Risk:High — Account takeover lets an intruder control your profile, intercept recovery messages, impersonate you and lock you out.
Install the app:Open the app and verify suspicious content in one scan.
Account Takeover Prevention and Recovery Guide
When this applies
Use this account takeover prevention guide if you entered a password or verification code after following an unexpected link, approved an unfamiliar login, or noticed account changes you did not make. A typical takeover page may ask you to “sign in to continue” and then request a one-time code. Treat any login you did not initiate from the service’s official site or app as potentially compromised.
Decision steps in order
- Open the genuine service directly from a trusted device; do not revisit the link or reply to the sender.
- If you can still sign in, change the password immediately and choose one that is unique to that account.
- Review active sessions or signed-in devices, then sign out every session you do not recognize—or all sessions if that option exists.
- Check the recovery email, phone number, authentication methods and backup codes; remove anything you did not add.
- Secure the connected email account next, because an intruder can use it to reset other passwords. Change its password, revoke unknown sessions and inspect forwarding rules or filters.
- Turn on multi-factor authentication using an authenticator or security key where available. Generate new backup codes if previous codes may have been exposed.
- Review recent messages, posts, purchases, payment details and security notifications, then warn contacts if the account sent anything without your permission.
If you already responded
- If you only clicked, close the page and check whether anything downloaded; clicking alone does not always mean the account was taken.
- If you entered a password, change it anywhere else you reused it.
- If you shared a one-time code or approved a login, revoke sessions before changing credentials.
- If you are locked out, use the service’s official recovery page and preserve screenshots of alerts, messages and unauthorized changes.
- Contact the bank or payment provider immediately if the compromised account shows unauthorized transactions or altered payment information.
Most common warning signals
- A login alert shows a device, location or time you do not recognize.
- Your password stops working even though you did not change it.
- The account’s recovery email address or phone number has changed.
- Messages, posts or purchases appear that you did not create.
- An unexpected page asks for both your password and a one-time code.
- A multi-factor authentication prompt appears when you are not signing in.
- Email forwarding rules or filters appear that you did not configure.
What to do now
- Open the genuine service directly on a trusted device.
- Revoke unfamiliar or all active sessions.
- Change the account password to a unique password.
- Secure the connected email account and remove unknown forwarding rules.
- Remove unauthorized recovery details and authentication methods.
- Enable multi-factor authentication and replace exposed backup codes.
- Review activity and report unauthorized payments immediately.
Sources
Further reading
- High-Risk Account Link Scam Warning for 2026
- Customs Fee Delivery Scam: 6 Checks Before Paying
- University Password Expiry Phishing Photo Alert
FAQ
What should I do if I reused the stolen password?
Change the reused password on every affected account, starting with your email and financial accounts, and use a different unique password for each one.
Is my account compromised if I clicked but entered nothing?
Not necessarily. Close the page, delete any downloaded file without opening it, and check your account’s login history and security alerts.
How do I recover an account after the attacker changed my password?
Use the service’s official account-recovery process, secure the connected email account, preserve security alerts, and report any unauthorized payments separately.