Active Incident? 24/7 Response →
SleuthX

For Individuals & Families

Account Hacked but You Still Have Access? Do This First

If you can still get in, you hold the advantage — but only until the attacker changes your password. Here's which of the two paths you're on, and the first moves on each.

All articles·7 min read·June 29, 2026

Two situations, two playbooks

“Hacked” covers two very different situations, and the right first move depends on which one you are in:

Not sure it was really a break-in? Is your email hacked? 10 signs and how to verify walks the diagnosis.

This guide assumes you are past that — something is wrong and you want it fixed.

Path A — you still have access (move fast)

While you can still log in, you can shut the attacker out without waiting on anyone. Do these in order:

  1. Change the password to something long and unique you have never used anywhere else.
  2. Sign out all other sessions and devices.Most accounts have a “security” or “your devices” page with a one-click “sign out everywhere.” This kills the attacker's live session — a password change alone does not always do that.
  3. Check what they left behind. Look at recovery email, recovery phone, two-factor methods, and mail forwarding rules. Attackers add their own so they can get back in. Removing a rogue forwarding rule is its own step — see is a hacker still reading your email after a password change?
  4. Turn on stronger two-factor if you have not already — an authenticator app or a passkey, not just a text message.

Path B — you are locked out

If the password no longer works, do not keep guessing — go straight to the provider's account-recovery flow.

Every major platform has one that verifies your identity through other signals (a device you used before, an old password, billing details) when you no longer hold the password or second factor.

The FTC's recovery guide lists the official recovery links for the major email and social platforms.

If the attacker changed your recovery email and phone, the recovery flow still has a path — it simply takes longer and leans harder on history only you would know.

Be patient and thorough, and do not pay any “recovery service” that promises to speed it up.

After you are back in

Regaining access is not the finish line.

Whichever path you took, lock the account down so it does not happen again — unique password, sign out unknown sessions, fix recovery info, upgrade two-factor, and review connected apps.

The full checklist is in how to secure any account after it has been hacked.

If money moved, your identity was used, or the same attacker keeps getting back in, account compromise recovery is the SleuthX service that investigates what was accessed and helps shut it down for good.

Sources

  1. Federal Trade Commission, How To Recover Your Hacked Email or Social Media Account. https://consumer.ftc.gov/articles/how-recover-your-hacked-email-or-social-media-account
  2. Federal Trade Commission, Email or social media hacked? Here's what to do, 2024. https://consumer.ftc.gov/consumer-alerts/2024/10/email-or-social-media-hacked-heres-what-do
  3. Cybersecurity & Infrastructure Security Agency (CISA), More than a Password. https://www.cisa.gov/MFA
  4. Google Account Help, Secure a hacked or compromised Google Account. https://support.google.com/accounts/answer/6294825

Related services

Self-serve forensic tool

Want professional help with securing a hacked account?

$995 once — lifetime license

Run the AI forensic agent yourself — every tool unlocked, no subscription.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Hacked but not locked out: quick answers

I can still log in. Does that mean I'm fine?
No — it means you have the advantage, not that the problem is over. An attacker who got in once can come back, and many leave a way back in (a forwarding rule, an added recovery phone, a connected app) even while you still have access. Use the access you have to change the password, sign out other sessions, and check those settings now, before they lock you out.
Should I change my password first, or check the account first?
Change the password first if you can still log in, then immediately sign out all other sessions and devices so the attacker's live session is killed. After that, audit recovery email, recovery phone, two-factor methods, and forwarding rules — a password change alone does not remove those. If your device might have malware, run a scan before trusting the new password.
I'm completely locked out. What now?
Use the provider's account-recovery flow — every major platform has one that verifies your identity through alternate signals when you no longer have the password or the second factor. Have account details ready (old passwords, a device you previously used, billing info). If the attacker changed your recovery email and phone, the recovery flow still has a path; it just takes longer.

Certified Expertise

GIAC

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management