What to do if…
you receive repeated account-recovery, password-reset, or security-code messages you did not request
Short answer
Do not use links, attachments, phone numbers, reply options, or security codes from the messages. Open the named service through its official app or an address you already know, then check the account’s security activity and recovery details.
Do not do these things
- Do not click an account-recovery or password-reset link you did not request.
- Do not share a security code with anyone who contacts you.
- Do not approve an unexpected sign-in or authentication prompt.
- Do not call a phone number included in an unexpected message.
- Do not enter your password on a page opened from the message.
- Do not assume repeated messages alone prove that someone entered your account.
- Do not reuse a new password on another account.
What to do now
- Note which service and account the messages name, along with when they arrived. Close the messages without using their links, attachments, buttons, or contact details.
- Open the service through its official app, an existing bookmark, or a web address you already know is correct.
- Check recent sign-ins, security activity, recognized devices, active sessions, and the listed recovery email address and phone number.
- If you see an unfamiliar sign-in, device, session, or account change, use the service’s official controls to remove or report it. Change the password to a new, unique password and sign out other sessions if that option is available.
- If the affected password was also used on another account, change it there too, starting with your email and financial accounts.
- Turn on multi-factor authentication if it is available and not already active. An authenticator app or security key is generally safer than a code delivered by text or email when the service offers a choice.
- If the messages concern your email account, check for forwarding rules you did not create and unfamiliar messages in the sent or deleted folders. Remove unknown forwarding rules through the account’s settings.
- If you do not have an account with the named service and see no other sign that your information was used, report or mark the message as spam and continue watching for related activity.
- If the account involves banking, payment services, payroll, or stored cards and you see an unauthorized change or transaction, contact the institution immediately through its official app, website, statement, or the number on the back of your card.
- If you are locked out, use the provider’s official account-recovery process. If money or personal information was misused, save relevant messages, screenshots, dates, and transaction details before using the appropriate federal reporting service.
What can wait
You do not need to identify the sender or determine immediately whether this was phishing, an automated account attempt, or someone entering the wrong email address or phone number. Changing every unrelated password, deleting all the messages, and preparing a detailed incident report can wait until you have checked and secured the named account, unless money is moving or sensitive account details are being changed.
Important reassurance
Repeated recovery, reset, or security-code messages do not by themselves establish that someone knows your password or has accessed your account. They may result from an attempted recovery, a mistaken email address or phone number, or a message intended to make you react. Checking the account directly is more reliable than trying to judge the messages alone.
Scope note
This guide covers immediate steps for checking and securing the affected account. Later decisions involving identity theft, financial recovery, workplace systems, device compromise, or wider account takeover may require help from the provider, your financial institution, your employer’s technology team, or a qualified specialist.
Important note
This is general information, not individualized cybersecurity, legal, financial, or professional advice. Follow the affected provider’s official instructions, and contact the provider or financial institution directly if control of an account, money, or sensitive information may be at risk.
Additional Resources
- Consumer Advice — What’s a verification code and why would someone ask me for it?
- Consumer Advice — How To Recognize and Avoid Phishing Scams
- Consumer Advice — How To Recover Your Hacked Email or Social Media Account
- Consumer Advice — Use Two-Factor Authentication To Protect Your Accounts
- Cisa — Recognize and report phishing
- IdentityTheft.gov — Identitytheft
- Ic3 — Account Takeover Fraud (ATO)
- ReportFraud.ftc.gov — Report Fraud
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.