Recovery

How to Recover a Hacked Account

Discovering that one of your accounts has been hacked is alarming, but acting quickly and methodically can minimize damage and restore your security. This guide walks you through the recovery process for major platforms.

Key Takeaways

  • โœ“ Act immediately โ€” change passwords, revoke sessions, and secure recovery options within minutes of discovering the breach
  • โœ“ Recover email first โ€” it is the master key to resetting passwords for all other accounts
  • โœ“ Enable 2FA with an authenticator app immediately after recovering each account
  • โœ“ Scan all your devices for malware and monitor financial accounts for at least 90 days after recovery

Immediate Steps

The first few minutes after discovering a hack are critical. Attackers often change passwords, update recovery information, and begin exploiting access within seconds of breaching an account. Your response must be fast and methodical.

Step 1: Change your password immediately. If you can still log in, go straight to the account settings and change the password. Choose a strong, unique password that you have never used before. A passphrase of 4-5 random words is both more secure and easier to remember than a complex password with symbols. Do not reuse any password from another site. If you cannot log in because the password has already been changed, proceed to the platform-specific recovery steps below.

Step 2: Revoke all active sessions. Most platforms show a list of currently active sessions or devices. Go to security settings and revoke every session. This forces the attacker out of your account immediately. Pay attention to any unfamiliar locations, browsers, or devices in the session list โ€” note them for later investigation. Even after the password change, active sessions may persist for some platforms, so session revocation is a critical separate step that is often overlooked.

Step 3: Check and update recovery information. Attackers often add their own recovery email address or phone number to maintain access after you change the password. Go to account security settings and verify that your recovery email, phone number, and security questions are yours. Remove anything unfamiliar. This is the most commonly missed step โ€” users change the password but the attacker still has a recovery email linked and simply resets the password again.

Step 4: Check for forwarding rules (especially email). Email attackers frequently set up inbox forwarding rules to receive a copy of all incoming emails. In Gmail, Outlook, and Yahoo, check Settings > Forwarding and ensure no unfamiliar forwarding addresses exist. Also check filter rules โ€” attackers sometimes use filters to hide security alert emails from you while they take over accounts.

Email Account Recovery

Email is the most important account to recover because it is used to reset passwords for almost every other service. Prioritize email recovery above all else.

Gmail recovery: Go to the Gmail sign-in page and click "Forgot email?" or "Forgot password?" depending on what was changed. Google walks you through a recovery flow that asks for your last remembered password and access to your recovery email or phone. If the attacker changed your recovery information, Google offers an account recovery form that asks detailed questions about your usage history โ€” when you created the account, labels you created, emails you sent to specific contacts. Fill this out as accurately as possible. Google's recovery system is largely automated, so detailed accurate answers improve your chances significantly. The process typically takes 24-48 hours.

Outlook / Microsoft account recovery: Visit account.live.com/acsr. Microsoft's recovery form asks for the email address, a contact email where you can be reached, and information about the account such as previous passwords, subject lines of recent emails, and names of contacts. Microsoft's recovery process is more manual than Google's โ€” expect 24 hours for a response. If you have a paid Microsoft 365 subscription, you can contact support directly for faster service.

Yahoo recovery: Visit the Yahoo account recovery page and enter your email. Yahoo sends a verification code to your recovery phone or alternate email. If you no longer have access to either, Yahoo provides a manual verification process that may ask for your birth date and answers to security questions. Yahoo's recovery is typically faster than Google or Microsoft because the security questions option reduces friction, but this also means security questions are a weak point โ€” if the attacker changed them, recovery is more difficult.

Social Media Recovery

Social media accounts are prime targets for hackers because they can be used to spread spam, scams, and malware to your followers. Recovery processes vary by platform.

Facebook recovery: Go to facebook.com/login/identify. Enter your email or phone number. Facebook offers recovery through your trusted contacts (you selected 3-5 friends who can give you recovery codes), a recovery email address, or identity verification by uploading a photo ID. The trusted contacts method is the fastest if you set it up before the hack. If you did not set it up, the ID verification process takes 1-3 days. For detailed instructions, see our how to set up 2FA for Facebook guide.

Instagram recovery: Open the Instagram app and tap "Get help signing in." Instagram offers recovery via email or phone number. If the attacker changed both, tap "Need more help?" and follow the identity verification flow, which may include receiving a code to your registered email or submitting a video selfie. Instagram's selfie verification is controversial but effective โ€” it uses AI to compare your face to photos on your account. This process can take up to 48 hours.

Twitter / X recovery: Visit the X login page and click "Forgot password?" Enter your email, phone number, or username. If the attacker changed the password and recovery info, select "I can't access this email or phone number" and file a support ticket. X's support is notoriously slow for account recovery โ€” prepare for several days to a week. Having a verified email or phone on the account before the hack significantly speeds things up. See our how to set up 2FA for Twitter/X guide for prevention tips.

LinkedIn recovery: Go to linkedin.com/help and click "Recover account." LinkedIn offers recovery via email, phone number, or a support ticket. LinkedIn's support is generally responsive, with recovery typically completed within 24 hours. If the attacker changed your email and phone, you will need to verify your identity with a government-issued ID.

Financial Account Recovery

Financial accounts require the highest priority after email. Time is critical because attackers can move funds in seconds.

Bank account recovery: Call your bank immediately. Do not rely on online recovery forms for financial accounts โ€” a phone call is faster and allows you to speak directly with fraud prevention. Most banks have 24/7 fraud hotlines. Tell the representative your account has been compromised. They will freeze the account, reverse any unauthorized transactions (within the fraud window), and guide you through setting up new credentials. Banks typically have strong fraud protection, but you must act quickly โ€” unauthorized transactions made more than 60 days after your statement are often not reimbursable under Regulation E.

PayPal recovery: Go to paypal.com and click "Having trouble logging in?" If you can still access your account, go to Settings > Security and change your password, update security questions, and review linked bank accounts and cards. Remove any unfamiliar financial links. If locked out, call PayPal support โ€” they have a dedicated fraud team. PayPal's Purchase Protection and seller protection policies may cover unauthorized transactions, but you need to report them promptly.

Crypto exchange recovery: Cryptocurrency exchanges have the most time-sensitive recovery needs because crypto transactions are irreversible. Contact the exchange's support immediately. Most major exchanges (Coinbase, Binance, Kraken) have 24/7 support for compromised accounts. They will lock the account, change credentials, and investigate. If the hacker already withdrew funds, there is very little that can be done to recover the crypto โ€” which is why enabling 2FA on crypto accounts before anything happens is critical. See our best 2FA for crypto accounts guide for prevention.

Enable 2FA After Recovery

Once you have recovered an account, the single most important step to prevent re-compromise is enabling two-factor authentication. Without 2FA, the attacker only needs to find or guess your new password to regain access.

Use an authenticator app, not SMS: SMS 2FA is better than nothing, but app-based TOTP is significantly more secure. After a hack, you should use the strongest available 2FA method. Install Google Authenticator, Authy, or Microsoft Authenticator and scan the QR code provided by each service. For the strongest protection, use a hardware security key (FIDO2) if the platform supports it. For platform-specific setup guides, see our Gmail 2FA setup and other platform guides.

Generate and store backup codes: Every platform that offers 2FA also provides backup codes โ€” typically 8-10 one-time codes that work if you lose access to your authenticator app. Download these codes immediately and store them in a secure place: your password manager is the best option. Print a physical copy and keep it in a safe location. Without backup codes, a lost phone after a hack could lock you out again permanently.

Revoke old 2FA methods: If the attacker set up their own 2FA on your account, revoke it. Check the security settings for any registered authenticator apps, phone numbers, or hardware keys that you do not recognize. Remove them immediately after you regain access.

Scan for Malware

Your account was likely hacked through one of three vectors: a data breach (your password was leaked), a phishing attack (you entered your password on a fake site), or malware on your device. If malware is involved, changing passwords alone will not help โ€” the malware will capture the new credentials.

Run a full system scan: Use Windows Defender (built into Windows 10 and 11), Malwarebytes, or Bitdefender to run a full offline scan. An offline scan runs before the operating system boots, which catches malware that hides from standard scans. On macOS, run a scan with Malwarebytes for Mac. While macOS malware is less common than Windows malware, it does exist and is increasingly targeting credential theft.

Check browser extensions: Malicious browser extensions are one of the most common credential theft vectors. They can read everything you type into websites, including passwords. Open your browser's extension settings and remove any extension you do not recognize, any extension that was installed without your knowledge, and extensions that have permissions to "read and change all your data on websites you visit." If you see extensions you did not install, that is a strong indicator of malware or a browser takeover.

Check for keyloggers: Keyloggers record every keystroke. They are commonly installed through phishing attachments or drive-by downloads. In addition to a standard antivirus scan, use a dedicated anti-keylogger tool like KeyScrambler or Zemana AntiLogger. Check your startup programs for unfamiliar entries โ€” keyloggers often persist through system reboots by registering as startup applications.

Secure your password manager: If you use a password manager, check that it has not been compromised. Change your password manager's master password, enable 2FA on the password manager itself, and review recent login activity. Most password managers (1Password, Bitwarden, Dashlane) show a list of recent access attempts.

Monitor for Further Damage

Account recovery is not the end of the process. Attackers may have used your accounts for fraud, identity theft, or other abuse before you regained control. Monitoring for the next several months is essential.

Credit monitoring: If the attacker had access to your financial accounts or personal information, they may attempt identity theft. Freeze your credit with the three major bureaus (Equifax, Experian, and TransUnion) โ€” a credit freeze prevents anyone from opening new accounts in your name. You can do this for free and it remains in place until you lift it. Set up credit monitoring alerts to be notified of any new accounts or inquiries. Services like Credit Karma and Experian offer free monitoring.

Identity theft protection: If your Social Security number, driver's license, or passport was exposed, consider a dedicated identity theft protection service like Aura, IdentityForce, or LifeLock. These services monitor dark web marketplaces for your personal information and provide dedicated recovery assistance if identity theft occurs. Many offer insurance coverage for identity theft losses and legal fees.

Account activity alerts: Enable notifications for account activity on every recovered account. Most platforms support email or push notification alerts for new logins, password changes, profile changes, and suspicious activity. Configure these alerts to be immediate (not daily digests) so you can respond to any new compromise attempt in minutes instead of days. Check your account activity logs weekly for at least 90 days after recovery.

Check haveibeenpwned.com: Visit haveibeenpwned.com and enter all your email addresses. This service aggregates data breach information and tells you exactly which breaches your email appeared in. If your credentials were part of a known breach, change the password on that site immediately. The site also monitors for future breaches and can send you an alert if your email appears in a new breach.

Prevention tip: After recovering your accounts, use 2faco.com to generate TOTP codes directly in your browser and keep your accounts protected without installing another app.

Related Articles