Active Incident? 24/7 Response →
SleuthX

For Individuals & Families

Account Hacked but You Still Have Access? Do This First

If you can still get in, you hold the advantage — but only until the attacker changes your password. Here's which of the two paths you're on, and the first moves on each.

All articles·7 min read·June 29, 2026

Two situations, two playbooks

“Hacked” covers two very different situations, and the right first move depends on which one you are in:

Not sure it was really a break-in? Is your email hacked? 10 signs and how to verify walks the diagnosis. This guide assumes you are past that — something is wrong and you want it fixed.

Path A — you still have access (move fast)

While you can still log in, you can shut the attacker out without waiting on anyone. Do these in order:

  1. Change the password to something long and unique you have never used anywhere else.
  2. Sign out all other sessions and devices.Most accounts have a “security” or “your devices” page with a one-click “sign out everywhere.” This kills the attacker's live session — a password change alone does not always do that.
  3. Check what they left behind. Look at recovery email, recovery phone, two-factor methods, and mail forwarding rules. Attackers add their own so they can get back in. Removing a rogue forwarding rule is its own step — see is a hacker still reading your email after a password change?
  4. Turn on stronger two-factor if you have not already — an authenticator app or a passkey, not just a text message.

Path B — you are locked out

If the password no longer works, do not keep guessing — go straight to the provider's account-recovery flow. Every major platform has one that verifies your identity through other signals (a device you used before, an old password, billing details) when you no longer hold the password or second factor. The FTC's recovery guide lists the official recovery links for the major email and social platforms.

If the attacker changed your recovery email and phone, the recovery flow still has a path — it simply takes longer and leans harder on history only you would know. Be patient and thorough, and do not pay any “recovery service” that promises to speed it up.

After you are back in

Regaining access is not the finish line. Whichever path you took, lock the account down so it does not happen again — unique password, sign out unknown sessions, fix recovery info, upgrade two-factor, and review connected apps. The full checklist is in how to secure any account after it has been hacked.

If money moved, your identity was used, or the same attacker keeps getting back in, account compromise recovery is the SleuthX service that investigates what was accessed and helps shut it down for good.

Sources

  1. Federal Trade Commission, How To Recover Your Hacked Email or Social Media Account. https://consumer.ftc.gov/articles/how-recover-your-hacked-email-or-social-media-account
  2. Federal Trade Commission, Email or social media hacked? Here's what to do, 2024. https://consumer.ftc.gov/consumer-alerts/2024/10/email-or-social-media-hacked-heres-what-do
  3. Cybersecurity & Infrastructure Security Agency (CISA), More than a Password. https://www.cisa.gov/MFA
  4. Google Account Help, Secure a hacked or compromised Google Account. https://support.google.com/accounts/answer/6294825

Related services

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 15 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Hacked but not locked out: quick answers

Certified Expertise

GIAC · AWS · Splunk · CompTIA

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management