SPC Servis PC Brno

Hacked email or Facebook — a step-by-step recovery guide

When you find out someone else is inside your email or social account, the first few hours decide how much damage is done. Here is a concrete, no-panic checklist.

Ing. Miroslav Jaroš 10 min read
Hacked email or Facebook — a step-by-step recovery guide

When you discover that someone else has your email, Facebook, Instagram or bank account, the first few hours decide how big the damage gets. This guide isn’t about whose fault it is or about security in the abstract. It’s a step-by-step checklist of what to actually do once the problem has already landed on you.

If your first instinct is “it’ll probably sort itself out, I’ll wait a few days” — don’t wait. Right now the attacker is most likely:

  • Sending phishing from your account to your contacts
  • Setting up a forwarding rule to their own address (so they’ll read your future mail too)
  • Buying something with the card saved in your account
  • Downloading your private photos to use for blackmail

Start now.

Step 1: Change the password from a different device (5 minutes)

First, make sure the attacker can’t lock you out.

If you can still log in

  1. Sign in from a different device than the one you suspect is infected (a friend’s phone, a clean laptop). From an infected computer the attacker can see your activity, including the new password.
  2. Set a strong password (16+ characters, mixed; use a password manager or write it down somewhere safe). Never reuse an old password with one small change.
  3. Sign out of all sessions (active sessions, devices, “where you’re logged in”):
    • Gmail: Google Account → Security → Your devices → Sign out of all
    • Outlook/Microsoft: account.microsoft.com → Security → Sign-in activity → Sign out
    • Facebook: Settings → Security → Where you’re logged in → Log out of all
    • Instagram: Settings → Security → Login activity → End sessions

If you CANNOT log in (the attacker already changed the password)

Recovery without proof of identity can take 2 to 14 days. If your recovery details (recovery email, phone) were compromised too, it’s even harder — which is exactly why two-factor authentication is worth turning on the moment you regain access.

Step 2: Check what the attacker managed to do (15 minutes)

Attackers typically do these four things:

1. Email forwarding to their own address

This is the worst one — the attacker logs out, you think everything is fine, but every new email (invoices, passwords, bank notices) is being copied to them.

Where to check:

  • Gmail: Settings → Forwarding and POP/IMAP → make sure no unknown address is left there
  • Outlook: Settings → Mail → Forwarding → turn off if the address is unknown
  • Outlook 365 (business): Settings → Mail rules → delete any suspicious rule (often “Delete messages containing…”, “Forward to…“)

2. Mail rules and filters

The attacker creates a rule like “delete all emails from the bank” or “move emails containing ‘password’ to trash”. The goal: hide suspicious activity from you.

Where to check:

  • Gmail: Settings → Filters and blocked addresses → delete anything you don’t recognise
  • Outlook: Rules → delete unknown rules
  • Yahoo: Settings → Filters → delete unknown ones

3. Added devices / apps with permissions

The attacker may have connected your account to a third-party app that keeps reading your mail even without your password.

Where to check:

  • Google: Account → Security → Third-party apps with account access → remove unknown ones
  • Microsoft: Privacy → Apps and services that can access your data → remove
  • Facebook: Settings → Apps and websites → remove anything you don’t recognise

4. Changed contact details (recovery email, phone)

The attacker sets their own email as the “recovery” address — then a single “forgot password” hands them the reset.

Where to check:

  • Google: Account → Personal info → Phone, Recovery email → confirm they’re yours
  • Microsoft: Security → Sign-in options → verify
  • Facebook: Settings → Personal details → Contact info

Step 3: Turn on two-factor authentication (2FA) — the critical step (10 minutes)

Without 2FA, getting an account hacked is a matter of time. With 2FA it’s much harder, because the attacker needs a second factor on top of the password (a code from an app).

Prefer an authenticator app (Microsoft Authenticator, Google Authenticator, Authy) over SMS. SMS can be intercepted via a SIM-swap attack — the attacker has your number ported to their SIM at the carrier, often by social-engineering support.

How to set it up:

  • Google: Account → Security → 2-Step Verification → set up
  • Microsoft: Security → Advanced security options → 2FA
  • Facebook: Settings → Security → Two-factor authentication
  • Instagram: Settings → Security → Two-factor authentication

Once it’s on, save your recovery codes (10 one-time codes). Ideally into a password manager (Bitwarden, 1Password) or on paper kept somewhere safe. Without them, you lose access if you lose your phone.

Step 4: Warn your contacts (15 minutes)

The attacker has probably sent messages from your account to your contacts. Typically:

  • “I’m in trouble, I urgently need money, please send it” (to family)
  • A phishing link, “look at this, it’s about you” (to friends)
  • A fake invoice (to clients, if you’re self-employed)

What to do:

  1. Send the warning from a clean email or another channel (Signal, WhatsApp, a phone call). Not from the hacked account — the attacker could just delete it.
  2. Keep it short: “My email / Facebook was hacked. If you got a request for money or a strange link from me, ignore it. I’m on it now — let me know if you clicked anything.”
  3. For clients (if you’re self-employed): if the attacker managed to send out a fake invoice with a changed bank account number, that’s serious — contact those clients personally, by phone.

Step 5: Bank, ID, sensitive services (30 minutes)

Check whether the attacker reached anything more serious:

  • Bank: review the transaction history for the last 7–30 days. If there’s an unauthorised transaction, contact your bank immediately — reported within 24 hours, many banks can reverse a fraudulent transfer, especially a domestic one.
  • Cards saved in accounts: Apple Pay, Google Pay, online shops with a stored card — check the transactions.
  • Government / tax portals: if you sign in with email, check the login log.
  • Cloud (OneDrive, Google Drive, Dropbox): check whether someone downloaded a large batch of files. Cloud services usually keep an “activity” log.
  • Other social networks (LinkedIn, Twitter/X, TikTok): if you use that email to log in, change those passwords too — the attacker may have access.

Step 6: Scan the computer for malware (60 minutes)

If the attacker got your password through a keylogger or info-stealer on your computer, changing the password alone isn’t enough — the attacker simply captures the new one again.

What to do:

  1. Update Windows (Settings → Windows Update → install everything).
  2. Run a full antivirus scan (Microsoft Defender, ESET, Bitdefender — whatever you have). A full scan, not just a quick one.
  3. Install Malwarebytes Free and run a one-off scan. Some info-stealers hide from Defender but Malwarebytes catches them.
  4. Check your browser extensions (Chrome, Edge, Firefox) — if you find anything unfamiliar, remove it. Browser extensions have become a leading route for password theft. More on that in Dangerous browser extensions.
  5. If you suspect a serious infection (Defender flags it but can’t remove it; the PC keeps acting strangely even after cleaning), it’s time for a clean Windows reinstall.

Step 7: Report it to the police (15 minutes)

Even when it feels hopeless, reporting it helps:

  • It feeds the statistics national cyber authorities use to track threats
  • If the attacker took money, criminal prosecution becomes possible
  • Your bank may require a police reference number to reverse a payment

Report it through your country’s official channel for reporting crime, or in person at your local police station. Most countries have a dedicated unit or online form for cybercrime — search for the official one for your region.

Prevention — five things for the weekend

So it doesn’t happen again:

  1. A password manager (Bitwarden free, 1Password paid) — a unique password for every service
  2. 2FA everywhere — at minimum your bank, email, social networks, cloud
  3. Regularly review “who has access” — third-party apps in your Google/Microsoft/Facebook settings
  4. The 3-2-1 backup rule — if the attacker wrecks an account, your data lives somewhere else too
  5. Healthy distrust of email — AI phishing in 2026 can no longer be spotted by “bad grammar”. More in AI scams in 2026

FAQ

I changed the password, but the attacker logged in again. Why? Either they have active sessions on their own devices (Step 1: sign out of all), or they’re forwarding your mail (Step 2.1), or there’s malware on your PC that captures the new password again (Step 6).

My email is hacked, but Gmail won’t let me through recovery. What now? Google’s recovery flow relies on history (which devices you signed in from, when you created the account). If it won’t work, try g.co/recover from your original device and network (at home, not at work). If that fails too, the account is usually lost and the only option left is to create a new one and warn your contacts.

The attacker is threatening me: “I have your nude videos, pay $500 in Bitcoin or I’ll send them out.” What do I do? This is a sextortion scam — in 99% of cases the attacker has no video, it’s a bluff. Don’t pay. Paying just invites more demands; report it instead. More in How to spot a phishing email.

How long does recovering a hacked account take? With 2FA backup codes, a recovery email and a phone — minutes. Without them, through the official recovery process, 2 to 14 days. That’s why 2FA is worth turning on today, not after the damage is done.

  • #hacked email
  • #phishing
  • #account recovery
  • #2FA
  • #Facebook
  • #Gmail
  • #Outlook
Share:

Found this useful? More security and privacy write-ups at ithope.cz.

Call Contact