Highlighted wordsare glossary terms — tap one for a plain-language definition.
Account takeoverWhat it means: When someone other than the owner gains control of an account, usually through a stolen or reused password, a phished code, or a SIM swap.Example: Friends receive money requests “from you,” and your email forwarding rules have changed on their own.What to do: From a trusted device, change the password, sign out all sessions, review recovery options, and turn on MFA.Important: Email is the master key — protect it first, because attackers reset everything else through it.What does this mean? is when someone else gets into your email, social media, bank, or shopping account and starts acting as you. It often starts with a reused password, a PhishingWhat it means: A deceptive email or message designed to make you click, share information, send money, or give account access.Example: An “unpaid delivery fee” text with a link to a page that looks like the post office.What to do: Don't tap links in unexpected messages — open the company's app or type its address yourself.Important: Real companies never ask for your password or a login code by message.What does this mean? link, a leaked code, or a SIM swapWhat it means: An attack in which a criminal tries to take control of your phone number, which can affect text-message codes and account recovery.Example: Your phone loses service, and password reset texts start arriving somewhere else.What to do: Ask your mobile carrier to add a PIN or port-out lock to your account.Important: It's one reason phishing-resistant sign-in is preferable to SMS where a service offers both.What does this mean?. Your email account matters most, because it can reset the passwords to almost everything else. [1, 2]
Spot the signs early
Warning signs include password-reset emails you did not request, sign-in alerts from new places or devices, messages or posts you did not send, changed recovery details, new forwarding rules, and friends saying you asked them for money. Act on these quickly — every hour gives the intruder more time to lock you out. [1, 2]
- Treat an unexpected Verification codeWhat it means: A temporary code used to verify a login or action. Don't provide an unexpected code to an incoming caller or message.Example: “Your verification code is 481920.”What to do: Only enter a code on a page or app you opened yourself.Important: A code you didn't request often means someone has your password — change it from a trusted device.What does this mean? as a warning: someone may be trying your password right now.
- Never read a code back to someone who calls or messages you, even if they claim to be support. [3]
- Check your email's sent folder and filters for things you did not create.
Take the account back
Use a device you trust and go to the official app or type the site address yourself — never follow a link in a 'recover your account' message. Use the provider's recovery process to reset the password. If you are locked out, the provider's official account-recovery page is the only safe route; people who offer to 'recover' accounts for a fee are often scammers. [1, 2]
- Change to a long, unique password or passphrase you use nowhere else. [4]
- Sign out of all other sessions and devices.
- Remove recovery emails, phone numbers, and connected apps you do not recognize.
- If the same password was used anywhere else, change those accounts too.
Change the locks
Once you are back in, add Multifactor authenticationWhat it means: Using more than one type of authentication evidence before an account grants access.Example: Entering your password and then approving the login through an authenticator app.What to do: Turn it on first for your email, financial, social-media, and cloud accounts.Important: Never give an unexpected login code to someone who contacts you.What does this mean? so a stolen password alone is not enough. Passkeys and security keys resist phishing best; an Authenticator appWhat it means: An app that generates temporary login codes or supports account-approval methods.Example: A six-digit code that changes every thirty seconds.What to do: Install one, then enable its backup so a lost phone doesn't lock you out.Important: No support agent ever needs you to read a code from this app aloud.What does this mean? is a strong next step; text-message codes are better than nothing. Save your recovery codes somewhere offline. [3, 4]
- Turn on a PasskeyWhat it means: A phishing-resistant way to sign in using cryptographic credentials stored or managed by a trusted device or credential provider, instead of typing a reusable password.Example: Unlocking an account with your fingerprint, face, or device PIN — nothing to type.What to do: Consider a passkey when an important account offers one, starting with your email.Important: Keep a device lock and a backup sign-in method in case you lose the device.What does this mean? or authenticator app for email first, then banking, then social media.
- Ask your mobile carrier about a port-out or SIM lock to reduce SIM-swap risk.
- Run your device's security updates and scan for MalwareWhat it means: Software designed to damage, spy on, disrupt, or gain unauthorized access to a device.Example: A “free video player” download that quietly installs something else.What to do: Install apps only from official stores and keep automatic updates switched on.Important: Pop-ups warning that your device is infected are usually the scam itself.What does this mean? if you clicked a Suspicious linkWhat it means: A link whose destination, sender, wording, or context may be deceptive.Example: A login page at “paypa1-secure.com” instead of the real domain.What to do: Long-press or hover to preview the real destination before opening it.Important: Shortened links and QR codes hide where you are actually going.What does this mean?.
Limit the damage
Tell friends and followers through a different channel that your account was hacked and to ignore requests for money or codes. If money moved, contact your bank or payment app right away. If Personal informationWhat it means: Information that identifies or can be connected to a person.Example: Your full name together with your birthdate and home address.What to do: Share only the minimum a form actually requires.Important: Small details combined are enough for identity theft.What does this mean? was exposed and could be used to open accounts, follow an identity theft Recovery planWhat it means: A prepared set of actions for responding to account theft, scams, lost devices, or exposed information.Example: Written steps plus saved bank and platform support numbers.What to do: Write it now and keep a copy offline where you can reach it without your phone.Important: The first hour after a compromise matters most, so don't improvise it.What does this mean? at IdentityTheft.gov. [1, 5]
- Report fake posts or messages to the platform so it can remove them.
- Report scams or money lost to ReportFraud.ftc.gov.
- Keep a short log of what happened and any case or ticket numbers.
Why Hygi. recommends this — the guidance above follows these published sources:
Federal Trade Commission
How To Recover Your Hacked Email or Social Media Account(opens in a new tab)Warning signs, official recovery steps, and how to protect contacts after a takeover.
Federal Trade Commission
Email or Social Media Hacked? Here's What To Do(opens in a new tab)Published October 29, 2024. Sign out other sessions, reset passwords, add multifactor, and fix recovery details.
CISA
Turn On Multifactor Authentication(opens in a new tab)Secure Our World guidance on MFA and why phishing-resistant methods are strongest.
NIST
SP 800-63B-4: Authentication and Authenticator Management(opens in a new tab)Length over complexity, no forced rotation, and phishing-resistant authenticators.
Federal Trade Commission
IdentityTheft.gov(opens in a new tab)Official FTC identity theft reporting and personal recovery plans.
Brought to you by NorthBridge
Unfamiliar term? Open the Digital Safety Glossary