PanicStation.org
uk Technology & digital loss

What to do if…
you receive repeated account-recovery, password-reset, or security-code messages you did not request

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Do not click links, approve requests, reply, or share any code. Open the service through its official app or a web address you already trust, then check the account’s recent activity and security settings.

Do not do these things

  • Do not give a security code to anyone, including someone claiming to be support.
  • Do not approve a sign-in, recovery request, or authentication prompt you did not start.
  • Do not use links, phone numbers, or contact details contained in an unexpected message.
  • Do not reply to the sender to ask why the messages are arriving.
  • Do not request more codes merely to test whether the account works.
  • Do not assume that receiving a code means someone has entered the account.
  • Do not delete every message until you have noted which service and account it concerns.

What to do now

  1. Stop interacting with the messages. Silence their notifications temporarily if they are making it difficult to concentrate, but keep the messages available for reference.

  2. Identify the service named in the messages and the email address, username, or phone number they concern. A message about an account you do not recognise may be a scam or may have been sent because someone entered the wrong details.

  3. Open the service independently. Use its official app, a saved bookmark, or type the known web address yourself rather than following a link in the message.

  4. Check the account for sign-ins, attempted sign-ins, connected devices, recovery details, security-setting changes, and other activity you do not recognise.

  5. If you find unfamiliar activity, cannot access the account, or believe someone may know the password, follow the provider’s official account-security or recovery process.

  6. Change the affected account’s password through its official settings if the account may have been accessed. Use a strong password that is not used for another account.

  7. Change the password on any other account using the same password. Secure the linked email account first because it may be used to reset other accounts.

  8. Check the linked email account for unfamiliar sign-ins, recovery-detail changes, filters, and forwarding rules. Remove anything you do not recognise using the provider’s official controls.

  9. Use the service’s option to sign out other devices or sessions if unfamiliar activity appears or the provider recommends doing so.

  10. Turn on two-step verification where available. Use a passkey or another verification method offered by the provider that you can keep secure.

  11. Contact the provider through its official help centre if you cannot regain access, cannot remove an unfamiliar recovery method, or continue receiving approval prompts after securing the account.

  12. Forward suspicious emails to report@phishing.gov.uk. Forward suspicious text messages to 7726. Use the block and report controls for suspicious messages received through an app.

  13. If money has been taken, contact your bank immediately using a trusted number. Report cyber crime or fraud to Report Fraud if you are in England, Wales or Northern Ireland; in Scotland, contact Police Scotland on 101.

What can wait

You do not need to identify who triggered every request, reply to the sender, close the account, replace your phone, or review every online account immediately. Secure the affected account and its linked email first; lower-priority account checks can wait until the immediate alerts have been handled.

Important reassurance

A recovery or security-code message can be generated before anyone gains access, including when someone enters the wrong email address or phone number. The messages are worth checking, but their arrival alone does not prove that the account has been taken over.

Scope note

This guide covers immediate steps to reduce the chance of account loss and check for unauthorised access. Recovering a compromised account, dealing with financial loss, securing workplace systems, or responding to continuing targeted harassment may require help from the provider, your employer’s IT team, your bank, the police, or a cyber-security specialist.

Important note

This is general digital-safety information, not legal, financial, technical, or professional advice. Account features and recovery processes vary by provider, so use the provider’s current official instructions.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us