Finding out someone broke into your account feels stressful, but panicking makes people click dangerous links. You might have received a password reset notification, spotted a strange device on your profile, or found messages sent to friends that you never wrote. Follow this clear emergency plan step-by-step starting with your main email account.
Never trust the message that sounded the alarm: Scammers often send fake emails saying "Your account has been hacked! Click here to fix it!" to steal your login. Close the warning message immediately, open your web browser or official app, and type the genuine website address yourself. Never tap links, enter codes, or ring telephone numbers provided inside suspicious alerts.
Why you must follow the correct emergency order
Think of your digital life like a house. Your primary email address is the master key to the front door. If an intruder holds your email, resetting your Instagram, Roblox, or bank password will not help because the password reset links will land straight inside the hacker's hands. Once you kick the intruder out of your email, you can systematically take back everything else.
Do these five things immediately
1 Sever Contact Stop replying
2 Lock Email Reset password
3 Boot Devices End all sessions
4 Call Bank Freeze money
5 Warn Friends Stop scam spread
Stop interacting immediately: Hang up on the caller, close the chat window, and do not respond to texts or direct messages asking for codes or money.
Use a clean, trusted device: If you suspect your computer has a virus, switch to your smartphone on mobile data or borrow a family laptop to reset your passwords.
Take back your primary email: Change the password immediately and sign out all active sessions so the intruder loses access.
Lock your password manager: If you use Bitwarden, 1Password, or Apple Keychain, update your master password and review stored vaults.
Alert your bank: If debit cards, PayPal, or bank accounts are linked to the breached account, call your bank using the number printed on the back of your card.
The Absolute "Never Share" Rule: Real customer support staff from Google, Apple, Microsoft, or your bank will never ask you for your account password, screen PIN, six-digit authenticator code, or password manager master password. Anyone asking for these numbers is an attacker.
1Secure your main email first
Take back control of your email hub so the hacker cannot intercept password reset requests. Follow this exact path:
Official Email Site (e.g. myaccount.google.com) → Security → Password & Devices
Change the password immediately: Pick a brand-new, long passphrase that you have never used on any other website (e.g. 4 random combined words like PurpleRocketMonkeyGuitar99!). Do not reuse old passwords.
Kick out the intruder (Sign out all sessions): Under Security, locate Your Devices or Active Sessions. Click Sign out of all devices or manually remove any unfamiliar phone, tablet, or city location.
Audit your recovery details: Check the Recovery Email and Recovery Phone Number listed on the account. Hackers often change these to their own numbers so they can slip back in. Delete any unrecognized number or email address immediately.
Check for secret email forwarding rules: In your email settings (e.g. Gmail Settings > Filters and Blocked Addresses / Forwarding), inspect the forwarding tab. Hackers frequently set up hidden rules that quietly forward copies of all your incoming emails to their inbox. Delete any unfamiliar forwarding addresses.
Turn on or reconfigure Two-Factor Authentication (2FA): Enable an authenticator app (Google Authenticator or Microsoft Authenticator) or passkey. Generate a new set of 10 printable emergency backup codes and write them down in a notebook.
Why this comes first: Whoever holds the keys to your email inbox controls the password reset buttons for your banking, school portals, shopping accounts, and gaming accounts.
2If banking or payment cards are involved
If the compromised account contains saved payment cards (Amazon, PayPal, Google Play, Apple ID) or if your mobile banking details were entered, take immediate defensive action:
Contact your bank directly: Pick up your phone, open your official banking app, or look at the back of your plastic debit card for the official fraud phone number. (In the UK, you can dial 159 to reach most major banks directly and safely).
Request temporary card freezes: Tell the bank representative that you suspect account compromise. Ask them to temporarily freeze your payment cards and review recent transactions.
Audit recent payments and payees: Check your statement for unauthorized transfers, pending charges, or newly added recipient bank accounts.
Reset banking credentials: Change your online banking password and passcode using a known clean device. Remove any unfamiliar registered mobile phones from your banking profile.
The "Safe Account" Scam Trap: Real banks will never phone you and instruct you to move your savings into a "safe account", "holding vault", or "investigation account" because of fraud. That is an outright lie used by thieves. Never authorize a money transfer requested over a phone call.
3Recover social media, gaming, and shopping accounts
Once your email is secure, systematically reclaim your secondary platforms (Instagram, Discord, TikTok, Roblox, PlayStation, Amazon):
Option A: If you can still sign in
Open the official app or website and change your account password immediately.
Go to Settings > Security > Login Activity and click Log Out of All Other Sessions.
Turn on Two-Factor Authentication using an authenticator app.
Check your profile details: ensure your recovery phone number and email were not altered.
Review sent messages and recent posts. Delete any scam links the hacker published while in control of your account.
Option B: If the hacker changed your password
Go directly to the service's official recovery portal (e.g. instagram.com/hacked or roblox.com/support).
Click Forgot Password? or My account was compromised.
Select the option to send a verification link to your newly secured primary email address.
Complete the identity verification steps (such as video selfie verification or providing past transaction receipts).
Never pay a third party: Ignore people on Instagram or X claiming: "DM this ethical hacker to get your account back!" They are scammers trying to steal your money.
Warn your contacts: Hackers love to send messages from breached accounts claiming: "Hey, I need emergency money for a taxi!" or "Vote for my team in this contest!" Send a quick warning from a safe account or group chat: "My account was temporarily compromised. Please ignore any messages, links, or money requests sent from it."
4Clean and verify your phone and computer
Make sure the intruder did not leave behind malicious software, remote tools, or unauthorized tracking profiles:
Smartphone checks (Android & iPhone)
Install the latest operating system updates (iOS / Android) to patch vulnerabilities.
Audit your app list: delete any unfamiliar apps, battery savers, or unofficial keyboards you did not download.
On iPhone, check Settings > General > VPN & Device Management and remove any unfamiliar profile.
Confirm that your screen lock PIN and biometric locks (Face ID / Fingerprint) are active.
Computer checks (Windows & Mac)
Install all pending Windows Updates or macOS updates.
Run a full malware scan using Windows Security or trusted security tools.
Open your web browser settings, open Extensions, and delete any toolbar or plugin you do not recognize.
Uninstall any remote support software (such as AnyDesk or TeamViewer) that an unsolicited caller instructed you to install.
Authenticator App Tip: When setting up 2FA on your reclaimed accounts, keep your mobile phone nearby. Open Google Authenticator or Microsoft Authenticator, scan the barcode, and type the rolling 6-digit code into the official site you opened yourself.
5Make a repeat attack impossible
For all your personal accounts
Never reuse passwords: If a hacker breaches a minor gaming forum and you used the same password as your email, they instantly gain access to your whole life.
Activate passkeys or 2FA everywhere: Even if someone steals your written password, they are blocked without your physical device.
Turn on login notifications: Ensure your accounts send an instant alert whenever a new device logs in.
For your password manager
Change the master password immediately if there is any suspicion of exposure.
Sign out all other sessions and active browsers.
Ensure the password manager itself is fortified with 2FA or biometric authentication.
Begin using the built-in password generator to create complex 16-character passwords for every account.
Your recovery checklist
Step 1: Reset your primary email password to a new, unique passphrase.
Step 2: Sign out of all active devices and remove unfamiliar forwarding rules.
Step 3: Call your bank to freeze cards if financial data was exposed.
Step 4: Reclaim social and gaming accounts and log out all other sessions.
Step 5: Warn close friends and contacts not to click links sent from your profile.
Step 6: Enable Two-Factor Authentication or passkeys on every account.
What you see happening
The correct action to take
What you must NEVER do
Unexpected 2FA prompt or code appears on your phone
Tap Deny / Reject immediately and change your account password.
Never tap Approve just to clear the pop-up notification.
Someone on social media offers to "recover your account for a fee"
Use only the official recovery page provided by the company.
Never pay money, send gift cards, or give remote access to strangers.
Unfamiliar transaction shows on your bank statement
Call your bank immediately using the number on your card.
Never wait for an unsolicited caller to phone you back.
3Recover social media, gaming, and shopping accounts
Once your email is secure, systematically reclaim your secondary platforms (Instagram, Discord, TikTok, Roblox, PlayStation, Amazon):
Option A: If you can still sign in
Option B: If the hacker changed your password
instagram.com/hackedorroblox.com/support).