Coming Soon
Any device playbook · Fundamentals

Someone's in your account — take it back

Why this matters: Being known isn't the same as being watched

What you’ll be able to do afterward

If you’re not sure anyone’s actually in: reset emails you didn’t request and login alerts from odd places are enough reason to run this. It costs twenty minutes and can’t hurt.

The plays

  1. Start from a device you trust Where: a computer or phone the intruder can't be on — not the account's usual device if you suspect it's compromised

    What this just did: made sure the cleanup isn't being watched. Everything below happens from here.

  2. Take email back first Where: your email provider — change the password, then find "sign out of all sessions" and use it

    What this just did: evicted everyone but you from the account that can reset all the others. Every recovery flow runs through email — it has to be yours before anything else counts.

  3. Check forwarding rules and filters Where: email settings → forwarding, and settings → filters/rules

    What this just did: closed the classic quiet door. Intruders add a forward or a filter that copies your mail out (or hides security alerts) — it keeps working after the password changes, which is exactly why they do it.

  4. Re-point recovery at yourself Where: account security settings → recovery email and recovery phone

    What this just did: removed the other reusable key. A recovery address the intruder added is a fresh takeover waiting politely for the dust to settle.

  5. Review connected apps and app passwords Where: account security settings → third-party access / connected apps / app passwords — remove anything you don't recognize

    What this just did: revoked standing access that survives a password change. An authorized "app" with mail access is as good as your password, and it doesn't show up in the login history.

  6. Change the password anywhere it was reused Where: any other account that shared the old password, most-important first: banking, social, shopping

    What this just did: got ahead of the follow-on logins. Whoever had one password has already tried it everywhere else — assume that, act on it.

  7. Turn on two-factor as you go Where: each account you touch in this cleanup — authenticator app over text codes where offered

    What this just did: made round two not worth attempting. The cleanup pass is the one time you're already in every settings page — spend the extra minute per account.

  8. Warn anyone the account may have messaged Who: recent contacts, if you find sent messages you didn't write — a short "my account was compromised, ignore anything odd from me" note

    What this just did: cut off the scam's next hop. Compromised accounts get used against the people who trust them; a two-line heads-up beats their curiosity about that strange link.

You’re now covered against…

Twenty minutes, in order, from a clean device. Done is done — this isn’t a playbook you should need twice, because play 7 is the reason there’s no round two.

Progress is saved only on this device. It never leaves your phone.