Skip to main content
Recovery

So, Your Account Was Hacked — What To Do In The First Hour

John Sabo 6 min read

So, Your Account Was Hacked — What To Do In The First Hour

The first hour after an account takeover decides how the next six months go. I mean that literally. The accounts that come back clean are almost always the ones where somebody moved quickly and stayed calm.

This is the checklist I would hand a friend. It assumes you just found out, and it assumes you are not a security professional.

Minutes 0 to 10: stop the bleeding

Change the password now, from a different device than the one you normally use. If you normally check that account on your laptop and your laptop is the thing that feels wrong, use your phone, or a family member's computer.

Use a password you have never used anywhere else. If the site offers "sign out of all other devices" or "sign out everywhere," press it. That single button ends most active sessions an attacker is holding.

Then check that you can still get in tomorrow. Confirm the recovery email and the recovery phone number on the account are yours. Attackers change those first, because they turn a temporary intrusion into permanent ownership.

Minutes 10 to 20: read the settings, not the inbox

Do not start reading your email yet. Start reading your settings.

Look for a forwarding rule or a filter that sends your mail somewhere else. Look for a new "app password" or an application that has been granted access. Look for a new device on the trusted list. In my experience, a silent forwarding rule is the single most common thing left behind, and it is the thing that keeps the attacker in your life long after you changed the password.

Minutes 20 to 30: money and connected apps

Open the payment methods and remove anything you do not recognize. Then look at the apps that connect to this account, like the ones that read your files or post on your behalf. Revoke everything you cannot explain.

If this is a work account, tell your IT person now. Not at the end of the day. Now. An attacker with your work mailbox can email your customers and your vendors, and that damage is much harder to undo than a password reset.

Minutes 30 to 45: tell the people who need to know

Tell your bank if any payment method was connected. Call the number on the back of the card, not a number from an email.

Tell your staff, and tell your customers if the account could have reached them. A short, plain note beats a polished one. "Somebody got into my email this morning. If you got a strange message from me, please delete it and don't click anything."

Minutes 45 to 60: write down what you saw

Open a document and write a timeline. When you noticed, what you saw, what you changed, who you told, and anything strange you remember but cannot prove yet. Timestamps matter later, whether you handle this yourself or hand it to someone else.

Take screenshots before you clean up. It feels like a waste of five minutes. It is not.

When to call a professional

Call someone when any of these is true:

  • The account you lost is a business account, a domain registrar, or an email administrator account.
  • You changed the password and the attacker came back.
  • Money moved, or customer data was reachable from that account.
  • The lockout is on a platform with a review process instead of a support line.

That last one is the hardest case, and it is the one I get called about most. Meta is the clearest example. When a Facebook Business Portfolio gets locked, there is no password reset that helps. There is a case process, a review queue, and a set of evidence Meta expects to see. I have watched people spend four months on it and I have watched the same recovery close in about a week when the filing is done properly.

I built a service for exactly that problem. If you lost a Facebook Business Portfolio or a Page to a lockout, I run the whole Meta recovery process for you, from the case filing to the admin cleanup afterwards. Recently I recovered an entire portfolio for a Mesa family farm, case closed in September 2026, every Page and every admin seat back.

The part nobody says out loud

Getting hacked is not evidence that you were careless. I have watched people with excellent habits get taken by a stolen session cookie, which is a piece of data that does not need your password at all. The people who recover well are the ones who act quickly, keep records, and ask for help before the trail goes cold.

Work with me

If you are in the middle of this right now, call me. 602.501.0772. I answer the phone, and I will tell you honestly whether you need me.

If it can wait a day, book the free 30-minute consult at /book and bring your timeline. We will go through what happened and what is still exposed. Every engagement starts with that free consult and ends with a written quote, no obligation either way.

John Sabo — Lono Security Chandler, Arizona · Phoenix Metro · Remote everywhere

JS

John Sabo

John Sabo — 30 years in cybersecurity, GoDaddy WAF architect

Work with me

Every engagement starts with a free 30-minute consult and ends with a written quote.

Book a free consult