What to Do in the First Hour After an Account Is Breached
When an account goes wrong, the first hour decides how expensive the aftermath is. Work a checklist, not panic: stop the bleeding, lock the intruder out, then leave a trail.
Minutes 0-10: cut their access
- If you can log in, change the password to a new, unique one and sign out of all sessions/devices.
- If you cannot, use the recovery flow immediately; the password reset usually lands in your email, so secure email first if that is also compromised.
- Enable 2FA on the spot if you did not have it, so the new password is not enough on its own.
Minutes 10-25: stop the money and the spread
- Call or use the app to freeze the linked card or lock the bank account while you check.
- Look for and reverse any pending transfer you did not make; time-limit windows matter.
- Check the account’s connected services — app authorizations, alternate emails and forwarding rules the attacker may have added to keep coming back.
Minutes 25-45: contain the blast radius
A breached password is usually reused. Fix the other accounts that share the same email or password before they get hit too, and confirm your recovery phone/email on each important account has not been silently redirected to them.
Minutes 45-60: leave a trail
- Note exactly what you saw and when, with screenshots.
- Report to the bank/platform officially even for small amounts; the record starts the clock and supports dispute.
- For identity documents, consider a fraud alert or credit freeze with the bureaus, and set your free monitoring on.
The traps that turn one breach into many
- Resetting the email after the linked bank is still open lets them grab it again.
- Leaving the same reused password on your password manager defeats the fix.
- Panic-deleting messages destroys the evidence you need for disputes.
After the dust
Watch statements and credit for weeks, not just that day; delayed fraud is common. If it touched your workplace or an elder relative, say so early — the same leak is often spreading to them.