Account and Device Warning Signs
An unfamiliar login alert is stronger evidence than a phone that merely feels slow. Signs of account compromise include a password or recovery-address change you did not make, login notifications from an unknown device or location, messages or posts you did not send, new forwarding rules, unfamiliar connected apps, missing messages, or being locked out. The Federal Trade Commission lists these as common hacked-account indicators.
Device symptoms—unexpected pop-ups, redirects, disabled security tools, unexplained applications, unusual data use, or persistent crashes—can also justify investigation, but any one symptom may have an ordinary technical cause. Treat the pattern and account records as evidence. Do not install a “cleaner” from an unexpected warning window or give a caller remote access to diagnose the problem.
Reference: FTC guidance on signs of a hacked email or social account.
What to Secure First
If you believe a device is actively infected, stop using it for banking, password changes, or sensitive messages. Use another trusted, updated device to begin recovery. Secure the email account first because email often controls password resets for financial, shopping, cloud, and social accounts.
- Follow the provider's official account-recovery process; navigate to it yourself rather than using a link from an alert.
- Change the compromised password and every reused or closely related password.
- Sign out other sessions and remove devices, applications, or passkeys you do not recognize.
- Turn on multifactor authentication, preferably using the strongest method the service supports.
- Verify recovery phone numbers and email addresses, then inspect forwarding rules and filters.
- Update the operating system, browser, applications, and reputable security software before scanning the affected device.
CISA's Secure Our World guidance emphasizes phishing awareness, strong unique passwords, multifactor authentication, and prompt software updates.
Check for Financial and Identity Misuse
Review bank, credit-card, payment-app, mobile-carrier, cloud-storage, and shopping accounts for changes or transactions you did not authorize. Look for new payees, contact details, shipping addresses, account-recovery requests, credit applications, or SIM changes. Contact each provider through its official website, statement, or the number on the card—not contact information contained in a suspicious message.
If personal information was used or exposed, report it at IdentityTheft.gov to receive a recovery plan. Notify financial institutions quickly; available options depend on the account and transaction type. Tell contacts not to trust recent messages from the compromised account, especially requests for money or verification codes.
Preserve Evidence Without Spreading the Problem
Before deleting everything, preserve the facts needed to explain what occurred: screenshots of security alerts, full email headers, sender addresses, phone numbers, URLs shown in messages, dates and times, transaction identifiers, unfamiliar login details, and the sequence of actions already taken. Photograph a suspicious screen with another device if interacting with it could be risky.
Do not forward a suspicious attachment to other people, continue communicating with an intruder, or pay someone who promises instant recovery. Keep original files isolated and record where they came from. For a business account, follow the organization's incident-response process and involve qualified cybersecurity or IT personnel; containment and system restoration are different services from private investigation.
When an Investigator Can Help
A private investigator may help organize the timeline, correlate public identifiers, preserve open-source evidence, document impersonation or harassment, and prepare a coherent evidence package for an attorney, platform, insurer, financial institution, or law-enforcement report. An investigator cannot lawfully break into the suspected actor's accounts or compel a provider to release private subscriber data.
Use the right specialist for the problem. Choose the service provider's recovery team for account access, a qualified incident-response or forensic professional for malware and compromised systems, a bank for transaction response, and law enforcement for threats or active criminal conduct. Investigation is most useful when identity attribution, a documented pattern, or legally collected evidence is the unresolved question. See our identity theft investigations and cybercrime investigations.
Related Services
