What to do if you get hacked: a complete guide on how to react and protect yourself

Last update: March 1th 2026
  • Detecting the signs of a hack quickly allows you to limit the damage to accounts, devices, and personal data.
  • It is crucial to disconnect, change passwords, enable 2FA, and scan devices for malware.
  • In the event of leaks or fraud, banks and companies should be notified, and official cybersecurity channels should be used.
  • The best defense is prevention through good digital practices, training, and security tools.

digital security after a hack

When you realize something strange is happening with your accounts or devices, it's easy to panic. However, what truly makes the difference is acting quickly, calmly, and following a series of clear steps . In this guide, you'll learn how to detect a potential hack, what to do immediately, how to recover stolen accounts, what legal and financial risks are involved, and, most importantly, how to protect yourself from it happening again.

Clear signs that your account or device has been hacked

Before you frantically start changing things, it's important to identify whether you're actually facing a security incident or just a technical failure; there are several typical symptoms that someone has accessed your accounts or devices without permission.

One of the most common warning signs is losing access to your email, social media, or online banking , and having your long-standing password stop working even though you haven't changed it. If you also receive messages indicating that your session has been initiated from an unfamiliar device or location, the suspicion increases.

It's also very common for your friends, family, or clients to tell you that they receive strange emails or messages from your address or profile: suspicious links , requests for money, files you haven't sent, or texts that don't match your writing style.

On a technical level, your computer or mobile device may start running extremely slowly, freeze, restart for no reason , or display pop-up windows you've never seen before. You might even see installed applications that you don't remember downloading.

Another dangerous clue is noticing strange movements in your bank accounts or payment services : charges you don't recognize, online purchases you haven't made, new addresses, or modifications to your payment methods saved on platforms like Amazon, eBay, or other stores.

What to do immediately if you suspect you've been hacked

When you detect any of these symptoms, it's not a good idea to just stand by and watch; the first few hours are key to limiting the damage, cutting off the attacker's access, and protecting your sensitive information.

1. Disconnect the device from the Internet

If the problem appears to be with your computer, tablet, or mobile device, the first thing to do is disconnect it from the internet to stop the attack . As long as the device remains connected, the attacker can continue sending data, installing malware, or controlling it remotely.

In practice, you can turn off Wi-Fi, disable mobile data, or activate airplane mode if you're on a phone. If you suspect the attack is affecting multiple devices at home or in the office, you can even turn off your router for a few minutes to buy time and prevent the problem from spreading.

2. Change all your passwords from a secure computer

The next critical step is to update the passwords for all your important accounts (email, social media, online banking, cloud storage, etc.), but always from a device that you are almost certain is not compromised.

New passwords should be strong, unique, and difficult to guess . Ideally, they should combine uppercase and lowercase letters, numbers, and symbols, avoiding proper names, birthdates, dictionary words, or information that anyone can find on your social media profiles.

Additionally, it's best not to reuse the same password across multiple services . If an attacker has stolen one, their first instinct will be to try it on your other accounts. A reliable password manager can help you generate and store long, unique passwords without having to memorize them all.

Whenever possible, enable two-step authentication (2FA) or multi-factor authentication on your main services (Google, Apple, social media, banking, etc.). This way, even if a hacker has your password, they'll need an additional code sent to your mobile phone or generated by a specific app, making unauthorized access much more difficult.

If you can no longer access your account because the password has been changed, you should use the "Forgot your password?" or "Recover account" function on the platform itself. Also, check your email for any password change notifications and try to reset the password using the link provided, including checking your spam or junk folder.

3. Review the recent activity on your accounts

Once you start to regain control, it's time to carefully examine what was done to your accounts during the hack . This will give you clues about the extent of the problem and whether they still have access.

On services like Google, Microsoft, or Facebook, you can check connected devices, login locations, and recent activity . If you see devices you don't recognize, unusual geographic areas, or impossible times, close all active sessions and force log out on all devices, then change your password again if necessary.

In addition to checking your login credentials, it's important to look for emails or messages you didn't write , unusual posts, changes to your personal information, new recovery email addresses, or phone numbers added without your permission. Any unrecognized changes should be corrected immediately.

  Vlookup in Excel: Common Errors and How to Fix Them

4. Perform a thorough scan of your computer for malware

Many cyberattacks don't just steal passwords; they often leave hidden "gifts" on your devices. That's why it's essential to run a thorough scan with a trusted antivirus or antimalware program as soon as possible.

Ideally, you should use well-known and highly rated solutions and perform a full system scan , not just a quick one. Some tools are specialized in detecting Trojans, keyloggers (programs that record what you type), or spyware that monitors your activity.

If you continue to see unusual behavior after cleaning your device, you might consider formatting it and reinstalling the operating system . It's a drastic measure, but very effective when you're unsure whether you've completely eliminated the threat.

5. Inform your bank, employer, and, if applicable, the authorities

When the incident affects sensitive data, especially financial or professional data, simply changing passwords is not enough; it is necessary to notify the entities involved of the hack in order to contain the potential damage.

If there are any indications that your bank accounts, cards, or payment services have been accessed , speak to your bank immediately: review recent transactions, request a temporary block on your cards if necessary, and ask for new passwords or cards if you have any doubts.

If you work with a corporate account or use company equipment, it is essential to notify the IT department or the systems manager so that they can apply the appropriate technical measures: force password changes, monitor access, isolate equipment, etc.

In situations where personal data has been leaked or threats, harassment or blackmail are occurring , it is advisable to report it and ask for help from official cybersecurity channels and, if it is serious, from the security forces.

In Spain, the National Cybersecurity Institute (INCIBE) offers a service called "Your Cybersecurity Help ," which is free, confidential, and aimed at citizens, businesses, professionals, and minors and their families. They are available every day of the year, with extended hours, providing technical, legal, and psychosocial support to anyone who needs it.

Mobile phone hacking: warning signs and how to react

The phone has become the center of our digital lives: email, social media, online banking, 2FA authentication, and personal data all converge there . That's why, when a cybercriminal manages to gain access to your smartphone, the risk multiplies.

Mobile phone hacking can occur in several ways: from malware installed through fraudulent apps, to unsecured WiFi connections, to physical theft of the device and subsequent brute-force attacks on the PIN or password.

One of the first signs that something is wrong is that the battery starts to last much less time than before for no apparent reason . Many malicious apps consume resources intensively, running background processes that drain the battery.

Another sign is that the phone runs much slower, freezes, crashes, or restarts on its own . If the processor is busy serving the attacker's apps, overall performance worsens and these anomalies appear.

You should also be suspicious if you see SMS messages or calls in your call log that you didn't make . Some SMS Trojans use your number to send premium-rate messages or impersonate you to your contacts. Similarly, check your online accounts linked to your mobile phone for login attempts from unknown sources.

How to remove a hacker from your smartphone

If you suspect your phone has been compromised, the first step is to install a good mobile antivirus and run a full scan . For Android, there are specific solutions that, in addition to removing malware, allow you to block access to certain apps with additional passwords.

Once the malicious software has been removed, it's time to renew the passwords for all your key accounts associated with the phone : personal and professional email, Apple ID or Google account, online banking, social networks and, very importantly, the phone's unlock code.

Don't forget to check your shopping services and apps that store your card information (online stores, transportation services, subscriptions, etc.). For a few weeks, it's advisable to closely monitor your bank transactions to detect any unfamiliar charges.

How to recover a hacked account step by step

When the problem centers on a specific account (email, social network, online service), the goal is to regain access as soon as possible and limit what the attacker may have done with it.

1. Change your password if you can still log in

If you still have normal access, don't ignore it: change your password immediately and enable two-step verification . This way, even if the cybercriminal has your old password, it won't work for them to log in.

2. Use the recovery email to undo changes

If you can no longer log in because your password has been changed, check the inbox of the email associated with that account and look for messages notifying you of a password or data change . In many cases, these emails include a link to revert the change if it wasn't you who made it.

  Customized DDoS attack mitigation with programmable flow protection

Don't forget to check folders like spam, promotions, or deleted items , as these notifications may have been moved there. If you manage to revert the change, log in to your account and replace it with a new, strong, and unique password.

3. Use the platform's recovery forms

When none of the above works, you'll have to use the service's own help and recovery options . Almost all major platforms offer a system to verify your identity and restore control to you.

You'll usually have to provide information only you know : old emails sent, frequent contacts, approximate account creation dates, backup codes, identity documents, etc. It's a tedious process, but it's the only way if the attacker has changed the recovery email and associated phone number.

4. Evaluate the scope and other associated risks

Once you've recovered your account or confirmed the theft, it's time to analyze what additional risks stem from the hack . The most urgent question is whether you've reused that password on other services; if so, you'll need to change them there as well because it's very likely they've been compromised.

It's also worth considering whether the email address linked to that account might have been compromised . If you didn't receive the typical password change notifications, the attacker may have also accessed your email and deleted them. In that case, securing it should be your top priority.

Don't forget to warn your contacts about what happened, especially if it involved social media, messaging apps, or email . It's quite common for cybercriminals to try to trick your friends, family, or clients by impersonating you to send malicious links, ask for money, or request personal information.

5. Seek specialized help if the situation is serious

If you are unable to recover your account, if you are experiencing harassment, extortion, cyberbullying, or the dissemination of sensitive content , or if the impact is very serious, it is advisable to seek professional help services.

In Spain, you can contact INCIBE's Cybersecurity Helpline , where a multidisciplinary team will advise you on how to proceed, what evidence to save, what legal options are available, and how to protect minors or vulnerable individuals involved. In the most extreme cases, it will also be important to report the incident to the National Police or the Civil Guard.

Consequences of a hack: economic, legal and reputational

A hack isn't just a technological scare; it can impact your finances, your reputation, and, in the case of businesses, your legal liability . Both individuals and organizations can suffer serious consequences if they don't handle these incidents properly.

On a personal level, the most obvious danger is financial fraud through your card or bank accounts , but there are also risks such as identity theft, access to intimate photos or documents, or the publication of private information that could harm you in your work or family life.

When an attack affects a company, things get even more complicated. A cyberattack can compromise the information of customers, employees, and suppliers , as well as paralyze essential services, severely damage brand reputation, and cause significant financial losses.

In Europe, and therefore in Spain, companies are legally obligated to adequately protect the personal information they handle . If it is proven that they have not implemented the necessary security measures, they may face significant penalties from the supervisory authority.

The Spanish Data Protection Agency (AEPD) has imposed fines of several million euros on companies for serious security breaches that exposed sensitive user data. In addition to the administrative fine, those affected can claim compensation through civil proceedings if they can prove they have suffered harm due to poor security management.

If you are a user affected by a company's data breach, you have the right to be informed of what data has been compromised , to request explanations about the measures taken and, in case of economic or personal damage, to file a claim directly with the company or with the Spanish Data Protection Agency (AEPD) with the support of a specialized lawyer.

Prevention: how to avoid being hacked again

Beyond simply reacting to an incident, what's truly effective is minimizing the chances of your accounts or devices being compromised again . Prevention relies on good daily practices and certain tools that should be properly configured.

A basic first rule is to never click on suspicious links or download files from dubious sources . Many attacks begin with a simple phishing email that impersonates a bank, social network, or well-known platform; always be wary of urgent messages that ask for personal information or passwords.

It's also crucial to keep your operating system and all applications up to date . Updates aren't just cosmetic improvements; they include security patches that fix vulnerabilities hackers are already aware of and actively exploiting.

Regularly check which apps, extensions, and third-party services have access to your accounts (for example, apps connected to your Google, Facebook, or Microsoft accounts). Revoke permissions for anything you don't use or recognize, and avoid installing apps from dubious sources or outside of official app stores.

Another good practice is to use a reliable password manager to generate and store unique passwords , instead of saving them in your browser or phone notes. This reduces the risk that if one password is leaked, the rest of your accounts will be compromised as well.

  VPNs and websites without HTTPS: how far does your protection extend?

Specific best practices to protect your mobile phone

On phones, it is especially important not to make unauthorized system modifications (such as certain forms of "root" or "jailbreak") that leave you without security patches and force you to use much more dangerous unofficial app stores.

Whenever possible, keep your phone with you and avoid leaving it unattended . Physical access remains one of the easiest ways to compromise a device: a theft or a moment of inattention can be enough to install malware or copy data.

Protect access to your device with a strong PIN or password and, if possible, with biometrics (fingerprint, facial recognition). Avoid trivial codes like 0000, 1234, obvious dates, or overly simple patterns, and if your device allows it, use longer passwords.

It's not a good idea to store lists of passwords or highly sensitive data directly on your device in plain text. It's preferable to use applications designed to manage credentials in encrypted form , reducing the impact in case of loss or theft of the device.

Regularly clearing your browsing history, cookies, and cache can help , especially if you share your device or use it in untrusted environments. Clearing this data reduces the amount of information that could be used to profile you or for targeted attacks.

More layers of security: tracking, 2FA, and VPN

Whenever possible, activate a service that locates and remotely wipes lost devices . Both Android and iOS include options to locate your phone on a map, make it ring, remotely lock it, or erase its contents if you've given it up for lost.

Two-factor authentication is another key tool: adding a second verification step (codes per app, physical keys, biometrics) makes it much harder for the attacker to break in, even if your password is stolen.

However, caution is advised when using SMS or email verification , as some attacks, such as SIM swapping or email compromise, can intercept these codes. Whenever possible, opt for authentication apps or physical security keys.

On public or untrusted Wi-Fi networks, the wisest course of action is to avoid accessing sensitive services without a VPN . A virtual private network encrypts your traffic, making it difficult for other users on the same network to spy on your data, steal session cookies, or intercept credentials.

On public or unreliable WiFi networks, the wisest course of action is to avoid accessing sensitive services without a VPN.

What support and training can you look for after a hack

After an incident like this, in addition to recovering your accounts, it can be a good time to improve your personal cybersecurity skills . Understanding how attacks work, what techniques cybercriminals use, and what habits reduce risk will allow you to browse more safely.

There are courses, workshops and training resources aimed at citizens, professionals and companies that teach, in a practical way, how to identify signs of hacking, react quickly and securely configure devices and platforms.

For organizations, having cybersecurity experts who audit systems , assess damage after incidents, implement preventative measures, and provide legal advice in the event of data breaches can be the difference between a controlled scare and a major crisis.

From the end user's perspective, learning about official support channels such as national cybersecurity services , their opening hours, contact methods, and the types of inquiries they handle, is a very valuable investment of time in preparation for future incidents.

Ultimately, being hacked is an unpleasant experience, but it can also serve as a turning point to take the protection of your digital identity seriously, review security habits, and strengthen your technical and legal defenses , minimizing the chances of a similar attack catching you by surprise again.

Basic online security
Related articles:
Basic online safety guide for safe browsing