Unknown login: how to regain account control

Check whether the alert concerns your action. If not, secure login, end alien sessions and remove the remaining access routes.

2 min readPerformance: First action immediately; further control depends on the incident
In this guide

Notification of new login may apply to your new browser, but it can also warn you about real acquisition. Do not check this by the button from the suspicious message. Open the service yourself and find the activity history.

Compare time, device and your own actions. The alien city is not yet proof of hacking — the location can change VPN or operator. In turn, an unknown change to the recovery address is a stronger signal than the location itself.

If you can still log in

Use the current device to which you have confidence. If you suspect that the current computer is infected, perform actions with other equipment.

  1. Change the revealed or suspicious password to new and unique. Adding passkey does not automatically invalidate the old password.
  2. End unknown sessions. If the service offers to log out all other devices, consider them at a confirmed incident. Do not assume that the password change itself has already done so.
  3. Check the login and recovery methods. Remove foreign passkeys, keys, 2FA applications, addresses and numbers after making sure you keep your own working entry path.
  4. Take access to unknown applications. View integrations, tokens or application passwords if your account provides such features.

Perform these actions as a single review. The attacker may have more than one way of access, so correcting only the first visible setting can be insufficient.

If you can't enter your account

Run recovery from the official website or application. Use the previously added backup key, recovery code or supplier procedure. Do not quickly log out the only device on which you still have access — it can help confirm your identity.

There is no universal procedure for unlocking any account. The service may require additional information or time for verification. Avoid those who, in private messages, promise to recover the account for a fee and ask for a password or code.

Check what has been changed

Check the filters, transfer and sent messages at the post office. Check the orders and delivery addresses in the store.

If there has been an unauthorized payment, please contact the bank via a known channel. Please report the incident to the administrator for your business account. Save dates, notifications and information about foreign activities; do not publish your own codes or other data.

Close effects also outside this account

If the same password was used elsewhere, change it there as well. When someone sends messages on your behalf, alert the recipients via a different channel. After you have regained control check the new login and prepare the backup method.

The lack of another alert is not in itself proof of the problem being removed. It is important that only the methods of access are recognised and suspicious actions are explained.