How to Secure and Recover a Hacked Account

Your email and social accounts are the keys to almost everything else you do online, which is why they're such a target. This guide is for regular people, not IT departments. We'll cover the handful of habits that make your accounts genuinely hard to break into, and, if you've already lost access to one, the steps and recovery pages that give you the best shot at getting it back.

How we check this: Reflects account-security guidance from platform help centers and consumer-protection agencies. · Last reviewed: 2026-08

Step 1: Use strong, unique passwords

The single biggest cause of account takeovers isn't clever hacking. It's password reuse. When one service gets breached, attackers take the leaked email-and-password pairs and try them on your bank, your email, and your social accounts. If you use the same password everywhere, one breach anywhere unlocks all of it.

The fix is a unique password for every important account. Nobody can remember dozens of them, so use a password manager to generate and store long, random passwords. You only memorize one strong master password, and the manager handles the rest, including warning you when a saved password shows up in a known breach.

Start with your email account, because whoever controls your email can reset the password on nearly everything else. Make that one the strongest and most protected account you own.

A few small rules make a big difference. Length beats complexity, so a long passphrase of several unrelated words is both stronger and easier to handle than a short jumble of symbols. Don't build passwords from things a stranger could learn, a pet's name, a birthday, a favorite team. And never save important passwords in a plain notes file or a browser on a shared computer; a password manager keeps them encrypted and behind that single master key.

Step 2: Turn on 2FA, and prefer passkeys

Two-factor authentication (2FA) means a stolen password alone isn't enough to log in; an attacker also needs a second factor. Turn it on for your email, social, and financial accounts. Where you can choose, an authenticator app or a hardware key is stronger than SMS codes, because text codes can be intercepted or socially engineered out of you.

Passkeys are the newer, stronger option and are worth adopting wherever they're offered. A passkey ties your login to your device and a biometric or PIN, so there's no password to phish and no code to trick out of you. When a service offers a passkey, it's usually the safest choice you can make in two taps.

One warning that matters more than any other: never read a login or verification code aloud to anyone, and never type one into a page someone sent you. That code is the second factor. Handing it over defeats the entire point of 2FA.

Step 3: Recognize the takeover tricks aimed at your second factor

Because 2FA is so effective, scammers now spend most of their effort trying to steal the code rather than the password. The classic move is the "can you send me the code, I typed the wrong number" message from a friend whose account is already compromised. You forward the code, and now your account is the one being stolen. Never share a code that arrives on your phone, even with someone you trust; the request itself is the scam.

A more technical version is SIM-swapping, where an attacker convinces your phone carrier to move your number to their SIM, so your SMS codes land on their device. You can reduce this risk by adding a PIN or passcode to your mobile account and by preferring app-based or passkey authentication over SMS.

If you're ever pressured to "just read me the code to verify," whether by a caller, a message, or a support agent, stop. A real service that texted you a code does not need you to read it back.

Step 4: Act fast if an account is already hacked

If you've lost access, speed matters, attackers move quickly to change your recovery details and lock you out for good. The first move is to try the platform's official account-recovery flow immediately, before the attacker finishes changing your email and phone. From your email, revoke any suspicious sessions and reset the password if you still have access.

Each platform has its own recovery path, and the exact steps differ. We've written focused pages for the accounts people lose most often, so you can follow the right process instead of guessing. Start with the platform you've lost, then secure your email, since that's the master key to the rest.

As you regain access, turn on 2FA (or a passkey) if it wasn't on, change the password to something unique, and check that the recovery email and phone number are still yours and not the attacker's.

Two practical notes make recovery smoother. Do it from a device you already trust and have used to log in before, since platforms weigh familiar devices in your favor during a recovery review. And be patient with the official process even when it's slow, a legitimate recovery flow that takes a day is far safer than a stranger who slides into your messages promising to "restore" your account for a fee. That offer is itself a scam preying on locked-out users.

Step 5: Clean up and warn your contacts

Once you're back in, do a sweep. Change the password on any other account that shared it, remove unfamiliar connected apps or devices, and read through recent activity for messages or posts the attacker sent in your name. Hijacked accounts are routinely used to scam the victim's friends, so tell your contacts you were compromised and that any recent odd requests weren't from you.

Check your recovery settings carefully, a common trick is to leave you with access while quietly adding the attacker's email or phone as a backup, so they can waltz back in later. Remove anything you don't recognize.

It's worth watching your other accounts for a few weeks afterward, too. Attackers often sell access or reuse what they learned, so a takeover of one account can be followed by attempts on your email, your bank, or a shopping account days later. Treat any unexpected password-reset email or login alert in that window as a signal to check, not to click. Reset from the service directly rather than from a link in the message.

If the takeover led to money being sent, or your identity being used elsewhere, our aftermath guide covers the next steps for reporting and limiting the damage.

Related guides and terms

Account takeovers usually start with a phishing message or a fake login page, so the guides below on phishing and checking links are worth a read as prevention. They cover the messages that try to harvest your password in the first place, the step before any of this becomes necessary.

FAQ

What's the single most important thing I can do to protect my accounts?

Turn on two-factor authentication, ideally a passkey or authenticator app rather than SMS, and use a unique password for every important account. Together, those two habits stop the vast majority of takeovers.

A friend asked me to forward a verification code that arrived on my phone. Should I?

No. That code is your second factor, and the request is a classic takeover trick. Your friend's account is likely already hacked. Never share a login or verification code with anyone, ever.

My account is already hacked. What do I do first?

Use the platform's official recovery flow immediately, before the attacker changes your recovery email and phone. Then secure your email account, reset passwords, and turn on 2FA. Follow our platform-specific recovery pages for the exact steps.

Are passkeys really safer than passwords?

Yes. A passkey has no password to phish and no code to trick out of you. It's tied to your device and unlocked with a biometric or PIN. When a service offers a passkey, it's usually the safest option available.

Read more

Check a suspicious message now

Detection runs 100% locally on your device. We store nothing.

Please don’t paste other people’s personal data. Detection runs 100% locally on your device, and we store nothing.

Or try a real one:

Get it free

Or check it on Telegram