Don't panic. Work through these four phases in order. Select what happened to you and follow the steps built for your situation.
Choose your breach type below, then step through four phases: Contain (stop the bleeding), Assess (understand the damage), Recover (rebuild access and report), and Harden (close the gaps so it doesn't happen again). Each phase has specific actions tailored to what was compromised.
Most banks have a card freeze in the app. Use it immediately. If unauthorized transfers occurred, call the fraud line — do not use a number from any email you received.
Before you start resetting things, take screenshots. You'll need these for the fraud claim and potentially for law enforcement.
If your bank login was compromised, any account with the same password is also at risk right now.
Attackers often make small test charges days or weeks before larger ones. Look for:
If someone accessed your banking credentials, they may have also applied for credit in your name. You do not need a police report for most cases — the FTC report is accepted by banks and credit bureaus. Only involve local police if a creditor specifically requires it or you know the thief personally.
Understanding the entry point matters for your fraud claim and for preventing recurrence.
Federal law (Regulation E for bank accounts, Fair Credit Billing Act for credit cards) protects you — but only if you report promptly. Credit cards: generally 60 days. Debit cards: 2 days for full protection, 60 days maximum.
A freeze stops anyone from opening new credit in your name — it's free and the single most effective thing you can do against identity theft.
Most guides skip two bureaus: also freeze ChexSystems (blocks thieves from opening a new bank account in your name) and Innovis (a fourth bureau many lenders check). All five freezes are free. Do all five.
An FTC report (IdentityTheft.gov) creates a legal record and gives you an official document to show creditors. For losses over $500, a police report may help with reimbursement claims.
Many homeowners and renters insurance policies include an identity theft rider or endorsement that covers losses, legal fees, and recovery services — often up to $15,000-$25,000. Most people never think to call their insurer during a financial breach, but this is exactly what that coverage is for.
If shared accounts or family members' information was exposed, be direct with them. Silence creates more anxiety than honest communication.
This is the single most impactful change you can make. A password manager generates and stores long, random, unique passwords — you only remember one master password.
Use an authenticator app (Authy or Google Authenticator) — not SMS. SIM swap attacks can intercept text codes. Your bank, brokerage, PayPal, Venmo, and Zelle all support this.
Credit freezes prevent new accounts but don't alert you to misuse of existing ones. Monitoring catches things freezes don't.
Use a device you trust — ideally not the one you suspect was compromised. If possible, use a different network (mobile data instead of your home Wi-Fi).
Attackers almost always set up email forwarding within minutes of gaining access — so they silently receive all your emails even after you change your password. This survives a password change. Go to Settings > Forwarding (Gmail) or Rules (Outlook) and delete anything you did not create yourself.
Attackers often send emails from your account to your own contacts — phishing your family and friends on your behalf. They also often send password reset emails and delete them.
Think: banks, investment accounts, healthcare portal, Amazon, utilities, your kids' school portal. Every one of those is potentially compromised.
Prioritize in this order: financial accounts, healthcare, government portals, then all other services. Do not reuse the email password.
Send a message through a different channel (text, phone call) to people who may have received emails from your account during the breach window.
Keep it simple: "My email was compromised recently. If you got a message from me asking for money, gift cards, or a link to click, please ignore it. I'm all good now — just wanted to let you know."
Use a hardware key (YubiKey) if you want maximum security, or an authenticator app as a strong middle ground. Remove SMS as a 2FA option if you can — SIM swap attacks bypass it.
Proton Mail and Fastmail offer end-to-end encryption and stronger security defaults than Gmail or Outlook. Worth considering if this breach has you questioning your provider.
Every platform lets you see where you're logged in and force-log out other sessions.
Attackers often connect a third-party app to maintain access even after you change your password.
This is one of the most common attacks — running fake ads charged to your payment method on file.
Critical: Anyone contacting you — via DM, email, or website — offering to recover your account for a fee is running a scam. There are no legitimate paid social media account recovery services. Use only the official links above. Someone who "found your account" and is offering to help is exploiting your situation for a second hit.
Don't let your audience continue to be targeted. A clear, brief statement protects them and rebuilds your credibility.
"My account was compromised recently. Any messages asking for money, gift cards, or asking you to click a link were not from me. I've secured the account and this won't happen again. Sorry if you were contacted — please report and ignore those messages."
If Meta or another platform ran ads or charged your card without authorization, dispute it immediately with your bank — this is fraud and you're protected.
Use an authenticator app, not SMS. Most platforms support this now. Instagram and Facebook also offer hardware key support.
Every app you give your social account access to is a potential attack vector. Do a quarterly review and revoke anything you no longer use.
The most common way social accounts are compromised is fake login pages sent via DM — often appearing to come from a friend whose account was already hacked. Always go directly to the platform's website.
If you provided any login credentials, account numbers, or allowed remote access during the scam, treat those accounts as compromised.
Not sure which one applies to you? Start with the simplest question: Did someone contact you first? If yes, it's almost certainly a relationship-based scam (pig butchering or celebrity impersonation). Did you click a link and connect your crypto wallet? That's a wallet drainer. Did someone get remote access to your computer? Tech support scam. Match your experience to the closest description below:
Crypto transactions are generally irreversible. Wire transfers may be partially recoverable if reported within 72 hours. Gift cards are almost never recoverable. Law enforcement can occasionally freeze or seize assets, but it's rare and slow. Report anyway — it protects others and contributes to prosecution.
If you used Coinbase, Kraken, Binance, or another legitimate exchange to send funds, file a fraud report with them. They can sometimes flag destination wallets.
These scams exploit trust and manufactured relationships. Victims often report feeling ashamed — please don't. These are sophisticated criminal organizations that target smart, careful people. You are not alone.
If you provided personal information (SSN, DOB, account numbers) to the scammer, treat your identity as compromised.
Your email is the master key. If only one thing got through, this is the one to secure first.
Find out if your email and passwords have been exposed in known data breaches.
Not sure what was hacked? That's okay. Look at this list and find the symptom that matches what you noticed. Then click the matching tab at the top to get the specific steps for that type of incident.
If you think a device was compromised (slow, strange behavior, or you allowed remote access), run a scan.
If you suspect stalkerware — software installed by someone with physical access (a partner or family member) to monitor your location, messages, or calls — do not remove it immediately without planning first. Removing stalkerware can alert the person who installed it. If you are in an unsafe situation, contact the Coalition Against Stalkerware or the National Domestic Violence Hotline at 1-800-799-7233 before taking action on the device.
Prioritize: email, banking, investment, healthcare, government portals. Use unique passwords for each — this is exactly when a password manager pays off.
Different agencies handle different situations. Use this as a decision guide:
This is often overlooked, but many standard homeowners and renters policies include an identity theft endorsement or rider. If you've experienced financial fraud, account takeover, or identity theft, call your insurer before assuming you're on your own.
Who should a family member call if they think they've been hacked? What's the first three things to do? Having a simple, shared plan matters more than any single security product.
Unplug the ethernet cable and turn off Wi-Fi right now. If this is a work laptop or a device connected to other computers, also disable Bluetooth.
Ransomware spreads laterally. Disconnect any other computers, NAS drives, or external hard drives that were connected to the same router. If you have a smart home hub or other networked devices, disconnect those too.
Payment does not guarantee file recovery and funds criminal operations. Before paying anything, check whether a free decryptor exists for your ransomware variant. Reformatting destroys any chance of recovery — leave the disk intact.
Use your phone to photograph the screen before doing anything else. You will need the ransomware name, the wallet address, and any contact email for law enforcement reports and insurance claims.
If this is a business device, call your IT provider or MSP immediately — do not try to handle it alone. Notify your cyber insurance carrier within 24 hours; late notice can void coverage. Do not touch servers or shared drives until your IR team is engaged.
Upload the ransom note or an encrypted file sample to ID Ransomware. Knowing the exact variant tells you whether a decryptor exists and how the malware typically enters systems.
List every folder, drive, and cloud service accessible from the infected device. First, confirm it is actual ransomware, not scareware: scareware is a fake browser pop-up claiming your files are encrypted — it has NOT actually locked anything. If you can still open your files normally, close the browser (via Task Manager, not the X button), do not call any phone number displayed in the warning, and do not pay. True ransomware physically renders files unopenable — wrong file extensions, files will not open in any app. Check whether cloud sync (OneDrive, Google Drive, iCloud) propagated encrypted versions of your files — this is common and means your cloud backup may also be compromised.
External drives connected at the time of infection are likely encrypted. Check an offline backup (a drive that was unplugged, or a cloud backup with versioning enabled). If you use Windows Backup or Time Machine and it was connected, assume it is compromised.
Common entry points: phishing email with malicious attachment or link, RDP exposed to the internet, unpatched software vulnerability, malicious download. Check your email for suspicious messages received 1-3 days before the infection appeared. If you clicked a link or opened an attachment, that is likely the source.
Many ransomware groups steal data before encrypting it, then threaten to publish it if you do not pay. Check the attacker's communication for mention of stolen data. If customer or employee PII was accessed, you likely have a breach notification obligation under state law.
File with the FBI Internet Crime Complaint Center and CISA. Law enforcement can sometimes assist with key recovery or disrupt attacker infrastructure. Reports also help establish patterns used to develop future decryptors.
Over 160 ransomware families have free decryptors available. Check before paying any ransom. New decryptors are added regularly as law enforcement disrupts ransomware operations.
Ransomware often installs backdoors that survive malware removal. The only trustworthy recovery is a full OS reinstall from original media. Back up any unencrypted files you still need first, then wipe the drive completely before reinstalling.
Use the most recent backup that predates the infection. If you are unsure when the infection started, use a backup from at least two weeks prior. Verify files open correctly before reconnecting to your network.
The infected machine may have had a keylogger running before the ransomware detonated. Change every password — especially email, banking, and password manager — from a phone or another computer that was not on the same network.
If customer, employee, or patient data was accessed or exfiltrated, state breach notification laws require you to notify affected individuals within a set timeframe (typically 30-60 days). Contact your cyber insurance carrier immediately — most policies require prompt notice and may cover ransom negotiation, recovery costs, and legal fees.
3 copies of your data, on 2 different media types, with 1 stored offsite or offline. At minimum: an external drive that stays unplugged except during backups, plus a cloud backup with version history enabled. Backups that are always connected are not backups — they are part of the attack surface.
Windows Defender has built-in Controlled Folder Access — enable it in Windows Security → Virus & threat protection → Ransomware protection. On macOS, Time Machine with a dedicated backup drive (kept offline between backups) is your primary defense.
Enable automatic updates on your operating system, browser, and any plugins (especially Adobe Reader and Java). The majority of ransomware exploits known vulnerabilities for which patches already exist.
Credential theft often precedes ransomware — attackers steal passwords first, then move laterally. A password manager with unique passwords per site and MFA on every critical account closes the most common initial access path.
Remote Desktop Protocol exposed directly to the internet is the leading ransomware entry point for small businesses. Either disable RDP entirely if it is not needed, or require VPN access before RDP is reachable. Enable Network Level Authentication and account lockout policies.
Review every device on your network for outdated software, exposed ports, and shared credentials. If this was a business incident, bring in a professional for a post-incident review before declaring recovery complete.