SecurCheckCyber Centre

ACCOUNTS · ACCESS · COMPROMISE

Has my account been hacked? How to check and respond

Secur Cloud ·

Losing control of a Google, Microsoft 365 or social account is unsettling. Stolen data, messages sent in your name or exposed work access: when unsure, proceed methodically. This guide helps you assess a potentially hacked account and prioritise next steps.

1. What are the signs of a hacked account?

Unauthorised access can remain discreet. Compare signals rather than drawing a conclusion from one clue.

Unknown sign-ins or devices

An unknown device, unusual time or repeated alert deserves investigation. A displayed city may be approximate or reflect a VPN or mobile network: location alone does not prove a hack.

Settings changed without your knowledge

A password that no longer works, replaced recovery address or new MFA method are important signals. Check changes through the official service without following a link in a received alert.

Messages or actions you do not recognise

Contacts report requests for money or suspicious links sent in your name. Compare these with sent messages and account activity: your name can also be impersonated without control of your account.

Unexpected MFA requests

Do not approve a notification you did not initiate or share the received code. These requests may indicate an access attempt without establishing that a sign-in succeeded.

2. Check without sharing credentials

Never give a third-party site your password, MFA code, session cookie or recovery key to “test” an account.

Activity and devices

From a trusted device, open the official app or address and review security settings. Compare sessions with your devices and activity. Labels differ across Google, Microsoft, Facebook, Instagram and WhatsApp.

Email forwarding and inbox rules

Look for forwarding, delegation or rules you did not configure. They may divert messages or hide alerts. For a work account, preserve useful evidence and ask IT to review these settings.

Applications and permissions

Review connected applications, linked devices and extensions. Have unauthorised access removed; at work, check with IT before removing an integration you do not recognise.

3. Response checklist for suspected compromise

Do not wait for absolute confirmation when signals are serious. Follow the provider’s or your incident-response team’s instructions.

  1. Change the password and have sessions revoked

    Use the official service from a trusted device. Choose a long, unique password, ideally generated by a password manager, and replace it wherever it was reused. Also sign out other devices where this option is available.

  2. Check the scope of revocation

    For work Microsoft 365 accounts, ask an administrator to revoke sessions and review associated applications. Some tokens or application-owned sessions require additional measures; sign-out is not always immediate. A password change alone may be insufficient.

  3. Restore recovery methods

    Review the recovery email, phone and authentication methods. Have unauthorised additions removed. If you can no longer sign in, use the official recovery process or contact your administrator.

  4. Strengthen MFA and monitor afterwards

    Enable suitable multifactor authentication. Where supported, prefer phishing-resistant passkeys or FIDO2 security keys. Afterwards, check for further suspicious activity with the provider or your IT team.

Preserve useful alerts and timestamps. Warn contacts who received fraudulent requests. If payments are involved, contact your bank through its official channel; if the device may be infected, use another trusted device.

Open the “I clicked” emergency assistant

4. Understand related risks

Credential stuffing

Password reuse lets an attacker try stolen credentials on other services. Unique passwords limit this cascading effect.

AiTM session theft

A stolen session can allow reuse of already authenticated access. Traditional MFA is not equivalent to a phishing-resistant method.

Understand Storm-2755 and payroll fraud

Impersonation, extortion and exposed data

Access to private messages or photos can fuel further fraud attempts. Preserve evidence and seek suitable help rather than negotiating under pressure.

Help protect your employees’ access

Depending on its permissions, a compromised account can expose data or be used to deceive colleagues. SecurCheck Business helps teams recognise signals, organise their response and pass useful context to support.

Prevention combines message checks, unique passwords, suitable MFA and access controls. A guided assessment complements these measures and IT investigation without guaranteeing a two-minute resolution.

Explore the Business offer

Discuss deployment for your teams

Official help and sources

Sources consulted on 23 September 2026.