Active Incident? 24/7 Response →
SleuthX

For Individuals & Families

How to Secure Any Account After It's Been Hacked

The principles that apply to every account, not just email: the order to work them, why a malware scan can come first, and where to go for each major platform's specific steps.

All articles·8 min read·June 29, 2026

The universal lockdown

Every platform has its own recovery page, but the principles of locking an account back down are the same whether it is your email, your bank, your Instagram, or your Xbox. This is the platform-agnostic checklist — the moves that apply to anyaccount. For the exact menu clicks on a specific service, jump to that service's guide at the bottom.

  1. Clean the device first if malware is possible. Microsoft is explicit that you should run a malware scan before you change the password — otherwise malware on the device can simply capture the new one. If the account was used on a computer that may be infected, scan it before step 2.
  2. Set a new, unique password. Long, and used on no other account. A password manager makes this painless and is the single highest-leverage habit here.
  3. Sign out everywhere.Use the account's “active sessions” or “your devices” page to revoke every session. This is what actually ejects an attacker who is currently logged in.
  4. Reclaim your recovery info. Review the recovery email and phone number and remove any you do not recognize — attackers swap these to theirs so they can reset their way back in.
  5. Upgrade two-factor. Turn on the strongest second factor the account supports — an authenticator app or a passkey over SMS where possible (here is why SMS codes are the weakest 2FA).
  6. Audit forwarding rules and connected apps.Remove mail forwarding and filters and revoke third-party apps or “sign in with” permissions you did not grant (email specifics: is a hacker still reading your email?).
  7. Reset reused passwords. Any other account that shared the breached password is now exposed — change those too, starting with email and anything financial.

The exact clicks, by platform

The checklist above is the “what.” For the “where,” each major platform has a step-by-step recovery guide:

If the same attacker keeps getting back in, money has moved, or you need to know exactly what was accessed, account compromise recovery is the SleuthX service for the cases a checklist does not close on its own.

Sources

  1. Cybersecurity & Infrastructure Security Agency (CISA), Secure Our World — four steps to stay safer online. https://www.cisa.gov/secure-our-world
  2. Federal Trade Commission, How To Recover Your Hacked Email or Social Media Account. https://consumer.ftc.gov/articles/how-recover-your-hacked-email-or-social-media-account
  3. Google Account Help, Secure a hacked or compromised Google Account. https://support.google.com/accounts/answer/6294825
  4. Microsoft Support, How to recover a hacked or compromised Microsoft account. https://support.microsoft.com/en-us/account-billing/how-to-recover-a-hacked-or-compromised-microsoft-account-24ca907d-bcdf-a44b-4656-47f0cd89c245

Related services

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 15 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Securing a hacked account: quick answers

Certified Expertise

GIAC · AWS · Splunk · CompTIA

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management