Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Editorial illustration of account access verification
Editorial illustration

Response guide · accounts and email

Recover a compromised account and check that access is under control.

Changing a password does not close an incident on its own. Recovery should also review sessions, recovery channels and delegated access. Start with the provider’s official process and involve IT for a business account.

Published 3 October 2026Updated 3 October 2026

At a glance

Four rules for a useful review.

  • Use a trusted device.
  • Reach support through the official website.
  • Keep relevant alerts and times.
  • Review persistent access after recovery.

Step-by-step method

A reproducible path from question to conclusion.

  1. 1

    Assess the signs

    Distinguish an attempted sign-in alert from successful access. Record unrequested changes, sent messages, new devices and observed operations. An unusual location alone may reflect a VPN or imprecision.

  2. 2

    Regain control

    Open the official website directly from a trusted device. Use its hacked-account or recovery process. For a managed account, involve the administrator. Avoid links and numbers supplied by a supposed recovery agent.

  3. 3

    Close unnecessary access

    Follow the provider’s settings to change the password, remove unknown devices and revoke sessions. Check recovery email and phone, forwarding rules and authorised applications.

  4. 4

    Protect dependencies

    List accounts whose reset depends on this mailbox. Prioritise payments, administrative accounts and sensitive storage. Warn affected contacts if fraudulent requests were sent.

  5. 5

    Check stabilisation

    Record actions, reviewed access and new events. Recurrence, a suspect device or changed privileges calls for technical investigation.

Sessions, delegation and applications need separate checks

An open session, a forwarding rule and an authorised application are different forms of access. Settings and reset effects vary by service. Do not assume one action covers everything: consult documentation and record the checks actually completed.

For business email, ask the administrator to review delegation, rules, logs and permission changes. Coordinate before modifying organisational settings or evidence.

Choose protection and plan its recovery

CISA distinguishes MFA methods and recommends phishing-resistant FIDO/WebAuthn options where available. The choice should account for the provider, devices and a legitimate recovery path.

Document an appropriate backup method and protect recovery codes outside the mailbox being secured. Test the process with the account owner. Never disclose a temporary code to someone who contacts you.

Close the incident using observable criteria

Closure means access has been reviewed, identified consequences addressed and known limitations accepted by an owner. It does not establish that all data was unaffected.

A short file can record the known start, last signs, actions, preserved logs, notified recipients and next review. If personal data is involved, have the responsible functions assess applicable duties.

Common pitfalls

Four shortcuts that weaken the result.

Resetting then forgetting

Also check sessions and delegated access.

Paying for guaranteed recovery

Use official support rather than an unverified intermediary.

Deleting alerts

Keep the traces needed for the case.

Returning through a suspect device

Seek technical assessment if the device may be compromised.

Practical questions

Frequently asked questions.

Is the password enough?

No. Review the service’s access mechanisms, including sessions, recovery channels and authorised applications.

What if recovery fails?

Follow the provider’s official pathway and keep case references. Contact the administrator for an organisational account.

Does MFA prevent every incident?

No. Protection depends on method and context. It does not replace session review or device and support security.

Public references

Cybermalveillance.gouv.fr — account compromise. French response guidance for recovery and protection.

CISA — More than a Password. MFA methods and phishing resistance.

Editorial scope

Published by Internet Intelligence Service on 3 October 2026. Last content update: 3 October 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.

Find primary portals and their limitations