Someone Is Logged Into My Account — What to Do
Work the lockdown in the order that stops access first. Recovery details before password, sessions before cleanup, and the forwarding rules most people never check.
Security advice usually arrives as a list of things you should already have done, which is useless at the moment something has actually gone wrong. These guides are built the other way around: what the attack actually is, how to tell whether you are affected, and the specific order of steps that limits the damage. They also say plainly when a popular precaution is not worth your time, because attention spent on theatre is attention not spent on the controls that matter.
Work the lockdown in the order that stops access first. Recovery details before password, sessions before cleanup, and the forwarding rules most people never check.
The pop-up is an advert, not a detection. Here is how the con works from the page to the phone call, and the one thing you must never do.
Changing the search engine back does not work while the thing that changed it is still installed. Remove it in this order and it stays fixed.
Your browser already checks every saved password against known breaches. Here is where that report lives, and what to do with what it finds.
An exposed email address is not an emergency. What was exposed alongside it decides whether you have ten minutes of work or a serious afternoon.
The advice everyone repeats describes a web that stopped existing a decade ago. Here is what public Wi-Fi can and cannot expose now that HTTPS is universal.
A firewall filters connections by port and program. It cannot tell a good download from a bad one, which is why it is only part of the picture.
Display names are free and logos are copy-paste. Read the actual sending domain and the link destination, and most fakes collapse in ten seconds.
An ordered checklist that starts with the step that stops ongoing damage, not the one that feels productive. Work down it and stop where it stops applying.
Most phone malware symptoms are a battery-hungry app or a browser notification. Here is what counts as evidence, and what to check before worrying.
Unsubscribing works on legitimate marketing and backfires on real spam. Here is how to tell which you are looking at before you touch anything.
macOS already runs three layers of malware protection you never see. Here is what they cover, what they miss, and when a scanner is actually worth installing.
Microsoft Defender covers the malware scanning most people need. Here is what paid suites actually add, and which of those additions are worth money.
A normal scan can be defeated by malware already running. The Defender offline scan reboots first, which is why it finds what the quick scan missed.
Macs get adware and browser hijackers far more often than viruses. Here is where to look, in the order that finds the real thing fastest.
Social engineering attacks the person, not the software. Learn the four pressure patterns behind nearly every version, and the one rule that defeats them.
A botnet is thousands of ordinary devices quietly taking orders from a stranger. Here is how yours would join, and the handful of checks that matter.
Someone sits between you and the site you think you are talking to. Here is what that actually requires, and why HTTPS made most versions of it fail.
Opening the page is rarely the problem. What you typed next decides whether this is a non-event or an hour of work — here is how to tell which.
Phishing works by manufacturing urgency, not by looking convincing. Here are the signals that actually separate a real message from a fake one.
Set up two-factor authentication that you cannot get locked out of, recover accounts when you lose your phone, and audit where you are signed in.
14 guides
What a VPN actually does, which features matter, and how to fix one that is slow, leaking or connected but not working the way you expect.
16 guides