About this module
After an account compromise, speed helps, but order matters just as much. Learners start with the signs: unfamiliar login alerts, unexpected reset emails, activity they do not recognize, and strange messages sent from the account. Then they follow the recovery sequence: change the password from a trusted device, go directly to the service website, enable MFA, sign out of other sessions, check recovery details, inspect forwarding rules, and review connected apps. The lesson also covers when legal or privacy teams need to be involved, especially when other people's data may be affected.
Key takeaways
Discovering that an account has been compromised is alarming — but how quickly and systematically you respond determines whether it is a minor incident or a major disaster. In this video, we will walk through the exact steps to take when you suspect or confirm an account has been breached.
The first challenge is recognizing a compromise. Common signs include unexpected login alerts from unfamiliar locations, password reset emails you did not initiate, activity in your account that you do not recognize, and contacts reaching out about strange messages sent from your account.
Any of these warrants immediate investigation. According to IBM's Cost of a Data Breach report, breaches go undetected for well over half a year on average.
That extended window gives attackers time to harvest data, establish persistence, and move laterally. Early detection and immediate response are critical to limiting the damage.
Your first action is to change the password — but do it from a device you trust, not the one that may have been compromised. Log in directly to the service's website, not through an email link, to avoid phishing traps.
Use a long, unique password you have never used elsewhere. More than four out of five hacking incidents exploit stolen or weak credentials.
That statistic underscores why acting quickly to change a compromised password stops the majority of ongoing attacks. Attackers often sell or share stolen credentials — time is critical.
Once you have changed the password, enable multi-factor authentication if it is not already on. This ensures that even if the stolen password has been shared among attackers, it cannot be used without the second factor that only you control.
Do this before doing anything else. After securing the password and enabling MFA, check for active sessions.
Most major services have a security dashboard showing every device logged into your account. Sign out of all sessions except your current one.
This immediately cuts off any attacker who has an active session open. This checklist covers the critical first steps when responding to a compromised account.
The sequence matters: secure the account, add MFA, kill active sessions, audit for changes, then address any related accounts. Work quickly — attackers who still have access may be watching your response.
This step is commonly missed. After a compromise, attackers often set up persistent backdoors.
Check your email forwarding rules and filters for anything you did not create. Verify that recovery phone numbers and backup email addresses are still yours.
Look at your sent folder and connected applications for anything suspicious. When the breach touches data belonging to other people — customers, employees, or partners — legal obligations kick in.
Many jurisdictions require disclosure to regulators within a set timeframe, and affected individuals must often be warned too. Loop in your legal team or privacy officer without delay so they can assess scope and guide the response.
Under GDPR, organizations have just seventy-two hours to report a personal data breach. Studies show sixty percent of businesses never fully recover from a significant data loss event.
Your goal should be completing initial recovery steps within twenty-four hours of discovery. After the immediate crisis is resolved, conduct a brief post-incident review.
How did the attacker get in? Was it a reused password from a prior breach, a phishing email, or malware on a device?
Closing that gap prevents recurrence and often reveals similar vulnerabilities across other accounts. Knowing how to respond to a compromised account turns a potential disaster into a recoverable incident.
In the next video, we step back to look at the strategic framework behind modern security: zero-trust, and how its principles for never trusting anything by default produce dramatically better security outcomes.



