An unauthorised sign-in discovered straight away is a twenty-minute nuisance. The same sign-in discovered three months later is a different thing — and not only in scale.
This post describes what actually changes, financially, professionally, relationally and psychologically, when a long time passes between the event and the discovery.
It expands on the recommendation account login alerts.
Why the delay changes the nature of the problem
Before the consequences, the mechanism producing them.
A sign-in discovered straight away is an event: something happened, you act, you close it. A sign-in discovered late is no longer an event — it is a period. And a period has three characteristics an event does not:
- it accumulates: every day adds material;
- it branches: from one account others get reached;
- it fades: after weeks it is no longer possible to reconstruct what was touched.
The last is the heaviest and the least discussed. The worst damage of a late discovery is not what happened: it is not being able to know what happened.
1. The financial consequences
The direct costs
They are possible but they are not the centre. Unauthorised transactions have defined dispute periods, and most payment systems provide refund procedures.
The trouble with delay is exactly that: the dispute windows expire. A charge disputed within a few days follows a simple route; the same charge disputed after three months follows a much harder one, and in some cases can no longer be disputed at all.
The indirect costs
They are more substantial and more certain.
| Item | Why it weighs |
|---|---|
| Time to reconstruct | Weeks of accounts to check one by one |
| Restoring access | Every service has a different procedure |
| Documents to redo | If they were used to open something |
| Services interrupted | An unrecoverable email stops a great many things |
The “time to reconstruct” item is the one that surprises: after a late discovery, closing the hole is not enough. Every account that might have been reached has to be checked, and the list is longer than anybody imagines.
2. The professional consequences
The correspondence that went out
If messages went out from the account over weeks, those messages reached colleagues, clients, suppliers. Some may have produced actions: a payment redirected, a document sent to the wrong recipient, a decision taken on false information.
The professional consequence is not the message: it is what people did after receiving it. And reconstructing that, months later, means contacting everybody.
The obligation to report
If the account holds third parties’ data — clients, patients, employees — many contexts impose notification obligations with tight deadlines, starting from the moment you become aware of the event.
A late discovery does not remove the obligation: it makes it harder to meet, because it requires you to state a perimeter that can no longer be reconstructed.
This is not legal advice — for that you need somebody qualified to give it — but it is the practical reason why, in a professional setting, quick detection is not a preference: it is a condition for being able to respond correctly.
Your contacts’ trust
Anyone who received messages from your account for weeks has a legitimate question: how much of what you wrote me in that period was you? It is a question you cannot answer with certainty, and that is what strains the relationship.
3. The relational consequences
The people you involved without knowing
It is the heaviest aspect of a late discovery. Prolonged access to your email means the messages of others were read too: things friends, family and colleagues wrote to you in confidence.
Those people left no account open. They are exposed because of a configuration that was not theirs, and they have to be told — which is a difficult and necessary conversation.
The contacts reached in your name
If requests went out from the account to your contacts — for money, for data, for favours — some people may have replied. The damage, in that case, is not yours: it is theirs. And the fact that it happened through your address makes it hard to explain.
Retroactive suspicion
After a late discovery, the whole period becomes uncertain. Conversations that seemed normal get re-examined. It is a form of uncertainty that extends backwards, and it does not close with a password change.
4. The psychological consequences
The uncertainty with no end
It is the typical reaction, and it is specific to this scenario. After an incident discovered straight away, you know what happened. After one discovered late, you never will.
That uncertainty is more wearing than confirmed damage. Many people describe the period afterwards as dominated by a question with no answer: what did they see, for how long, what did they do with it.
One thing is worth saying: that question does not resolve by carrying on searching. It is managed by closing what can be closed — the configurations, the access, the passwords — and accepting that part of it will stay undetermined. It is uncomfortable, and it is the honest answer.
Guilt towards others
Different from the other scenarios: here it does not concern your own data, but that of the people who trusted you.
Here too a useful clarification: a delay in discovery is not carelessness. A well-conducted unauthorised access produces no visible symptoms — it is designed not to. Noticing it without alerts turned on is not a matter of attention: it is a matter of luck.
The action that genuinely helps is telling the people involved. It is not pleasant, but it is what puts control back where it can be.
Two discoveries compared
The exact same event — a password caught in a breach and used by somebody — with two different outcomes.
Discovered in ten minutes. An alert arrives: a sign-in from a device Mark does not recognise. He opens the app, revokes the session, checks the recovery methods, changes the password, turns on the second factor. Twenty minutes in all. He tells the story at dinner as an anecdote. There are no consequences to manage, because nothing happened beyond the sign-in.
Discovered four months later. No alerts on. Mark notices when a client asks him why he changed the bank details on an invoice — which he did not. From there: he finds the forwarding rule, finds that other communications went out from the account, has to contact every client from that period, has to check every connected account, has to tell his colleagues their correspondence was read. Weeks of work, and a relationship with that client that never quite goes back to how it was.
The difference between the two scenarios is not in Mark’s competence, nor in the severity of the attack. It is in one setting turned on, or not, months earlier.
The second difference is worth noting too: in the first case Mark knows exactly what happened. In the second he will never entirely know — and that is the part that stays.
What to do if it has already happened
In order, because in this scenario the order matters more than elsewhere.
- Remove the configurations: forwarding, recovery methods, connected apps, secondary numbers.
- Revoke every active session, not only the suspicious ones.
- Only now change the password, and turn on the second factor if there is none.
- Turn on the alerts, with an independent contact.
- Check the accounts linked to that address, starting with the most sensitive.
- Tell the people involved, with a short, factual message.
- In a professional setting, report it to whoever is responsible.
The first three steps in that order are not a detail: changing the password first tells whoever has the access that they have been found, without removing their means of getting back in.
How to tell the people involved
It is the step many people postpone, and it is worth approaching with some practical guidance, because how it is done changes the outcome.
Be factual and brief. What happened, over what period, what was potentially visible, what you did. It does not need a narrative: it needs usable information.
Do not minimise and do not dramatise. “Probably nothing happened” takes away the person’s chance to judge for themselves. “They could have everything” produces alarm that helps nobody.
Say what they can do. If they exchanged credentials, documents or personal data with you, say so explicitly and suggest the relevant checks. It is the part that makes the message useful rather than merely awkward.
Do not wait until you have the full picture. In this scenario the full picture never arrives. Telling people late is worse than telling them with some uncertainty.
In a professional setting, coordinate with whoever is responsible before writing to clients: there may be internal procedures and formal obligations.
A note on tone, which holds for this whole series: the most common reaction of somebody receiving a message like this is understanding, not recrimination. Most people have dealt with a compromised account or seen one close up. The fear of being judged is almost always larger than the actual judgement — and it is the main reason these communications get postponed past the point where they help.
Which consequences close and which do not
A useful picture for knowing where to spend your energy after an incident.
| Consequence | Can it be closed? |
|---|---|
| Active sessions | Yes, by revoking them |
| Forwarding rules and connected apps | Yes, by removing them |
| Recovery methods that are not yours | Yes, by replacing them |
| Future sign-ins | Yes, with a new password and a second factor |
| Information already read | No |
| Messages already delivered to recipients | No |
| Documents already copied | No |
| Your contacts’ trust | Only with time and transparency |
The first four rows close in half an hour, and they are the only ones where immediate action changes anything. The others do not close, and pressing on them is what makes the experience wearing without producing results.
The practical criterion: act on what is still active, communicate about what is not. It is a simple division, and it helps get out of the cycle of constant checking many people stay in for weeks.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Understanding that delay changes the nature, not only the scale |
| Skills | Knowing the correct order of the closing actions |
| Secure Behaviour | Telling those who were involved without knowing |
Reference level: FL2 — Beginner.
Summary
- A sign-in discovered late is not a bigger event: it is a period, and it behaves differently.
- The worst damage is not being able to reconstruct what was touched.
- People who made no mistake at all are involved: the ones who wrote to you.
- The order of the actions matters: configurations first, password afterwards.
One thing to do today. Turn on security alerts for your main email. It is the only measure that turns a period into an event.
Related content
- Account login alerts — the recommendation this expands on
- Impact of an undetected login — what accumulates technically over time
- How to turn on login alerts — the configuration, service by service
- Attacks that rely on delayed detection — why time is a resource for whoever attacks
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



