Use a device you trust before entering important credentials. The aim is to check security events, devices, recovery methods, forwarding and connected accounts without turning one unfamiliar event into a definite breach conclusion.
Start here
Choose the path that matches access
If you can still sign in, review and strengthen control points. If you are locked out, use the provider’s official recovery route rather than a search result or message link.
Deal with financial exposure first
If payment information, banking credentials or a transaction may be involved, contact the bank or card provider through an independent official channel. Ask what immediate review or protective action is available. Do not rely on the suspicious message’s contact details and do not delay this step for local technical assistance.
For reporting options, see Cyber.gov.au’s report guidance. Reporting does not itself establish what happened or guarantee a particular investigation or recovery result.
If you can still access the account
Open the provider’s security area directly. For Google, the official account guidance points to Recent security events and Your devices or Manage devices. Review unfamiliar events and devices using the provider’s prompts, but treat an unfamiliar entry as something to investigate rather than conclusive proof of an attack.
Check recovery email addresses and phone numbers, two-step verification or other MFA settings, active sessions, email forwarding, filters and automatic replies. Review connected apps or accounts and remove access only when you understand what it is and can preserve your own control. Sign out sessions where the provider offers that option. Changing a password does not prove that every session has been revoked.
Use a strong, unique password created on the trusted device. Never send the password or verification code to a helper.
If you are locked out
Use the provider’s official account-recovery process or sign-in helper. For Google, follow the account-recovery path described in its official security guidance. For Microsoft, start with the official compromised-account recovery guidance.
Microsoft advises addressing suspected malware before changing a password. If the device or browser may be questionable, use a reasonably clean trusted device for account actions where possible. A scan alone cannot confirm that a device is safe. Get appropriate device support if you are unsure which device to use.
Once access is restored, review recovery details, MFA, forwarding, automatic replies and connected accounts. Record dates, broad changes and provider reference numbers. Confirm that you have a working recovery method you control, then follow the provider’s instructions to remove unauthorised details. If you cannot do this safely, use its account-recovery process.
Check other accounts carefully
Start with accounts that control other services: your primary email, password-reset email, phone or identity provider. Then consider financial, shopping, social and work accounts connected to the affected address. Use each provider’s official security page and its own recovery process.
- Do not reuse a password across accounts.
- Do not copy secrets into your incident notes.
- Do not reopen the suspicious message or link to confirm details.
- Keep a short list of actions still pending and who owns each action.
If a provider presents a security warning, follow its official prompts while recording what you observed separately from what you infer.
What to read next
If you’d rather have local help, see our onsite scam and account-security assessment.
