Signs that suggest your account has been compromised
A hacked account means someone else has gained access to your login credentials and can read your messages, change your password, or use your identity. The clearest signs are changes you did not make: a password that no longer works, emails you do not recognize in your sent folder, friends reporting messages from you that you never wrote, or a notification that your password was recently changed.
Other warning signs include missing money from a linked bank account or credit card, new apps or devices connected to your account that you do not own, a recovery email or phone number you do not recognize, or a sudden flood of spam or phishing emails sent from your address. Some hacks are silent — the person accessing your account may be watching your messages or stealing information without making obvious changes.
If you notice any of these signs, the first step is to change your password when ready from a device you trust, using a password you have never used before. Do this before investigating further, because a hacker with access can lock you out or change your recovery information while you are still looking around.
Key Takeaways
- A hacked account means someone else knows your password and can access your messages, change settings, or impersonate you.
- The most obvious signs are a password that stops working, emails in your sent folder you did not write, or friends reporting messages from you that you never sent.
- Change your password when ready from a trusted device using a completely new password before taking any other steps.
- Check your connected apps and devices in your account settings and remove anything you do not recognize.
- Enable two-factor authentication so that a stolen password alone cannot give someone access to your account.
How to change your password safely after a hack
Use a device you are confident has not been compromised — typically a phone or computer you use regularly and have not lent to anyone. Go to the account's official website by typing the address yourself rather than clicking a link in an email, because hackers sometimes send fake password-reset emails that look real.
Find the password change option, usually under Settings or Account Security. Enter your current password if the site asks for it, then create a new password that is at least 12 characters long and includes uppercase letters, numbers, and symbols. Do not use a password you have used before, and do not use one that is similar to your old password with a number added at the end.
After you change the password, you will usually be logged out of all devices. This is intentional — it forces the hacker to log back in with the new password they do not know. If the site offers to show you which devices are currently logged in, check that list and log out any devices you do not recognize.
Checking what apps and devices have access to your account
Most email, social media, and financial accounts let you see which apps and devices are currently connected. In Gmail, this is called "Manage your Google Account" and then the Security tab. In Facebook, it is Settings and then Where You're Logged In. In Apple accounts, it is Settings and then Devices. The exact name varies, but the principle is the same: you are looking for a list of phones, computers, tablets, or third-party apps that have permission to access your account.
Go through this list and remove anything you do not recognize. A device you sold or gave away should not still be on this list. An app you never installed should not be there. If you see a location you do not recognize — for example, a login from a city you have never visited — that is a sign someone else accessed your account from there.
After removing unknown devices and apps, change your password again. This second change ensures that even if a hacker knows your first new password, they cannot use it to regain access through an old app or device.
Turning on two-factor authentication to prevent future hacks
Two-factor authentication (often called 2FA or two-step verification) means that even if someone steals your password, they cannot log in without a second piece of information only you have — usually a code sent to your phone or generated by an app. This is the single most effective way to stop a hacker from getting back in.
Most major accounts offer two-factor authentication in their security settings. You will be asked to choose a method: a code texted to your phone, a code from an authenticator app like Google Authenticator or Microsoft Authenticator, or a security key (a small physical device). An authenticator app is more find than text messages because hackers can sometimes intercept texts, but any method is better than no two-factor authentication.
Set this up when ready after changing your password. Write down the backup codes the site provides — these are one-time passwords you can use if you lose access to your phone or authenticator app. Store them somewhere safe, like a locked drawer or a password manager.
What to do if you cannot log in to your account
If your password no longer works and you cannot reset it, a hacker may have changed your recovery email or phone number. Go to the account's login page and look for a "Cannot log in?" or "Forgot password?" link. Follow the recovery process, which usually asks you to verify your identity using information only you would know — your phone number, a recovery code you saved earlier, or answers to security questions.
If the hacker changed your recovery information and you cannot verify your identity through the automated process, contact the company's support team. Have ready any information that proves you own the account: the original email address you used to create it, the phone number you registered with, a credit card you used to pay for services, or the date you created the account. Support teams can be slow, so be patient — this process can take days or weeks.
While you wait for support to restore your account, monitor your linked accounts and financial institutions. If the hacked account was connected to your email, bank, or social media, check those accounts for unauthorized changes. If you see fraudulent charges, contact your bank or credit card company when ready.
Checking if your passwords appear in known data breaches
A data breach happens when hackers steal information from a company's servers — usernames, passwords, email addresses, or payment information. Your password might be compromised not because your device was hacked, but because a company you use was breached and your password was stolen along with thousands of others.
You can check whether your email address or password appears in a known breach using a free tool called Have I Been Pwned, available at haveibeenpwned.com. Type in your email address and the site will tell you which breaches included your information. This does not mean your account is currently hacked, but it does mean your password is no longer secret and you should change it.
If your password appears in a breach, change it when ready on any account where you used that same password. This is why using the same password on multiple sites is dangerous — one breach compromises all of them. After a breach, use a unique password on every account, or use a password manager to generate and store different passwords for you.
Recovering your account if it has been used to send spam or phishing
If your account has been sending spam emails or phishing messages to your contacts, your contacts may have reported it and the email provider may have temporarily locked your account. You will usually see a message saying your account has been compromised or is sending suspicious activity.
Follow the account recovery process the provider offers. This typically involves changing your password, confirming your identity, and reviewing recent activity. After you regain access, send a message to your contacts letting them know your account was compromised and they should not click any links in emails they received from you during the breach period.
Check your email forwarding settings and recovery information to make sure the hacker did not set up a way to regain access. In Gmail, this is under Settings and then Forwarding and POP/IMAP. In Outlook, it is Settings and then Mail and then Forwarding. Remove any forwarding rules you did not create, and update your recovery email and phone number to information only you control.
Frequently Asked Questions
Can a hacker access my account if I use the same password everywhere?
Yes. If one company is breached and your password is stolen, a hacker can use that password to log into your email, bank, social media, and any other account where you used the same password. This is why security experts recommend a unique password for every account. A password manager stores different passwords for you so you only have to remember one master password.
Is two-factor authentication really necessary?
Two-factor authentication stops most hacks because a stolen password alone is not enough to log in. Without it, a hacker who knows your password can access your account from anywhere. With it, they would also need your phone or authenticator app, which is much harder to steal. It is the most effective single step you can take.
What if I think my bank account has been hacked?
Contact your bank when ready by calling the number on the back of your card or on your bank statement — do not use a number from an email or search result. Tell them you suspect fraud and ask them to freeze your account and review recent transactions. Your bank can reverse fraudulent charges and issue you a new card. Do this before changing your password, because your bank may need to verify your identity using information only you know.
Should I be worried if my password was in a data breach but my account seems fine?
Your account may seem fine but your password is no longer secret. Change it when ready on that account and on any other account where you used the same password. Monitor your account for unusual activity over the next few weeks. You do not need to panic, but you do need to act quickly to prevent someone from using your compromised password to access your accounts.
Can I tell if someone is currently reading my emails?
Not directly, but you can check your account activity. Most email providers show you the last time your account was accessed and from which location and device. If you see a login from a place you have never been or a device you do not own, someone else has accessed your account. Change your password when ready and remove that device from your connected devices list.