A step-by-step recovery plan for a hacked email, social, bank, or exchange account — including removing the backdoors attackers leave behind.
Do this from a clean device
If your computer or phone may be compromised, do the recovery steps from a different device you trust — otherwise the attacker can capture your new password too.
Taking back a hacked account is more than changing the password. Attackers plant persistence — a passkey, a recovery email/phone they control, an app password, or a mail-forwarding rule — so they keep access even after a reset. You have to remove those too.
—The recovery steps
- 1Change the password and sign out all other sessions/devices.
- 2Remove anything you didn't add: unknown passkeys, recovery email/phone numbers, app passwords, and mail forwarding/filters.
- 3Turn on strong 2FA — an authenticator app or hardware security key, not SMS.
- 4Review recent security/login activity for unfamiliar IPs or devices.
- 5Change the password anywhere you reused it.
—Check your exposure
See whether your email address appears in known data breaches — a common source of the credentials attackers use.
Use the toolCheck an email addressEmail Fraud Checker→For Google accounts, run the official Security Checkup at myaccount.google.com/security-checkup. For breach specifics, check haveibeenpwned.com.
Watch for follow-up scams
After a hack, expect fake 'account recovery' or 'security team' messages. Real providers never ask for your password, codes, or payment to restore access.
Get a step-by-step action plan tailored to your exact situation.
Open the guided help wizard →