If you think an account has been hacked, changing the password is only the first step.
This guide explains how to change password after account hack, secure related accounts, and reduce the chance of repeat compromise.
Account takeovers often involve more than one password, so a fast, organized response matters.
The steps below help you regain control while preserving access, recovery options, and evidence.
What to do first after you suspect a hack
Before you change anything, confirm whether the breach is limited to one account or part of a wider compromise.
Check for unusual sign-ins, unfamiliar devices, password reset emails you did not request, and changes to recovery details such as phone numbers or backup email addresses.
- Look for login alerts from the provider.
- Review recent security activity and active sessions.
- Check sent messages, financial activity, and linked apps for unauthorized actions.
- Use a trusted device and network whenever possible.
If the account controls access to email, banking, cloud storage, or social media, prioritize it immediately.
Email is especially important because attackers often use it to reset passwords on other services.
How to change password after account hack
Once you have confirmed access, change the password from the account’s official security or settings page.
If you cannot log in, use the provider’s password recovery flow and choose a reset option sent to a trusted recovery email, phone number, or authentication app.
Use a strong new password
Create a password that is long, unique, and unrelated to any old password.
A passphrase with several random words, numbers, and symbols is often stronger and easier to remember than a short complex string.
- Use at least 14 to 16 characters where supported.
- Do not reuse passwords across multiple sites.
- Avoid personal details such as birthdays, pet names, or company names.
- Never store the new password in an insecure note or message thread.
Change the password from a secure device
If malware may be involved, do not change the password from the same device until it has been checked.
A compromised browser, keylogger, or remote access tool can capture the new credentials immediately.
When possible, use a device you trust and keep the session limited to the official site or app.
Why changing the password alone is not enough
Attackers often maintain access through recovery settings, session cookies, app passwords, or connected OAuth applications.
If you only reset the password, an active session or linked app may let the intruder back in without needing the old password.
Review all security-related settings after the reset.
This is especially important for Google, Microsoft, Apple, Meta, Amazon, PayPal, and bank accounts, where linked devices and recovery options can persist across password changes.
Security settings to review immediately
After you reset the password, inspect the following settings and remove anything unfamiliar:
- Active sessions and logged-in devices
- Recovery phone numbers and backup email addresses
- Two-factor authentication methods
- App passwords
- Connected third-party apps and integrations
- Authorized devices and browser sessions
- Security questions and account recovery contacts
Sign out of all sessions if the platform offers that option.
Then sign back in only on devices you recognize.
If an attacker added a new recovery method, remove it before they can use it for another reset.
Enable two-factor authentication
Two-factor authentication, often called 2FA or multi-factor authentication, adds a second proof of identity beyond the password.
Authentication apps such as Google Authenticator, Microsoft Authenticator, or Authy are generally safer than SMS because text messages can be intercepted through SIM swapping or phone number port-out attacks.
When setting up 2FA, save backup codes in a secure location.
If the account offers passkeys, consider enabling them because they reduce phishing risk and can simplify future sign-ins.
Check your email and financial accounts next
If one account was hacked, other accounts may be at risk.
Start with the email address tied to password resets, then move to banking, payment apps, shopping sites, and cloud storage.
Attackers frequently use one stolen login to pivot into other services.
- Change the email password first if it may have been exposed.
- Update recovery settings for every important account.
- Monitor bank and card statements for unauthorized charges.
- Freeze or lock credit if identity theft is suspected.
Look for password reset notifications you did not trigger.
If you receive one, act quickly because it may indicate an ongoing attempt to take over more accounts.
Remove malicious access and damaged trust points
Some account hacks involve mail forwarding rules, auto-replies, OAuth permissions, or hidden filters that help attackers stay in control or spy on communications.
Check your inbox rules, delegation settings, and connected apps carefully.
On social platforms, review device sessions, admin roles, page access, and business accounts.
On cloud platforms, inspect shared folders, public links, API tokens, and app integrations.
On gaming and marketplace accounts, remove unknown payment methods and linked payment providers.
What if you cannot regain access?
If the password reset fails or the attacker changed the recovery methods, use the provider’s identity verification or account recovery process.
Be prepared to submit proof such as a government ID, previous passwords, transaction details, or device history, depending on the service.
For work or school accounts, notify the organization’s IT or security team immediately.
Microsoft 365, Google Workspace, and other enterprise platforms may allow administrators to invalidate sessions, reset credentials, and review audit logs faster than a standard user flow.
How to document the incident
Keeping records can help with support requests, fraud disputes, and law enforcement reports.
Save screenshots of suspicious activity, email headers, timestamps, login alerts, and any unauthorized purchases or messages.
- Record when you noticed the compromise.
- Note what changed in the account.
- Save support ticket numbers and case IDs.
- List any devices, locations, or IP addresses shown in security logs.
Clear documentation can speed up recovery if the provider requests evidence or if the incident expands into financial fraud or identity theft.
How to prevent another account hack
Once access is restored, improve your baseline security so the same attack path is harder to repeat.
The most effective protections are unique passwords, 2FA, updated recovery options, and careful phishing resistance.
- Use a reputable password manager to generate and store unique credentials.
- Keep operating systems, browsers, and security software updated.
- Do not approve login prompts you did not initiate.
- Watch for phishing emails that imitate support teams or login pages.
- Remove old accounts you no longer use.
If you suspect malware, run a full security scan and consider resetting the device after backing up essential files.
For especially sensitive accounts, re-register security keys or passkeys on a clean device.
When to contact support, your bank, or law enforcement
Contact support as soon as you lose access, especially for accounts tied to money, identity, or business operations.
Call your bank or card issuer if you see fraudulent transactions, and ask about chargebacks, card replacement, or account monitoring.
If the hack involved identity theft, financial loss, or blackmail, file a report with local law enforcement and any relevant cybercrime reporting portal in your country.
Some providers require a police report before they will restore certain account controls.
Fast action, careful password changes, and thorough session cleanup are what stop most account takeovers from continuing.
The main priority is not just to replace the password, but to close every path the attacker could use to return.