business-tier compromises beyond a package (Microsoft 365 tenants, multiple personal accounts plus a small business, or compromises with downstream financial fraud) are scoped per case at a flat $400/hour, with no multipliers. Sliding-scale pricing is available where the loss already hurts financially — that conversation happens on the first call, not buried in fine print.
How long does account-compromise recovery take?
Active containment (sign-outs, OAuth audit, forwarding-rule cleanup, MFA hardening) is typically the same day or within 24 hours. The full forensic audit and written report usually take 5–10 business days, depending on platform (Microsoft 365 unified audit log review takes longer than a single Gmail account) and scope. Where there is downstream fraud, financial-crime documentation, or insurance / litigation timelines, the work is structured around your deadlines.
Will my data be safer afterward?
Yes — substantially. The deliverable is not just an incident report; it is a hardened account with documented changes: app-specific passwords audited, OAuth tokens revoked except for known-good apps, recovery contacts verified, MFA enforced, login alerts enabled, and a written record of what was changed and why. We also map the broader exposure (other accounts that share the compromised credentials, third-party services with stored payment methods or personal data) and either close those gaps directly or hand you a prioritized punch list.
Can the report be used for insurance, law enforcement, or in court?
Yes. The forensic report is written to hold up under courtroom scrutiny — chain of custody documented, methodology disclosed, findings supported by artifact evidence — though admissibility is ultimately the court's call. Reports have been used for cyber-insurance claims, IC3 filings, FTC identity-theft reports, civil litigation against responsible parties, and where applicable, criminal-referral packages for state attorneys and federal investigators. We do not produce "good enough for the insurance company" reports; the standard is the same regardless of the eventual use.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 15-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management