An unfamiliar login, password reset notice or message sent from your profile may mean someone else has reached your account. Treat it as urgent, but work through the recovery in a clear order.
Protect Money First
If the account stores payment details or can make purchases, check recent activity. Call your bank straight away if money or card information may be at risk. Use the number on your card or the bank's official website.
Use the Provider's Recovery Page
Open the service's app or type its address yourself. Do not use a password-reset link from the message that raised your concern.
Change the password to a new, unique one. Review recovery email addresses, phone numbers and multi-factor authentication methods. Remove anything you do not recognise, then use the option to sign out other devices if it is available.
Check Connected Accounts
- Change the same password anywhere else you reused it.
- Inspect your email account, especially if it controls password resets.
- Review linked apps and accounts that use the affected service to sign in.
Look for purchases, changed settings, forwarding rules or posts you did not create. Save screenshots and note when you first saw the problem.
Warn Your Contacts
Tell people to ignore unusual messages sent in your name. This helps stop a stolen account from being used to trick someone else.
Secure the Device
If you do not know how access was gained, update the device and run its trusted security scan. A work account or managed device should be reported to the organisation's IT contact promptly.
Record and Report the Incident
Keep the messages, login alerts, transaction details and actions you took. Report the compromise to the account provider. Australians can also use ReportCyber, and Scamwatch if deception was involved.