Realizing you’ve been hacked — whether it’s a single email account, a social media profile, or your entire computer — is unsettling. But panic is the enemy of a good recovery. Attackers count on confusion and hesitation; the faster and more methodically you respond, the less damage they can do. This guide walks through what to do in the minutes, hours, and days after discovering a compromise. It’s written to apply no matter where you live or which platforms and banking system you use.
First, figure out what you’re dealing with
Before acting, take a minute to identify the scope of the problem:
- One account (email, social media, a single app) showing signs of unauthorized access — your password no longer works, there are unfamiliar posts or messages, or you’re getting login alerts you didn’t trigger.
- A device (computer or phone) behaving strangely — pop-ups, unfamiliar programs, extreme slowness, files that are encrypted or missing, or a webcam light turning on unexpectedly.
- Multiple accounts or a company data breach — a service you use has announced a breach and confirmed your information was included.
Each situation calls for a slightly different first move, but the overall priorities are the same: cut off the attacker’s access, secure your most important accounts first, then work outward.
Immediate steps — do these first
1. Disconnect if a device is compromised. If you suspect malware, ransomware, or that someone has remote access to your computer or phone, disconnect it from the internet right away — turn off Wi-Fi, unplug the ethernet cable, or switch on airplane mode. This cuts off live access and stops malware from spreading to other devices on your network or sending out more of your data. Don’t wipe the device yet if you might need it inspected later (for a work IT team, an insurance claim, or a police report) — disconnecting is usually enough for the moment. If it’s a work device, loop in your IT or security team before doing anything else.
2. Secure your email account first. Email is the master key to almost everything else you own online, since it’s usually how you reset every other password. If you can still get into it:
- Change the password immediately to something long and unique.
- Check the recovery settings (backup email, phone number, security questions) to confirm the attacker hasn’t added their own.
- Look for new forwarding rules or filters. A common trick is to quietly forward copies of your incoming mail to the attacker, even after you’ve changed the password.
- Review connected third-party apps and revoke anything you don’t recognize.
- Turn on multi-factor authentication (MFA) if it isn’t on already.
If you’re locked out of your email entirely, start the provider’s official account-recovery process immediately. The longer someone else holds your email, the more they can do with it.
3. Change passwords on your other important accounts. Move on to banking, cloud storage, social media, and work accounts next — especially any that shared the same or a similar password. Give each one a unique password; a password manager makes this painless. Never reuse a password that may have been exposed.
4. Log out everywhere and revoke unfamiliar access. Most major platforms let you view active sessions and sign out of all devices at once, and let you review and remove connected apps, browser extensions, or API tokens. A new password doesn’t help much if the attacker still has an active session open somewhere.
5. Turn on multi-factor authentication. If it isn’t already active on your key accounts, enable it now. An authenticator app or hardware security key is stronger than text-message codes, but SMS-based MFA is still far better than none at all.
Check how deep the compromise goes
Once the immediate bleeding has stopped, look for lingering damage:
- On accounts: unfamiliar payment methods, shipping addresses, or linked accounts; sent messages you didn’t write; changed profile or recovery details.
- On devices: unfamiliar programs, browser extensions, or admin/user accounts. Scan with reputable, up-to-date antivirus or anti-malware software. If the scan turns up something serious — ransomware, a rootkit, or an infection that keeps coming back — consider backing up your personal files (scanning them first) and doing a full reinstall of the operating system. Some malware is built to survive a simple scan-and-remove.
- On finances: review recent bank and card statements line by line for anything unfamiliar.
If ransomware has encrypted your files and is demanding payment, most national cybersecurity agencies advise against paying: it doesn’t guarantee you’ll get your data back, and it funds further attacks. Report it (see below) and look for free decryption tools — projects like No More Ransom aggregate these — before considering any other option.
Protect your money
If there’s any chance your card details, bank information, or other financial data was exposed:
- Contact your bank or card issuer directly, using the number on the back of your card or their official app or website — not a number or link from a suspicious email or text. They can freeze the card, reverse fraudulent charges, and issue a replacement.
- If your country has a credit bureau or similar reporting system, look into a fraud alert or credit freeze, which stops new accounts being opened in your name. Availability and process vary a lot by country, so search for “[your country] credit freeze” or simply ask your bank what’s available locally.
- Keep monitoring your statements for weeks afterward. Some fraud shows up well after the initial breach.
Contain the spread — warn the people around you
If the attacker used your email or social media to message your contacts, your friends, family, or colleagues could be targeted next using your name as bait. Send a quick, clear heads-up — a short message or post explaining that your account was compromised and that any strange messages “from you” during that window weren’t really from you.
If a work account or device was involved, tell your IT or security team right away, even if you’re not sure how serious it is. Organizations usually need to act fast to protect other employees and systems, and reporting early is almost never held against you.
Report it
Reporting does two things: it can help you recover losses, and it helps authorities track patterns that protect other people.
- Report to the platform itself. Most major services — email providers, banks, social networks — have a dedicated “my account was hacked” process that moves faster than general customer support.
- Report to your national cybercrime authority. Nearly every country has some official channel for this, though the names differ. In the United States, it’s the FBI’s Internet Crime Complaint Center (IC3.gov). In the United Kingdom, it’s Report Fraud (reportfraud.police.uk), the national fraud and cybercrime reporting service run by the City of London Police, which took over from the older Action Fraud service in early 2026. In Australia, it’s ReportCyber, run through the Australian Signals Directorate’s Cyber Security Centre (cyber.gov.au). Most other countries have an equivalent national CERT or CSIRT (Computer Emergency Response Team) — for example, CERT-FR in France or ngCERT in Nigeria — and the nonprofit FIRST.org maintains a public directory of national teams worldwide if you’re unsure where to start. If nothing else is available, your local police non-emergency line can usually point you in the right direction.
- Report to your national data protection authority, if one exists, especially when a company’s breach — not something you did — exposed your data. Many countries, including all EU member states under GDPR and a growing number of others, have a body set up specifically for this.
- File a police report if money was stolen or your identity was used fraudulently. You may need the report reference number for insurance claims or bank disputes.
Watch for identity theft
Especially after a breach involving personal details like ID numbers, date of birth, or home address, keep an eye out for:
- Accounts or loans you never opened
- Unexpected bills, tax notices, or government correspondence about accounts unfamiliar to you
- Calls from debt collectors about debts that aren’t yours
If you spot any of these, contact the institution directly and, if available, your country’s fraud or identity-theft resource. Acting quickly limits how much damage can build up.
It’s not your fault — and that matters
Feeling shaken, embarrassed, or even a little foolish after being hacked is completely normal, and it isn’t a reflection of carelessness on your part. Phishing emails, fake login pages, and social engineering tactics are specifically designed to fool careful, intelligent people — that’s their entire purpose. Hiding what happened out of embarrassment usually makes things worse, since the people around you can’t help protect themselves, or you, if they don’t know. Telling your bank, your employer, or your contacts promptly is one of the most effective things you can do.
Reduce the chance it happens again
Once things are stable, a few habits go a long way:
- Use a password manager so every account has a long, unique password you don’t have to remember.
- Turn on MFA everywhere, preferring an authenticator app or hardware key over SMS where you can.
- Keep software updated — operating system, browser, and apps — since many attacks exploit known vulnerabilities that have already been patched.
- Back up important files regularly, ideally following the 3-2-1 rule: three copies, on two different types of storage, with one kept offline or offsite. This is your best protection against ransomware.
- Be skeptical of unexpected links and attachments, even from people you know — their account may be compromised too.
- Check periodically, not just after an incident, whether your email shows up in known data breaches using a reputable breach-checking service, and review your accounts’ connected apps and active sessions every so often.
Being hacked is stressful, but it’s rarely unrecoverable. Work through the list methodically, prioritize your email and financial accounts first, and don’t hesitate to involve your bank, employer, or local authorities — they exist for exactly this kind of situation.
