PanicStation.org
us Technology & digital loss

What to do if…
you get an alert that an unknown passkey was added to your account

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Treat it as possible unauthorized access. Open the account directly, not through the alert, then remove any passkey you do not recognize, sign out other sessions, and check recovery details.

Do not do these things

  • Do not click “secure your account” or sign-in links inside the alert message.
  • Do not ignore it because passkeys are safer than passwords.
  • Do not keep using the account for payments, messaging, or admin tasks until you have checked sessions and sign-in methods.
  • Do not delete the alert until you have noted the date, time, device, and account it names.
  • Do not post screenshots publicly; they may expose account details and attract phishing.

What to do now

  1. Open the service directly.
    Type the website address yourself, use a saved bookmark, or open the official app. Go to the account’s security area, usually called Account, Security, Sign-in methods, Devices, or Passkeys.

  2. Remove the passkey you do not recognize.
    In the passkey or sign-in-method list, remove any passkey, security key, device, or passwordless sign-in method that you did not add.

  3. Sign out other sessions and devices.
    Use “sign out everywhere,” “log out of other devices,” or the session list. Remove unknown devices from the account if the service allows it.

  4. Check recovery routes before the account is taken back again.
    Verify recovery email addresses, phone numbers, authenticator settings, backup codes if the service uses them, and trusted devices. Remove anything unfamiliar.

  5. Check email forwarding and hidden-message rules if this is an email account.
    Look for forwarding addresses, filters, rules, blocked senders, deleted-message rules, or labels that could hide security emails.

  6. Change the password if the account still uses one.
    Use a strong, unique password. If you are locked out, or changes disappear after you make them, use the provider’s official account recovery flow from its website or app.

  7. Look for other ways someone could stay connected.
    Check for new authorized apps, linked accounts, connected devices, trusted sign-in methods, developer access, or API access if the service has those settings.

  8. Secure the email account tied to this account.
    If your email can reset this account, repeat the same passkey, session, recovery, and forwarding checks on that email account.

  9. If it is a work or school account, contact IT or security now.
    Ask them to force sign-out, review sign-in logs, and reset authentication methods using your organization’s process.

  10. If money can move from the account, reduce financial exposure.
    Lock or pause cards, payments, transfers, or purchasing if the provider offers that option. Then contact the bank, issuer, or provider using the official number on your card, statement, app, or the company’s website, and review recent activity.

What can wait

  • You do not need to know exactly how the passkey was added before you secure the account.
  • You do not need to reset every account you own in the first few minutes; start with this account and the email or phone number that can reset it.
  • You usually do not need to wipe devices in the first minutes unless you see repeated re-compromise, malware warnings, unknown remote-access software, or other clear signs the device itself is affected.
  • You do not need to decide now whether to close the account.

Important reassurance

This alert is alarming, but it gives you a chance to act while there may still be access to the account. Removing the unfamiliar passkey, ending sessions, and checking recovery details can stop a common route back in.

Scope note

These are first steps for account control and damage prevention only. If you are locked out, see financial activity you do not recognize, or suspect identity theft, later steps may need the provider, your bank, a consumer reporting agency, or another specialist support route.

Important note

This is general information for urgent first actions, not legal, financial, technical, or professional advice. In the US, IdentityTheft.gov is the federal government’s guided reporting and recovery tool for identity theft; for fraud, scams, or bad business practices that are not clearly identity theft, ReportFraud.ftc.gov is the FTC’s reporting route.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us