The Computer BasicsPlain answers, without the guesswork

Staying Safe

Staying Safe

What to Do After a Compromise

An account taken over, malware installed, or details given to a scammer — the order of actions that limits the damage, starting with the one people do last.

Legitimate workplace monitoring should be distinguishable from an intrusion on a managed device; Monitask provides further details on remote employee monitoring.

Something has gone wrong — an account is behaving oddly, you clicked something, or you gave details to someone who turned out not to be who they said. The order of actions matters, and the most important one is not the one people do first.

First: secure your email

Before anything else.

Email resets every other account. Someone with access to it can take everything else regardless of how well those accounts are protected.

Change the password, from a device you believe is clean.

Enable two-factor authentication if it is not already on. See two-factor authentication.

Check the forwarding rules and filters. This is the step almost everyone misses. A common attack adds a rule that forwards or deletes messages silently, so you never see the password reset notifications for your other accounts. Look at the rules, look at forwarding addresses, and remove anything you did not create.

Check the recovery email and phone number on the account. If an attacker changed them, they can lock you out permanently.

Check the list of devices and active sessions, and sign out of everything you do not recognise.

Then: work out what was actually affected

One account or the device?

One account — the password was guessed, reused, or phished. Fix that account and anywhere the password was reused.

The device — malware, or someone had remote access. Everything typed on it since is suspect, including passwords entered afterwards. This changes the order: clean the device before changing passwords on it, or you are handing over the new ones too.

Payment details given to a scammer — the bank comes first.

If money or payment details were involved

Contact your bank immediately. Speed genuinely matters; some transactions can be stopped in the first hours.

Use the number on your card or their official site, not any number given to you.

Freeze the card if that is available in the app.

Check recent transactions, including small ones — a small test charge frequently precedes a large one.

Report it to your national fraud reporting body.

And be ready for the second approach. People who have been defrauded are targeted again by "recovery services" who take a fee and do nothing. Anyone contacting you offering to recover the money is a second scam. See scams that target home users.

If the device may be compromised

Disconnect it from the network, which stops ongoing exfiltration and remote access.

Do not use it to change passwords. Use a phone or another machine.

Run a full scan with the built-in protection, from safe mode if it will not run normally.

Look for remote access software you did not install, particularly if someone talked you through installing something.

Check startup programs and installed applications for anything unfamiliar with a recent date.

Consider reinstalling. For a serious compromise, a clean install is the only way to be confident, and it is a day of work. For an account phished on a clean machine, it is unnecessary.

Back up your files first, and scan them separately before restoring them.

Then: the accounts

In this order.

Email, done above.

Anything holding money — banking, payment services, shopping accounts with stored cards.

Your password manager, if you have one, and check its access log if it provides one.

Anywhere you reused the compromised password. This is why reuse matters — one breach becomes many. Use the manager's reuse report if it has one. See passwords: what changed.

Social accounts, which matter for impersonation of you to your contacts.

For each: change the password, enable two-factor, review active sessions, and check for changed recovery details.

Check what was changed, not just what was accessed

The part people skip, and where lasting damage hides.

Forwarding rules and filters, on email.

Recovery email and phone, on every account you check.

Connected applications with access to your accounts.

Delegated access — anyone added as a manager or collaborator.

Payment methods and addresses on shopping accounts.

An attacker who is removed but who changed the recovery address can return.

Tell people

Contacts, if your accounts were used to message them. Scams frequently spread through compromised accounts, and a short warning prevents someone you know being caught.

Your bank, as above.

The platform, which may be able to help and which needs to know.

Your employer, if any work account or device was involved. This is not optional and delaying it makes it worse.

And someone you trust. Being compromised is stressful and isolating, and people make poor decisions alone under pressure.

Afterwards

Watch for follow-up attempts, which are common — the information gained is used for a more convincing approach.

Monitor your accounts and statements for a few months.

Consider a credit freeze if identity details were exposed, where that is available.

Set up what would have prevented it: a password manager, two-factor everywhere, a backup that is not always connected.

And do not be embarrassed. These are professional operations that succeed against careful people. Staying quiet is what allows them to continue, and it is also what stops people getting help.

A quick order of actions

  1. Email first — password, two-factor, forwarding rules, recovery details, sessions
  2. Bank, if money or card details were involved
  3. Disconnect the device, if it may be compromised
  4. Change passwords from a clean device, in order of importance
  5. Check what was changed, not just what was accessed
  6. Tell contacts, the platform, and your employer if relevant
  7. Set up what would have prevented it

The short version

Email first, always — it resets everything else, and the forwarding rules are what people miss.

If the device may be compromised, clean it before changing passwords on it.

Contact the bank in the first hours, because speed determines what can be stopped.

Check what was changed — recovery addresses and forwarding rules let an attacker return after being removed.

And anyone who contacts you offering to recover the money is the second scam.

For practical baseline security guidance for home users, see CISA Secure Our World.