Take back a hacked account (email, social media)
In short
Start the service's recovery procedure without waiting, from a clean device. Once you have the account back, sign out every session, remove what the attacker added — forwarding rules, connected apps — and restore your recovery options before anything else. Then warn your contacts through another channel.
Why this works
Taking back an account is not enough to keep it. An attacker who changed the backup email, the recovery number or added a forwarding rule can repeat the move as often as they like: until those are restored, changing the password achieves nothing. Speed matters for another reason too: recovery procedures get harder once the associated email address has been replaced. Finally, a hacked account is often used to write to the people close to you in your name, and they are the ones to protect.
Step by step
Recover the account from a clean device
Use the service's official recovery procedure. If you suspect malicious software on your device — a recently installed program, an unknown extension — do it from another device.
Sign out sessions, then change the password
Sign out all devices and sessions, then change the password. This order matters when session cookies have been stolen: they stay valid as long as the session is not closed. Then generate new backup codes.
Remove what the attacker left behind
Delete any unknown forwarding or filtering rule in your email, revoke authorized third-party apps, and restore the recovery email address and number. Turn on two-factor authentication.
Protect linked accounts and your contacts
Change the passwords of the accounts tied to this address, starting with your bank. Warn your contacts through another channel and, if needed, post a message flagging the requests sent in your name. If someone close to you sent money, they must contact their bank immediately and file a police report themselves. Report what happened to Cybermalveillance.gouv.fr (in France).
The most common mistakes
- Changing the password without checking the recovery email and number.
- Forgetting the email forwarding rules, which keep sending your messages to the attacker.
- Running the recovery from the device that may have been used to steal access.
- Waiting before starting recovery: it gets harder once the associated address has been changed.
- Not warning anyone, while your contacts receive requests in your name.
A tool to do it
The attacks this defeats
Official sources
Other guides · Last updated: 2026-10-07.