What to do if…
your account shows an unknown login, trusted device, or new sign-in
Short answer
Open the service through its official app or a website address you know is genuine, not through the alert. Check the account activity and, if the access is not yours, change the password, sign out other sessions, and review the security settings from a device you trust.
Do not do these things
- Do not click a link or call a number in an unexpected login alert.
- Do not approve a sign-in request you did not start.
- Do not share a verification code with anyone who contacts you.
- Do not assume an unfamiliar location or device label proves who accessed the account.
- Do not reuse the old password when changing it.
- Do not delete the account or erase a device in panic.
What to do now
- Open the account using its official app or by entering a website address you already know. Find the recent activity, security, sessions, or devices page and compare the listed time, device, and location with your own activity.
- If you do not recognize the access, take a screenshot or note the details. Then change the account password from a device you trust and use a new password that is not used for any other account.
- Use the account’s option to sign out of all devices or other sessions, if available. Remove unfamiliar devices, sessions, trusted devices, passkeys, app passwords, or connected applications that are listed.
- Check the recovery email address, recovery phone number, multi-factor authentication methods, and other security details. Remove or correct anything you do not recognize.
- If you cannot sign in, use the provider’s official account-recovery page. For a work or school account, contact the organization through its known IT or security support route.
- For an email account, check for forwarding rules, filters, delegates, sent messages, and deleted messages you did not create. For other accounts, check for unfamiliar messages, posts, purchases, payment details, or profile changes.
- Turn on multi-factor authentication if it is available. An authenticator app or security key is generally safer than receiving a code by text or email, but use the strongest method the provider offers that you can access reliably.
- Change the password on any other account where you used the same or a similar password, starting with your main email and financial accounts.
- If you entered account information on an unfamiliar page, clicked a suspicious link, or opened an unexpected attachment, update the device’s security software and run a scan. Use another trusted device for account changes if the original device is behaving unexpectedly.
- Contact the relevant financial institution through its official app, website, or known phone number if you find an unfamiliar payment or transaction. Use IdentityTheft.gov if someone appears to be misusing your personal information.
What can wait
You do not need to identify the person, determine their exact location, close the account, replace your equipment, or review every old login right now. Secure current access and your most important accounts first. Telling contacts can wait unless the account sent them unfamiliar messages, links, or requests.
Important reassurance
An unfamiliar entry does not always mean another person accessed the account. Travel, a new device, an app sign-in, or several sessions from one device can make activity look unfamiliar. Taking security precautions is still reasonable while you confirm what happened.
Scope note
This guide covers the first steps for checking and containing possible unauthorized account access. Account recovery, identity-theft recovery, workplace reporting, or device repair may require help from the provider or an appropriate specialist.
Important note
This is general information, not individualized cybersecurity, legal, financial, or other professional advice. Account features and recovery procedures vary, so follow the provider’s current official instructions.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.