CYBER WELFARE

Protect your Digital Privacy

Compromised Account: The First Steps and Who to Ask for Help

Additional resource for the lesson “Recognising a Compromised Account and Asking for Help” — Online Security course

An account can be taken over without you doing anything wrong. This resource explains the signs worth taking seriously, why a new password on its own is often not enough, the order of steps that takes an account back, and where to find genuine help. Most of it is best prepared on a calm day.

The key idea: whoever takes an account over often changes the lock and leaves a spare key. Take back both, from a clean device, by a route you chose yourself.

A. Why this matters

Passwords leak from services, devices get infected, and convincing messages catch careful people. When an account is taken over, the natural reaction is to change the password straight away. That matters, but it is rarely the whole job.

Whoever takes an account over usually changes two things. The password, so that you cannot get in. And the way back in: the recovery email and phone number that let you reset the password, and sometimes a forwarding rule that quietly sends copies of your emails elsewhere. The first locks you out. The second lets them return after you have changed the password.

Taking an account back means reclaiming both, from a device you trust, by a route you chose yourself.

Who to turn to depends on what happened

For the account itself, the first help is the service’s own recovery process. The UK’s National Cyber Security Centre (NCSC) and the US Federal Trade Commission (FTC) describe the same path: try to reset the password; if that fails because the recovery email or phone has been changed, use the service’s official account recovery.

If money is involved, call your bank straight away, alongside the steps below, on a number you already know, such as the one on the back of your card.

To report what happened:

  • England, Wales and Northern Ireland: Report Fraud, the national service for reporting fraud and cybercrime, at reportfraud.police.uk or on 0300 123 2040.
  • Scotland: Police Scotland on 101.
  • United States: report fraud to the FTC at ReportFraud.ftc.gov, and internet crime to the FBI’s Internet Crime Complaint Center (IC3) at ic3.gov.
  • Elsewhere: your national police or cybercrime reporting service.

B. Key concepts

Six ideas about recognising a takeover and reversing it.

The signs

The NCSC, the FTC and the major platforms list the same signs: you cannot sign in; contacts receive messages you did not send; you get alerts about sign-ins or changes to your security settings that you did not make; a password reset or a verification code arrives that you did not request.

Why it matters to you: A weak sign on its own is not proof: a reset email can simply mean someone typed your address. A strong sign, such as no longer being able to sign in, deserves action; so do two weaker signs together.

The way back in

The recovery email address and phone number an account uses to let you reset the password, plus any forwarding rules on an email account.

Why it matters to you: If these now belong to someone else, they can reset your new password too. Checking them is part of taking the account back, not an optional extra, and keeping them up to date on a calm day is what makes recovery possible.

Your own route

Opening the service’s app, or typing its address yourself, and using its official account recovery page.

Why it matters to you: A message that warns you about your account, or offers to help you recover it, may be part of the same attack. Real recovery starts from a route you chose yourself.

A clean device

A device you have good reason to trust: not the one that may have been infected.

Why it matters to you: If malware is running on your usual device, it can copy the new password as you type it. That is why Microsoft’s guide to recovering a hacked account puts a full antivirus scan of the computer before the password change.

Signing out everywhere

Most major services let you end every session on every device at once, usually in the security settings.

Why it matters to you: It ends access for anyone already signed in, which a new password does not always do.

Genuine help

The service’s own help pages, your bank, and your national reporting service.

Why it matters to you: Genuine help does not contact you first offering to recover your account, and no one helping you will ask you to tell them your password or a code sent to you.

C. A practical example: the messages Tom did not send

On Sunday morning two friends asked Tom about a link he had sent them overnight. He had sent nothing. When he tried his email on his laptop, the password no longer worked.

A few minutes later a message arrived offering to “restore his account” through a link. Tom was about to use it.

Nothing Tom did was unreasonable. But the offer had found him, rather than the other way round.

What changed the outcome

  • Tom ignored the message and used his phone, which he trusted, rather than the laptop.
  • On the phone he opened his email provider’s official recovery page himself and proved it was his account.
  • He set a new password and, straight away, checked the security settings. He found a recovery phone number that was not his, and a forwarding rule sending his mail to an unknown address, and removed both.
  • Then he used “Sign out everywhere”, so no one could stay signed in or reset the password again.
  • He scanned the laptop before signing in on it again, told his contacts to ignore the link, and turned on a second factor.

The difference was the order, and taking back the way back in as well as the password.

D. Try it yourself: prepare your way back in (20 minutes)

Four steps, done on a calm day. None of them assumes anything is wrong.

Step 1 — Check your email’s way back in

  • In your main email account’s security settings, find the recovery email address and recovery phone number. Are both still yours, and still in use?
  • In the email settings, look for forwarding rules and filters. Is each one something you set up?

Step 2 — Save the official recovery pages or guides

For your email and your two or three most important accounts, save the official recovery page or guide somewhere you can reach from another device. For example:

Step 3 — Write down your order

For the day you might need it, write these lines somewhere you can find without your usual device:

  1. Use a clean device, and go in by your own route.
  2. Recover the account through the service’s official recovery.
  3. Set a new password and, straight away, check and fix the recovery email, recovery phone and forwarding rules.
  4. Sign out everywhere, so no one can stay signed in or reset the password again.
  5. Tell your contacts, and turn on a second factor if it was not on.

Step 4 — Note who you would call

  • Your bank’s number, from the back of your card or your bank’s paperwork, in case money is involved.
  • Your national reporting service: in England, Wales and Northern Ireland, Report Fraud (0300 123 2040); in Scotland, Police Scotland on 101; in the United States, ReportFraud.ftc.gov and ic3.gov; elsewhere, your national police or cybercrime reporting service.

Step 1 takes five minutes, and it does most to decide how a bad day goes.

E. Videos, articles and further resources

Reporting channels first, then national guidance and platform documentation. All in English.

Where to report

Report Fraud (England, Wales and Northern Ireland)
The national service for reporting fraud and cybercrime; by phone on 0300 123 2040. In Scotland, contact Police Scotland on 101.
https://www.reportfraud.police.uk/

FTC (US) — ReportFraud.ftc.gov
Where to report fraud in the United States.
https://reportfraud.ftc.gov/

FBI (US) — Internet Crime Complaint Center (IC3)
Where to report internet crime in the United States.
https://www.ic3.gov/

National guidance

NCSC (UK) — Recovering a hacked account
The signs, and a step-by-step guide to getting back into an account.
https://www.ncsc.gov.uk/guidance/recovering-a-hacked-account

FTC (US) — How to recover your hacked email or social media account
Signs, recovery steps and links to the recovery pages of many major services.
https://consumer.ftc.gov/articles/how-recover-your-hacked-email-or-social-media-account

Platform documentation

Google Account Help — Secure a hacked or compromised Google Account
Recovery, then checking the recovery phone, recovery email, devices and Gmail forwarding.
https://support.google.com/accounts/answer/6294825?hl=en

Apple Support — If you think your Apple Account has been compromised
The signs Apple lists, and the steps to secure the account.
https://support.apple.com/en-us/102560

Microsoft Support — How to recover a hacked or compromised Microsoft account
A scan of the computer before changing the password, then the checks on mail forwarding and connected accounts.
https://support.microsoft.com/en-us/accounts-billing/manage/how-to-recover-a-hacked-or-compromised-microsoft-account

Links checked in October 2026. If an address changes, searching for the title on the organisation’s site usually finds it.

F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior

This lesson sits on the Secure Behavior pillar at level FL2. It closes the Essential level of the course and opens the way to the Intermediate level.

Skills

  • Finding and checking an account’s recovery details and forwarding rules.
  • Using a service’s official recovery, from a clean device.

Awareness

  • Recognising the signs of a takeover, and knowing that a weak sign on its own is not proof.
  • Understanding that a takeover changes the way back in as well as the password.
  • Knowing that, when money is involved, contacting your bank straight away comes before everything else.

Secure Behavior

  • Going in by your own route, never through a link in a warning message.
  • Asking for help from the service, your bank and your national reporting service, never from someone who contacts you first offering to recover the account.

G. Questions to sit with

  • If your main email account were taken over tonight, which device would you use to take it back?
  • Is the recovery phone number on your email account still yours?
  • Who would you call first if money had left your account?

H. What to do now

The recommendations (R) and security measures (MS) from the Cyber Welfare database that apply most directly here.

1. Notice early

  • R8 — Turn on login alerts, so a sign-in you did not make reaches you quickly.
  • R29 — When a contact warns you about a message in your name, take it seriously and follow the steps.

Minimum commitment: check today that the recovery email and phone on your main email account are yours.

2. Take it back, and keep it

  • R4 — Turn on a second factor, starting with your main email, once the account is yours again.
  • R1 and R2 — A different password for every account, kept in a reliable password manager, so one takeover does not open the others.

Minimum commitment: write down the five lines from step 3 and keep them away from your usual device.

In short

  • A weak sign on its own is not proof; a strong sign deserves action, and so do two weaker signs together.
  • A takeover changes the password and the way back in. Take back both.
  • Clean device and your own route first, then recovery, a new password with the recovery details and forwarding fixed straight away, then sign out everywhere, then contacts.
  • If money is involved, call your bank straight away; then report it to your national reporting service.
  • Genuine help does not contact you first offering to recover your account, and no one helping you will ask you to tell them your password or a code sent to you.

Related resources in this course

Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.

If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.

→ Join the Cyber Welfare Program