If You Get Hacked: A Calm Response Plan
A clear, ordered plan for the moment something goes wrong. Panic makes things worse; method makes them recoverable. Here's exactly what to do, and in what order, if an account or device is compromised.
Even careful people get caught sometimes — a password leaks, a convincing scam lands, a device goes missing. What separates a scare from a catastrophe is having a plan before you need one. If something's wrong right now, take a breath: methodical action beats panic every time, and most situations are recoverable if you move in the right order.
First, contain it
Your first job is to stop the bleeding — cut off the attacker's access before you clean up.
- Change the password on the affected account, using a different, trusted device if you suspect the one in your hand is compromised.
- Sign out everywhere. Most services have a "log out of all sessions" option — use it to kick the attacker off.
- Turn on two-factor authentication if it wasn't already, so a stolen password alone can't get back in.
- Check the recovery details — the recovery email and phone number. Attackers change these to lock you out, so set them back to yours.
Protect what's connected
Accounts are linked, so think about the blast radius. If your email was compromised, treat it as the emergency it is — it can reset everything else, so secure it first and then check the accounts tied to it. If you reused the breached password anywhere, change it on those accounts too. If money is involved, contact your bank or card issuer and watch for unfamiliar charges.
If something's wrong as you read this, don't try to figure out everything at once. Start with the single most important account — usually email — change its password from a device you trust, sign out all sessions, and turn on 2FA. Then work outward from there.
Match the response to the situation
Different incidents need different first moves. These step-by-step emergency guides walk you through the exact actions:
- A hacked account — regaining control and locking it back down.
- A suspicious login alert — telling a real warning from a fake one.
- Clicked a phishing link — what to do in the minutes after.
- A lost or stolen phone — locking and erasing it remotely.
- Sent money to a scammer — acting fast to improve your odds of recovery.
Clean the device if needed
If malware might be involved, run a scan with your device's built-in security tools, remove any unfamiliar programs or browser extensions, and make sure everything is updated. In a serious case, restoring from a clean backup is the surest way to know the device is truly clean — another reason those backups are worth having.
Afterward: learn, don't blame
Once you're back in control, take a quiet minute to notice how it happened — a reused password, a convincing message, a missing second factor — and close that specific gap. This isn't about self-blame; it's how one bad day becomes the reason the next attempt fails. Getting hacked doesn't mean you failed. Handling it calmly means you won.
Tell the people who need to know
Containing the account is step one, but a compromise often ripples outward, and a few quick heads-ups limit the damage.
- Warn your contacts if your email or social account was taken over — attackers use it to scam the people who trust you, and a simple "if you got an odd message from me, ignore it" stops that cold.
- Notify your bank the moment money or payment details are involved, so they can watch for fraud and reverse what they can.
- Report it to the platform (most have a hacked-account recovery flow) and, for financial fraud or identity theft, to the relevant authorities — a report can matter later for disputes.
Watch for the slow aftermath
Some damage shows up days or weeks later, so stay alert for a while after the initial cleanup. Keep an eye on account statements for unfamiliar charges, be extra skeptical of "we noticed suspicious activity" messages (scammers pile on after a breach), and if sensitive identity information was exposed, consider a credit freeze so no one can open accounts in your name. The immediate scramble is the loud part, but a calm second pass a week later — confirming everything's locked and nothing new has appeared — is what turns a bad day into a closed chapter rather than a lingering problem.
Keep this plan somewhere you can find it when you're stressed, because the order matters more than the speed. Contain the account, protect what's connected, tell who needs to know, clean up, and learn — work through it calmly and even a serious compromise becomes something you handled rather than something that happened to you.
Key takeaways
- Contain first: change the password, sign out all sessions, enable 2FA, fix recovery details.
- Secure email first — it can reset everything else — then any account sharing that password.
- Use the matching emergency guide for the specific incident.
- Clean or restore the device if malware's involved, then close the gap that let it happen.
Quick quiz
A couple of quick questions to lock in what you just read. Nothing is saved — pick an answer to see if you got it.
-
Which account should you secure first after a suspected hack?
Email is the master key that resets everything else.
-
After regaining access, what should you check for?
Attackers plant these to keep access even after you change your password. Remove anything you did not set up.
-
What is the right mindset in the first hour?
A calm, ordered plan limits the damage far better than panic.
Keep going
Subscribe for new lessons and a printable security checklist.