Someone Is Logged Into My Account — What to Do
Short answer
Change the password, then sign out every other session — a password change alone does not evict someone already signed in. Before either, check the account's recovery email and phone: if an attacker changed those, they can simply reset the password back. Recovery details first, then password, then sessions.
On this page
The usual advice is to change your password, which is correct and roughly third in order of priority. Doing it first is how people spend an evening on a lockdown and still lose the account by morning.
Two things outrank it. Whoever is in there may have already changed the recovery email and phone number, which lets them reset the password back whenever they like. And a password change on its own does not sign anyone out — existing sessions survive it on most services.
Work in the order below. It is arranged by what removes access, not by what feels like taking action.
Which account first
If more than one is affected, the order is not arbitrary. Email sits above everything because password resets for your other accounts arrive there.
| Account type | Priority | Why |
|---|---|---|
| Primary email | Immediate | Every other reset flows through it |
| Phone/carrier account | Immediate | Controls SMS codes and number porting |
| Password manager | Immediate | Holds everything else |
| Banking, payment | High | Direct financial loss |
| Social, shopping | After the above | Usually reachable only via email |
If you cannot get into your email, start there and treat the rest as blocked until it is recovered. Working on a shopping account while the attacker still holds the mailbox is wasted effort.
Step 1 — check the recovery details
This is the step that decides whether the rest holds.
In the account’s security settings, look at the recovery email address, the recovery phone number, and any backup codes. You are checking whether they are still yours.
- Google: Account → Security → How you sign in to Google
- Apple: Apple Account → Sign-In & Security
- Microsoft: Account → Security → Advanced security options
If any of them have been changed to something you do not recognise, remove it and put your own back. Do this before touching the password. An attacker who holds a recovery address can undo everything you are about to do.
Also check for a second factor you did not add — an unfamiliar authenticator app or phone number registered as a security key. That is a quieter form of the same problem.
Step 2 — change the password
Now it is worth doing. Use a password you have never used elsewhere, and change it from a device you trust rather than the one you suspect.
If the password has already been changed and you are locked out, stop here and use the provider’s account recovery flow. Those exist precisely for this, and they are slow by design — Apple’s in particular can take several days, and no amount of contacting support shortens the timer. There is no faster legitimate route.
Step 3 — sign out every other session
The step most often skipped, and the reason people get re-compromised a week later. A session cookie stolen through malware or a phishing page keeps working independently of your password.
- Google: Security → Your devices → Manage all devices → sign out each one
- Apple: Apple Account → Devices → remove unrecognised ones
- Microsoft: Security → Sign me out everywhere
- Facebook, Instagram, X: Settings → Security → where you’re logged in
Our guide on seeing where your Google account is signed in covers the device list in more detail, including entries that look alarming but are your own.
After signing everything out, sign back in on your own devices. Being asked to log in again everywhere is the confirmation that it worked.
Step 4 — check what was changed while they were in
This is the part almost everyone misses, and it is how access persists after a textbook lockdown.
Email forwarding and filters. A rule that silently forwards mail to an outside address, or auto-deletes messages containing “password” or “receipt”, keeps working after you have evicted the session. Check forwarding settings and the full filter or rule list, not just the inbox.
Connected apps. Third-party apps with account access hold their own tokens. In Google this is Security → Your connections to third-party apps; most providers have an equivalent. Revoke anything unfamiliar.
Reply-to address. Rarer, and nastier. Mail appears to come from you but replies go elsewhere.
Account recovery requests in progress. Some providers show pending changes awaiting a confirmation window. Cancel any you did not start.
Step 5 — work outward
Assume anything reachable from the compromised account is also compromised, particularly if it was email.
Check your sent folder and deleted items for password reset emails. Those tell you exactly which other accounts were targeted, and that list is more useful than guessing. Reset those, in the priority order from the table above.
If you reused the compromised password anywhere, change it there too. This is the one case where mass password changes are justified rather than busywork, and checking whether your password was leaked tells you how widely the problem spreads.
Step 6 — close the original hole
A lockdown that leaves the entry route open just delays the next one.
If the cause was a phishing page, the password is now changed and that is dealt with. If a file was downloaded and run, a password change does not help while the malware is still on the device — scanning for and removing malware comes first, from a clean device, before you trust any new password typed on the old one.
Turn on two-factor authentication if it was not already, and prefer an authenticator app over SMS. If it was already on and they got in anyway, the cause was almost certainly a stolen session cookie rather than a defeated second factor, which makes Step 3 the one that mattered.
What this does not fix
Messages already sent from your account cannot be unsent, and anything read cannot be unread. If the account was used to contact people in your contact list, tell them directly — a short message that your account was compromised and to ignore anything odd is more effective than any cleanup you can do inside the account.
Data already copied out is gone. That is an uncomfortable thing to accept, but acting as though a thorough enough lockdown undoes it leads people to skip telling their bank or their contacts, which is the part that still has value.
Most account takeovers end here: evicted in an hour, cleaned up in an evening, with no lasting consequence beyond a few awkward messages. The cases that go badly are nearly always the ones where the recovery details were never checked, or the sessions were never revoked.