Locked Out or Hacked? How to Protect and Recover Your Online Accounts
Could you get back into your email, social media, or bank account if you were locked out today?
Most people assume they can reset a password and move on.
But what happens when the recovery phone number is old? What if the recovery email address no longer works? What if someone changed the password before you noticed?
Several people I know have recently been locked out of important accounts. Some forgot their passwords and had never set up recovery options. Others clicked a suspicious link and worried that someone might have stolen their login information.
One friend replaced her phone and discovered that she could no longer access the password saved on her old device. She tried the usual account-recovery process, but support could not help her regain access. Eventually, I worked with her to recover the main email account she had used for years.
Being Locked Out Is Not Always the Same as Being Hacked
First, determine what may have happened.
You may have forgotten your password, lost access to an old phone number, or triggered a security check. That does not always mean someone stole your account.
However, these warning signs may point to unauthorized access:
Your password suddenly stops working.
You receive a password-reset message you did not request.
Your recovery email address or phone number changed.
You see a login from an unfamiliar device or location.
Friends receive messages you did not send.
You notice purchases, transfers, or charges you do not recognize.
If you see any of these signs, act quickly. Start with your email account.
Why Your Email Account Comes First
Your email is like the master key to many parts of your online life.
Banks, credit cards, shopping sites, and social media platforms often send password-reset links through email. If someone controls your email, that person may be able to reset other passwords and take over more accounts.
If you can still access your email:
Change the password.
Make the new password long and unique.
Sign out of all other devices or sessions.
Turn on multi-factor authentication.
Confirm that your recovery email and phone number are correct.
Check for email-forwarding rules you did not create.
Review your sent and deleted folders for activity you do not recognize.
The FTC also recommends checking for unauthorized forwarding rules because someone could use them to secretly receive copies of your messages.
If you cannot sign in, use the provider’s official account-recovery page. Do not trust a phone number or recovery link found in an unexpected message.
How to Check for Email Forwarding Rules
Someone who gets into your email may create a hidden forwarding rule. This can send copies of your messages to another address, even after you change your password.
Check both Forwarding and Rules or Filters because they are usually stored in separate places. If the steps below do not match what you see, visit your email provider’s official support page for current instructions.
Gmail
Using Gmail on a computer:
Open Gmail.
Select the Settings gear.
Select See all settings.
Open Forwarding and POP/IMAP.
Check whether your email is being forwarded to an address you do not recognize.
Disable unauthorized forwarding and remove the unfamiliar address.
Open Filters and Blocked Addresses.
Look for filters that forward, delete, archive, or mark messages as read.
Delete anything you did not create.
Outlook or Hotmail
Using Outlook on the web:
Open Outlook.
Select the Settings gear.
Select Mail.
Select Forwarding.
Make sure forwarding is turned off unless you intentionally use it.
Return to Mail and select Rules.
Look for rules that forward, redirect, delete, move, or mark messages as read.
Delete any rule you do not recognize.
Yahoo Mail
Open Yahoo Mail.
Select Settings.
Select More Settings.
Select Mailboxes.
Choose your primary email account.
Review the forwarding section for an unfamiliar address.
Select Filters.
Delete filters you did not create, especially ones moving important messages out of your inbox.
iCloud Mail
Go to iCloud.com/mail and sign in.
Select the Settings button.
Select Settings.
Select Mail Forwarding or Forwarding.
Check whether Forward my email to is turned on.
Remove any address you do not recognize.
Select Rules.
Delete unfamiliar rules, especially those that forward messages or mark them as read.
If You Find a Rule You Did Not Create
Removing the rule is not enough. It may mean someone accessed your email account.
Immediately:
Take a screenshot of the rule and forwarding address, if it is safe to do so.
Delete the unauthorized rule.
Change your password from a trusted device.
Sign out of all other devices and sessions.
Turn on MFA.
Check your recovery phone number and email address.
Review your sent, deleted, archived, and trash folders.
Check your bank, credit card, social media, shopping, and payment accounts.
A hidden rule can quietly expose password resets, financial alerts, and personal messages. Check it before assuming that changing the password solved everything.
Set Up Account Recovery Before You Need It
Do not wait until you are locked out.
Review the recovery settings for your important accounts and add:
A current mobile phone number
A recovery email address you can access
Multi-factor authentication
Saved recovery or backup codes
A trusted device, when the service supports it
Recovery codes are especially important. They can help you sign in if your phone is lost, replaced, or unavailable.
Store the codes somewhere safe. Do not keep your only copy inside the account they are meant to recover.
You can use the password manager built into your phone or browser, such as Apple Passwords or Google Password Manager. You can also choose a trusted standalone password manager. The best option is one you understand and will use consistently.
Quick Win
Choose your main email account today. Check the recovery phone number and recovery email address.
This small task could save hours of frustration later.
Use a Different Password for Every Important Account
Reusing one password creates a chain reaction.
If a scammer steals the password from one account, that person may try the same password on your email, bank, credit card, shopping, and social media accounts.
Use a unique password or passphrase for every important account. A password manager can create and store them for you.
Then turn on multi-factor authentication whenever it is available.
MFA adds another step to the login process. It cannot prevent every type of account theft, but it can reduce the chance that someone can sign in with only your password.
Review Social Media Privacy and Security
Account recovery is only one part of social media safety.
While reviewing your settings:
Make your profile private when appropriate.
Review who can see your posts and photographs.
Remove people you do not recognize.
Check active login sessions.
Sign out unfamiliar devices.
Limit who can find you using your phone number or email address.
Review connected apps and remove ones you no longer use.
Check who can tag you, message you, or mention your account.
Public information can help scammers impersonate you or answer common security questions.
Reviewing these settings will not eliminate every risk, but it can reduce how much personal information is available to strangers.
What If You Clicked a Suspicious Link?
Did you only open the message, or did you enter information?
If you clicked a link but did not enter a password, payment information, or personal details, close the page. Update your device’s security software and run a security scan if you downloaded a file or installed anything.
If you entered a username and password, assume the information may have been stolen.
Take these steps:
Go directly to the real website or official app.
Change the affected password immediately.
Change it anywhere else you used the same or a similar password.
Sign out of other devices and sessions.
Turn on MFA.
Review account activity and recovery settings.
Watch for additional password-reset messages and scam attempts.
Do not return to the link in the original message.
Check Your Bank and Credit Card Accounts
If the suspicious page requested financial information, review your bank, credit card, payment, and shopping accounts.
Look for:
Charges you do not recognize
Small test charges
New payees or linked accounts
Transfers you did not make
Changes to your contact information
New cards or accounts you did not request
Contact the bank or credit card company immediately if something looks wrong.
Use the official mobile app, type the website address yourself, or call the number printed on the back of your card. Do not call a number provided in the suspicious message.
If your bank or credit card information was stolen, the federal government’s IdentityTheft.gov website can create a recovery plan based on what happened.
Help Family Members Before There Is an Emergency
Parents, grandparents, teens, and other family members may need help setting up account recovery.
Sit together and review one account at a time.
Do not ask them to give you their passwords. Help them create a safe system they understand and can use on their own.
This Week’s Goal
Review these four accounts:
Your main email
Your primary social media account
Your bank account
Your main credit card account
For each account, confirm the password is unique, MFA is active, and the recovery information is correct.
Final Thoughts
Being locked out of an account is frustrating. Discovering that someone else may be using it is even more stressful.
You do not need to fix every account in one day.
Start with your email, then review your financial and social media accounts. Set up recovery options before an emergency happens, and teach your family members how to do the same.
A few minutes of prevention today can make account recovery much easier tomorrow.
Keep Learning
Are Passwords Going Away? Understanding Passkeys Without the Confusion
Learn how passkeys work and how they may make your accounts easier and safer to access.
Five Quick Ways to Keep Your Family Safe Online
Start with five simple habits that can help protect your family’s accounts, devices, and personal information.
What to Do After a Data Breach
Follow practical steps to protect your accounts and personal information after a company reports a breach.
Get the Free Family Cybersecurity Checklist
Not sure which security settings your family should review first?
Download the Free Family Cybersecurity Checklist for simple steps that can help you protect your accounts, devices, and personal information.
Stay safe,
The SimplifySec Team
Simple. Practical. Cybersecurity.
About SimplifySec
SimplifySec helps families and small businesses understand cybersecurity without confusing technical language.
Our goal is to make online safety feel practical, manageable, and part of everyday life.
Disclaimer
The content on this blog is published by SimplifySec Group LLC for general educational and informational purposes only. It is not legal, financial, or professional cybersecurity advice, and reading a blog post does not create a professional-client relationship between you and SimplifySec.
Cybersecurity risks depend on your specific environment, and recommendations that work for one system or business may not be appropriate for yours. You should evaluate your own circumstances and consult a qualified professional before acting on anything you read here. SimplifySec makes no warranty that the information is complete, current, or error-free, and to the fullest extent permitted by law disclaims liability for any loss arising from your reliance on it.
This blog may link to or reference third-party tools, vendors, or resources for convenience. SimplifySec does not endorse, control, or assume responsibility for those third parties or their content.
© 2026 SimplifySec Group LLC. All rights reserved.
This article may not be copied, reproduced, distributed, or republished, in whole or in part, without prior written permission from SimplifySec Group LLC, except as permitted by applicable copyright law.

