Home AI Threats Free Help Services About IT Support Contact Book Consultation →
Back to Free Help
2–3 days12 steps

What to Do If You've Been Hacked

If you know or strongly suspect your computer has been compromised — by malware, an infostealer, a phishing attack, or any other means — you need to act immediately. Every minute you wait is another minute the attacker has access to your data. Don't panic, but don't wait. Follow these steps in order.

1

Disconnect from the internet immediately

Unplug the Ethernet cable and turn off Wi-Fi. Do this right now, before anything else. This instantly stops the malware from sending more stolen data to the attacker and prevents remote control of your machine. Leave the computer powered on but disconnected.

Do not try to "find" the malware first. Do not run an antivirus scan while still connected. Disconnect first, investigate second.
2

Stop all logins on the infected device

Do not log into any account — email, banking, social media, school, or work — on this computer. The malware may include a keylogger recording every keystroke. Assume that everything stored in your browser — saved passwords, autofill data, cookies — has already been compromised. From this point, use only a separate, known-clean device.

3

Back up only plain personal data files

Plug in an external USB drive and copy only irreplaceable personal files: photos (.jpg, .png), documents (.docx, .pdf), videos (.mp4). Do not copy executable files (.exe, .scr, .bat, .msi), unknown .zip/.rar archives, browser profile folders, or the AppData directory. Malware hides inside these and will reinfect a clean system.

4

Mass password reset from a clean device

Move to a separate clean device — an uninfected phone, tablet, or trusted friend's laptop. Change passwords in this exact priority order: 1) Primary email (the master key), 2) Backup/recovery emails, 3) Financial accounts (bank, PayPal, Venmo, crypto), 4) Social media, 5) Gaming platforms, 6) Everything else. Every new password must be unique, at least 16 characters, generated by your password manager.

5

Enable or rotate 2FA on all accounts

While resetting each password, enable multi-factor authentication using an authenticator app (not SMS). If 2FA was already on, disable and re-enable it — this rotates the secret key and invalidates any recovery codes the attacker stole. Print or write down your new recovery codes physically.

6

Nuke all active sessions on every account

In each account's security settings, find "Active Sessions" or "Sign Out of All Devices" and use it. This forcibly disconnects any session the attacker is using. They may have stolen a session token that keeps them logged in even after you change your password. Killing all sessions forces re-authentication.

7

Audit recovery emails & phone numbers

Check recovery settings on every critical account. Verify the recovery email and phone number are actually yours. Attackers sometimes change these to lock you out permanently later. If anything looks unfamiliar, remove it and set your own.

8

Delete hidden email forwarding rules

Log into your email on the clean device. Go to Settings → Forwarding / Filters / Rules. Look for any rules you didn't create. Attackers create hidden rules that silently forward your bank reset emails, shipping confirmations, and other sensitive messages to their own inbox. Delete anything you don't recognize.

This is one of the most commonly missed steps. Even after a password change and 2FA, a hidden forwarding rule continues silently leaking your emails to the attacker.
9

Revoke unfamiliar third-party app access

In each major account (Google, Microsoft, Facebook, Discord), go to security settings and look for "Connected Apps," "Third-Party Access," or "OAuth Permissions." Remove anything you don't recognize. Attackers use stolen credentials to authorize their own apps, which maintain access even after a password change.

10

Wipe & clean reinstall your operating system

Do not trust antivirus to "clean" an active infostealer — sophisticated malware deep-roots itself beyond what scanners detect. On your clean device, go to your OS manufacturer's official site (microsoft.com or apple.com) and download the media creation tool. Create a bootable USB installer. Boot the infected machine from USB and delete every existing partition until it shows only "Unallocated Space." Install fresh. Run all system updates immediately. Download apps only from official sources. Do not import old browser profile data — start completely fresh.

11

Freeze credit at all 4 bureaus

If financial data, tax documents, or SSNs lived on the compromised computer, treat this as potential identity theft. Place a security freeze at: Equifax (equifax.com/personal/credit-report-services), Experian (experian.com/freeze), TransUnion (transunion.com/credit-freeze), and Innovis (innovis.com/personal/securityFreeze). Enable instant transaction alerts on all bank accounts and credit cards.

12

File an identity theft report if needed

If you suspect your personal data is being actively misused, go to IdentityTheft.gov — the FTC's official identity theft portal. File a report and follow the step-by-step recovery plan they generate. This creates a legal record for disputing fraudulent accounts and working with creditors. Bookmark cisa.gov for ongoing security alerts.

Dealing with an active compromise right now?

If you're in the middle of a hack and feeling overwhelmed, we can walk you through every step in real time. We'll help you prioritize what to lock down first, verify your accounts are clean, and catch the hidden things most people miss — like email forwarding rules and OAuth tokens.

Contact Us Now