Skip to main content
FixMyTech

Someone Is Logged Into My Account — What to Do

By

Published

8 min read

Share

Short answer

Change the password, then sign out every other session — a password change alone does not evict someone already signed in. Before either, check the account's recovery email and phone: if an attacker changed those, they can simply reset the password back. Recovery details first, then password, then sessions.

On this page

The usual advice is to change your password, which is correct and roughly third in order of priority. Doing it first is how people spend an evening on a lockdown and still lose the account by morning.

Two things outrank it. Whoever is in there may have already changed the recovery email and phone number, which lets them reset the password back whenever they like. And a password change on its own does not sign anyone out — existing sessions survive it on most services.

Work in the order below. It is arranged by what removes access, not by what feels like taking action.

Which account first

If more than one is affected, the order is not arbitrary. Email sits above everything because password resets for your other accounts arrive there.

Account type Priority Why
Primary email Immediate Every other reset flows through it
Phone/carrier account Immediate Controls SMS codes and number porting
Password manager Immediate Holds everything else
Banking, payment High Direct financial loss
Social, shopping After the above Usually reachable only via email

If you cannot get into your email, start there and treat the rest as blocked until it is recovered. Working on a shopping account while the attacker still holds the mailbox is wasted effort.

Step 1 — check the recovery details

This is the step that decides whether the rest holds.

In the account’s security settings, look at the recovery email address, the recovery phone number, and any backup codes. You are checking whether they are still yours.

  • Google: Account → Security → How you sign in to Google
  • Apple: Apple Account → Sign-In & Security
  • Microsoft: Account → Security → Advanced security options

If any of them have been changed to something you do not recognise, remove it and put your own back. Do this before touching the password. An attacker who holds a recovery address can undo everything you are about to do.

Also check for a second factor you did not add — an unfamiliar authenticator app or phone number registered as a security key. That is a quieter form of the same problem.

Step 2 — change the password

Now it is worth doing. Use a password you have never used elsewhere, and change it from a device you trust rather than the one you suspect.

If the password has already been changed and you are locked out, stop here and use the provider’s account recovery flow. Those exist precisely for this, and they are slow by design — Apple’s in particular can take several days, and no amount of contacting support shortens the timer. There is no faster legitimate route.

Step 3 — sign out every other session

The step most often skipped, and the reason people get re-compromised a week later. A session cookie stolen through malware or a phishing page keeps working independently of your password.

  • Google: Security → Your devices → Manage all devices → sign out each one
  • Apple: Apple Account → Devices → remove unrecognised ones
  • Microsoft: Security → Sign me out everywhere
  • Facebook, Instagram, X: Settings → Security → where you’re logged in

Our guide on seeing where your Google account is signed in covers the device list in more detail, including entries that look alarming but are your own.

After signing everything out, sign back in on your own devices. Being asked to log in again everywhere is the confirmation that it worked.

Step 4 — check what was changed while they were in

This is the part almost everyone misses, and it is how access persists after a textbook lockdown.

Email forwarding and filters. A rule that silently forwards mail to an outside address, or auto-deletes messages containing “password” or “receipt”, keeps working after you have evicted the session. Check forwarding settings and the full filter or rule list, not just the inbox.

Connected apps. Third-party apps with account access hold their own tokens. In Google this is Security → Your connections to third-party apps; most providers have an equivalent. Revoke anything unfamiliar.

Reply-to address. Rarer, and nastier. Mail appears to come from you but replies go elsewhere.

Account recovery requests in progress. Some providers show pending changes awaiting a confirmation window. Cancel any you did not start.

Step 5 — work outward

Assume anything reachable from the compromised account is also compromised, particularly if it was email.

Check your sent folder and deleted items for password reset emails. Those tell you exactly which other accounts were targeted, and that list is more useful than guessing. Reset those, in the priority order from the table above.

If you reused the compromised password anywhere, change it there too. This is the one case where mass password changes are justified rather than busywork, and checking whether your password was leaked tells you how widely the problem spreads.

Step 6 — close the original hole

A lockdown that leaves the entry route open just delays the next one.

If the cause was a phishing page, the password is now changed and that is dealt with. If a file was downloaded and run, a password change does not help while the malware is still on the device — scanning for and removing malware comes first, from a clean device, before you trust any new password typed on the old one.

Turn on two-factor authentication if it was not already, and prefer an authenticator app over SMS. If it was already on and they got in anyway, the cause was almost certainly a stolen session cookie rather than a defeated second factor, which makes Step 3 the one that mattered.

What this does not fix

Messages already sent from your account cannot be unsent, and anything read cannot be unread. If the account was used to contact people in your contact list, tell them directly — a short message that your account was compromised and to ignore anything odd is more effective than any cleanup you can do inside the account.

Data already copied out is gone. That is an uncomfortable thing to accept, but acting as though a thorough enough lockdown undoes it leads people to skip telling their bank or their contacts, which is the part that still has value.

Most account takeovers end here: evicted in an hour, cleaned up in an evening, with no lasting consequence beyond a few awkward messages. The cases that go badly are nearly always the ones where the recovery details were never checked, or the sessions were never revoked.

Frequently asked questions

Will changing my password kick the other person out?
Not reliably. Most services keep existing sessions alive after a password change, and a stolen session cookie keeps working until it is explicitly revoked. You have to use the sign-out-everywhere control as a separate step.
Why check recovery email and phone before changing the password?
Because whoever has access may have already changed them. If the recovery address points at the attacker, they request a reset and take the account straight back, and you have achieved nothing but a wasted hour.
How did they get in if I have two-factor authentication on?
Usually a stolen session cookie, which bypasses the login step entirely, or an approval you tapped during a prompt-bombing attempt. SMS codes can also be intercepted by taking over the phone number.
Should I delete the account and start fresh?
Rarely, and not for email. Other accounts use it for password resets, and deleting it can free the address for re-registration on some providers. Regaining control and cleaning up is almost always the better route.
How do I know which account was the way in?
Start with whichever account can reset the others. If your email was compromised, assume everything reachable through it was too, and work outward from there rather than treating each account as an isolated incident.

All Security guides