Skip to main content

Your account was taken over. The first 30 minutes matter

Published September 16, 2026 · Updated September 16, 2026 · 5 min read

Quick answer

Secure your email first, then your social account, then warn your contacts. The email address is the master key for password resets; changing a password while the attacker still controls your inbox changes nothing.

An account takeover is rarely a password that was guessed. It comes from a reused password leaked in someone else's breach, from a session token stolen by an app, or from a message that looked like a login reminder. The account itself is worth little — what has value is the contact list, which is sold and used to send believable requests from someone people trust.

In this order

  1. Change the password of your email account and sign out every active session. This is the account that can reset all the others.
  2. From that secured email, change the password of the taken-over account and revoke its sessions and connected apps.
  3. Check the recovery options on both accounts: add or remove a phone number, a backup address, and a "trusted contact" the attacker may have inserted.
  4. Enable two-factor authentication, preferring an authenticator app or a hardware key over SMS.
  5. Tell your contacts that messages from the account were not yours, in your own words, without a link — friends will get the fake request within the hour.
  6. Report the takeover in the platform's own form rather than by replying to emails: the message offering to "restore" your account for a fee is the same attacker, charging twice.

How the same scam comes back at your friends

Once inside, the attacker writes to your contacts: an urgent problem, a small amount of money, a payment method that is not reversible. It works because it comes from you — no domain to check, no odd wording to notice. If a friend asks for money by message, verify on a channel the attacker does not control: a phone call to a number you already had, or a question only the real person can answer.

Getting the account back when you are locked out

  • Use the platform's recovery flow from a device and a network you normally use — a completely new location reads as suspicious.
  • If the attacker changed the email and phone, look for the "I no longer have access to these" option in the recovery form; it exists but is not offered first.
  • Keep a copy of your identity documents and a photo of you holding them if asked, and answer only through the platform's own form.
  • Never pay a "recovery service" that contacts you. Real platforms do not charge for account recovery and never message you offering it.

Frequently asked questions

The questions this article gets asked most, answered directly.

My friend is asking for money on Facebook. How do I check?

Call a number you already had for that person, from before the message. Do not call a number in the conversation. If the voice sounds odd, ask something only the two of you would know — voice cloning is covered in a separate article.

I changed my password but the session is still active. How?

Changing a password does not always close existing sessions, and some apps keep access tokens that survive the change. Log out of all devices explicitly and review the list of apps with access.

Will the platform restore my account automatically?

Only if the recovery data is still yours. If the attacker replaced the email and phone, without a trusted contact left intact the account is usually lost, which is why recovery details matter more than the password itself.

Should I install an app to protect my account?

Install an authenticator app from your platform's own app store listing, and be extremely careful with anything recommended to you in a message — fake "security" apps that harvest codes are a common follow-up.

Written by The BaitScan editorial team

Results are automated risk estimates based on public indicators and heuristics.