Skip to main content

6.1 Account Compromise

Compromised Email Account

Signs your email might be compromised:

  • Can't log in / password doesn't work
  • Emails you didn't send in your sent folder
  • New forwarding rules or filters you didn't create
  • Password reset emails you didn't request
    • Even assuming the reset email is not a phishing attempt, this is not necessarily a major warning sign, but if you recieved a password reset email for a website or service and then lose access to that service it is possible someone used that email to reset your password
  • Contacts reporting spam from you

Step 1: Regain Control if Locked Out (IMMEDIATELY)

  • Go to the email provider's recovery page

  • Use your recovery email or phone number to reset your password

  • If recovery fails, contact provider support immediately

  • Change password to a strong, unique password (20+ characters)

  • Store new password in your password manager

  • Remove ALL authorized devices from account settings

  • Re-add only your trusted devices

Step 2: Update Security Settings (Within Minutes)

  • Verify recovery email and phone number are correct

  • Update security questions (if applicable) with new answers

  • Enable MFA if not already enabled

  • If MFA is already enabled, remove all MFA devices and re-add only yours

  • Save new recovery codes in password manager

Step 3: Damage control (Within Hours)

  • Check for and remove any email forwarding rules you didn’t create

  • Review sent folder for emails you didn’t send

  • Review recently deleted emails

  • Check for auto-replies or vacation responders you didn’t set

  • Alert contacts immediately if spam / phishing was sent from your account

  • Review inbox filters and labels for suspicious rules

  • Check for password reset emails from other services

    • If found, secure those accounts immediately (see relevant sections below)

Step 4: Additional Actions

  • Monitor account daily for 1 week for suspicous activity

  • If sensitive information was accessed, consider notifying affected parties (contacts and calendar invites often contain sensitive information)

Compromised Password Manager

This is the worst-case scenario. Act fast!

Signs your password manager is compromised:

  • Can't log in with your master password

  • Unauthorized devices in account settings

  • Notifications of success password changes you didn't initiate

  • Unfamiliar new entries or missing entries in your vault

Step 1: Regain Control (IMMEDIATELY)

  • If you can still log in

    • Change master password

    • Remove ALL authorized devices

    • Re-add only your trusted devices

  • If locked out and recovery is available

    • Use your password manager’s account recovery process

    • Follow provider’s emergency access procedures

    • Once recovered, change master password

  • If locked out with no recovery

    • Create new password manager account

Step 2: Reset All Passwords In Your Vault (IMMEDIATELY – this takes time)

Assume every account in your vault is compromised. Work through tiers in order. For EACH account changed:

  1. Change password to new unique password

  2. Remove all authorized devices

  3. Enable or verify MFA

  4. Check recent activity

  5. Verify security questions and recovery settings

  6. Check for account-specific issues (email forwarding, rofile changes, etc)

Tier 1 – Immediately

  • Password manager account itself (if recovered)
  • Recovery email addresses
  • All other email accounts

Tier 2 – Within 1 Hour

  • Banks and credit unions

  • Investment accounts

  • PayPal, Venmo, payment processors

  • Credit card accounts

Tier 3 – Within 4 Hours

  • Cloud storage (Google Drive, iCloud, OneDrive, Dropbox, etc)

  • Medical portals

  • Social media accounts (Facebook, Twitter, LinkedIn, etc)

Tier 4 – Within 12 Hours

  • Shopping sites (Amazon, eBay, etc)

  • Gaming accounts (Steam, Xbox, Discord)

  • Streaming services (Netflix, Hulu, AppleTV, etc)

Tier 5 – Within 24 Hours

  • Everything else

Step 3: Additional Actions

  • Monitor all financial accounts daily for 1 week

  • Review credit reports for unauthorized activity

  • Consider placing fraud alert on credit reports

  • Document which accounts were in vault when compromised

  • File police report if identity theft of financial fraud occurred

Compromised Financial Account

(Bank, credit union, credit card, investment account, etc)

Signs of compromise:

  • Unauthorized transactions
  • Can't log in / password doesn't work
  • Alerts about new devices or locations
  • New accounts or cards you didn't open
  • Unexpected credit inquiries

Step 1: Regain Control (IMMEDIATELY)

  • Call the fraud number on the back of your card

  • Ask them to:

    • Freeze the account

    • Document the compromise

    • Issue new cards

    • Enable enhanced monitoring

  • Report known unauthorized transactions and explain you will call back after a full review

  • If you cannot log in, reset the password using recovery options

  • Once logged in, change the password to a strong, unique password

  • Store new password in your password manager

  • Remove ALL authorized devices from account settings

  • Re-add only your trusted devices

Step 2: Update Security Settings (Within Minutes)

  • Verify recovery email and phone number are correct
  • Update security questions (if applicable) with new answers
  • Enable MFA if not already enabled
  • If MFA is already enabled, remove all MFA devices and re-add only yours
  • Save new recovery codes in password manager
  • Verify linked external accounts
  • Review authorized card users

Step 3: Damage Control (Within Hours)

  • Review all recent transactions (go back 90 days)
  • Document every transaction you didn’t make
  • Check for, document, and correct where possible:
    • New accounts opened in your name
    • Credit applications you didn’t submit
    • Chagned account settings (address, email, phone)
    • New beneficiaries or authorized users
  • For payment apps (Venmo, Paypal, etc) review sent messages for phishing attempts
  • Call the fraud line back and report all unauthorized activity

Additional steps:

  • File a police report (required for most fraud disputes)

  • Place fraud alert on credit reports with all three bureaus:

    • Equifax: 888-766-0008

    • Experian: 888-397-3742

    • TransUnion: 800-680-7289

  • Monitor credit reports monthly for 6 months

  • Consider credit freeze if multiple accounts were affected

  • Monitor affected financial accounts daily for 2 weeks

Compromised Social Media Account

(Facebook, Twitter/X, Instagram, LinkedIn, forums, etc)

Signs of compromise:

  • Can't log in / password doesn't work

  • Posts you didn't make

  • Messages sent from your account

  • New friends or followers you didn’t send

  • Profile information changed

  • Friends reporting spam from you

Step 1: Regain Control (IMMEDIATELY)

  • Use platform-specific recovery:
    • Facebook: facebook.com/hacked
    • Instagram: help.instagram.com
    • Twitter/X: help.twitter.com
    • LinkedIn: linkedin.com/help
  • Reset password using recovery email or phone
  • Once logged in, change the password to a strong, unique password
  • Store new password in your password manager
  • Remove ALL authorized devices from account settings
  • Re-add only your trusted devices
  • If you cannot recover your account:
    • Create new account and notify contacts
    • Ask friends to unfriend/unfollow compromised account

Step 2: Update Security Settings (Within Minutes)

  • Verify recovery email and phone number are correct
  • Update security questions (if applicable) with new answers
  • Enable MFA if not already enabled
  • If MFA is already enabled, remove all MFA devices and re-add only yours
  • Save new recovery codes in password manager
  • Check for connected accounts (e.g., "Sign in with Facebook" to other services)
  • Revoke access to third-party apps you don’t use

Step 3: Damage Control (Within Hours)

  • Alert friends/contacts if spam was posted or sent

  • Post a public message explaining the compromise

  • Message close contacts directly

  • Review and delete posts you didn't make

  • Review and delete messages sent from your account

  • Check friend/follower lists for accounts you didn't add

  • Remove suspicious connections

  • Review profile information and undo any changes

  • Check privacy settings

  • Review tagged photos and posts

Step 4: Additional Actions

  • Monitor account daily for 1 week for new suspicious activity

  • Report the compromise to the platform

  • If personal information was exposed, consider notifying affected individuals

Compromised Cloud Storage Account

(Google Drive, OneDrive, iCloud, Dropbox, etc)

Signs of compromise:

  • Can't log in / password doesn't work

  • Files you didn't upload or share

  • Sharing notifications you didn't create

  • New devices accessing your files

  • Unusual storage usage

Step 1: Regain Control (IMMEDIATELY)

  • Reset password using recovery email or phone

  • Change password to strong, unique password

  • Store new password in password manager

  • Remove ALL authorized devices and active sessions

  • Re-add only your trusted devices

Step 2: Update Security Settings (Within Minutes)

  • Verify recovery email and phone number

  • Update security questions if available

  • Enable or verify MFA

  • Save recovery codes in password manager

  • Revoke access to ALL third-party apps

  • Re-authorize only apps you actively use

Step 3: Damage Control (Within Hours)

  • Review all shared files and folders and remove unauthorized users

  • Remove public sharing links you didn't create

  • Review recently accessed files for sensitive data exposure

  • Check for files you didn't upload and delete them

    • If you must open them to verify, download and perform a virus scan first!

  • Review deleted files folder for files you didn't delete

  • Check activity log for unauthorized downloads

  • If sensitive files were accessed:

    • Note which files (financial docs, passwords, personal info)

    • Determine what actions to take based on exposure (change passwords, notify affected parties)

Step 4: Additional Actions

  • Download audit log if available (Google and Microsoft offer this, but availability varies by account type and region)

  • Monitor account daily for 1 week

  • If sensitive data was exposed, take appropriate action:

    • Financial documents - monitor accounts, consider credit freeze

    • Passwords - change affected passwords

    • Personal identification - consider identity theft protection

  • Review all devices with cloud app installed

Compromised Shopping Account

(Amazon, eBay, Etsy, etc)

Signs of compromise:

  • Unauthorized orders

  • Can't log in / password doesn't work

  • New payment methods you didn't add

  • Changed shipping address

  • Gift cards purchased without your knowledge

Step 1: Regain Control (IMMEDIATELY)

  • Reset password using recovery email or phone

  • Change password to strong, unique password

  • Store new password in password manager

  • Remove ALL authorized devices

  • Re-add only your trusted devices

Step 2: Update Security Settings (Within Minutes)

  • Verify recovery email and phone number

  • Update security questions if available

  • Enable or verify two-step verification

  • Save recovery codes in password manager

Step 3: Damage Control (Within Hours)

  • Review ALL orders (including cancelled orders)

  • Cancel any unauthorized pending orders

  • Contact seller to cancel shipped unauthorized orders

  • Report unauthorized orders to platform

  • Review and remove unauthorized payment methods

  • Check for unauthorized gift card purchases or balances

  • Verify shipping addresses and remove unauthorized addresses

  • Review account balance or store credit for unauthorized changes

  • Check wish lists and shopping lists for changes

  • Review seller account for unauthorized listings (if you have one)

Step 4: Additional Actions

  • Dispute unauthorized charges with credit card company

  • Monitor payment methods for unauthorized charges

  • File police report if fraud amount is significant

  • Contact platform customer service to document compromise

If Any Other Account is Compromised

Signs of compromise:

  • Unauthorized transactions
  • Can't log in / password doesn't work
  • Alerts about new devices or locations
  • Alerts about personal information updates
  • Account information changes you didn’t make
  • Notifications about password changes you didn’t initiate

Step 1: Regain Control (IMMEDIATELY)

  • Use the site's password recovery to reset password

  • Change password to strong, unique password

  • Store new password in password manager

  • Remove ALL authorized devices and active sessions

  • Re-add only your trusted devices

Step 2: Update Security Settings (Within Minutes)

  • Verify recovery email and phone number
  • Update security questions if available
  • Enable or verify two-step verification
  • Save recovery codes in password manager
  • Revoke access to all third-party apps (if applicable)
  • Re-authorize only apps you actively use (if applicable)

Step 3: Damage Control (Within Hours)

  • Review recent account activity for unauthorized actions:

    • Purchases or transactions

    • Posts, messages, or comments

    • Profile or account information changes

    • Privacy setting changes

    • Friend/connection requests sent

  • Undo unauthorized changes

  • Delete unauthorized content

  • Alert contacts if spam/phishing was sent from your account

  • Review any sensitive data that may have been accessed

  • Check for linked accounts ("Sign in with..." connections)

Step 4: Additional Actions

  • Report the compromise to the service provider

  • Monitor account daily for 1 week for suspicious activity

  • Review connected services, secure any that use this account for login

  • If financial loss occurred, file police report (also review Compromised Financial Account playbook)

  • Document the incident for your records

  • Consider whether any legal/regulatory notifications are required