Someone's in your account — take it back
Why this matters: Being known isn't the same as being watched
What you’ll be able to do afterward
- An intruder is out — and stays out, because the doors they left open are closed too.
- The quiet persistence tricks (forwarding rules, connected apps) are checked, not assumed.
- Anyone the account was used against gets warned before the scam spreads.
If you’re not sure anyone’s actually in: reset emails you didn’t request and login alerts from odd places are enough reason to run this. It costs twenty minutes and can’t hurt.
The plays
-
Start from a device you trust
Where: a computer or phone the intruder can't be on — not the account's usual device if you suspect it's compromised
What this just did: made sure the cleanup isn't being watched. Everything below happens from here.
-
Take email back first
Where: your email provider — change the password, then find "sign out of all sessions" and use it
What this just did: evicted everyone but you from the account that can reset all the others. Every recovery flow runs through email — it has to be yours before anything else counts.
-
Check forwarding rules and filters
Where: email settings → forwarding, and settings → filters/rules
What this just did: closed the classic quiet door. Intruders add a forward or a filter that copies your mail out (or hides security alerts) — it keeps working after the password changes, which is exactly why they do it.
-
Re-point recovery at yourself
Where: account security settings → recovery email and recovery phone
What this just did: removed the other reusable key. A recovery address the intruder added is a fresh takeover waiting politely for the dust to settle.
-
Review connected apps and app passwords
Where: account security settings → third-party access / connected apps / app passwords — remove anything you don't recognize
What this just did: revoked standing access that survives a password change. An authorized "app" with mail access is as good as your password, and it doesn't show up in the login history.
-
Change the password anywhere it was reused
Where: any other account that shared the old password, most-important first: banking, social, shopping
What this just did: got ahead of the follow-on logins. Whoever had one password has already tried it everywhere else — assume that, act on it.
-
Turn on two-factor as you go
Where: each account you touch in this cleanup — authenticator app over text codes where offered
What this just did: made round two not worth attempting. The cleanup pass is the one time you're already in every settings page — spend the extra minute per account.
-
Warn anyone the account may have messaged
Who: recent contacts, if you find sent messages you didn't write — a short "my account was compromised, ignore anything odd from me" note
What this just did: cut off the scam's next hop. Compromised accounts get used against the people who trust them; a two-line heads-up beats their curiosity about that strange link.
You’re now covered against…
- The re-takeover — passwords, recovery routes, sessions, and standing app access all reset in one pass.
- Quiet persistence — forwarding rules and connected apps checked by name, not by vibes.
- The spread — contacts warned before “you” asks them for anything.
Twenty minutes, in order, from a clean device. Done is done — this isn’t a playbook you should need twice, because play 7 is the reason there’s no round two.
Progress is saved only on this device. It never leaves your phone.