A hacked account triggers the same panic almost every time: a friend gets a strange message in your name, or you suddenly can't log in even though you never changed anything. The useful reaction isn't to reset everything at random, it's to follow a specific order, starting with whatever limits the damage right away. I deal with compromised email, Facebook and banking accounts regularly for clients in Paris, and the mistake that comes up most often is the same one: the victim changes the password from the device that's already infected, thinking the problem is solved.

The first-hour checklist
The first thirty minutes matter more than anything that follows. If the attacker still has an active session, every extra minute gives them time to dig further: contacts, photos, bank details sitting in some old email. Four steps, in this order.
Change the password from a device you know is clean, not the one where you first noticed the problem. If the computer itself looks compromised — unusual slowdowns, alerts popping up on their own — use your phone or a friend's computer instead. Typing a new password on an already-infected machine hands it straight to the attacker: a keylogger or an active remote-access tool captures the input live.
Next, revoke every active session. Every major service — Google, Microsoft, Facebook, Instagram — has a "connected devices" screen listing every place the account is open, usually with an approximate city. A "sign out everywhere" button closes the attacker's access instantly.
Then check that the recovery email and phone number tied to the account are actually yours. This is the step people forget most often, and it's exactly the one attackers change first to lock the real owner out. If an unfamiliar email or phone number shows up, fix that before worrying about anything else: as long as it's there, the attacker can request a new reset at any time, even after the password is changed.
Finally, turn on two-factor authentication if it wasn't already on, using an authenticator app rather than SMS whenever possible — SMS codes remain vulnerable to fraudulent SIM swaps. Once it's on, a stolen password alone is no longer enough to get back in.
Checking whether your credentials leaked elsewhere
A changed password says nothing about how the account was breached in the first place. It's often traced back to an old data breach on some service you'd forgotten about — a forum, an app you stopped using years ago — whose reused credentials eventually end up circulating in leaked databases. Have I Been Pwned, a free tool, lets you enter an email address and see which known breaches it appeared in, in about thirty seconds: if the hacked password was reused across five other accounts, changing just one fixes nothing.

Dark-web monitoring tools, built into some antivirus suites or password managers, go a step further: they continuously compare your saved credentials against known breach databases and alert you on a new match. A password manager that generates a unique password per account limits the damage of any future leak, since a password stolen from one site no longer unlocks anything else.
Email: the master key
If you can only secure one account first, make it your primary email. Almost every other account — banking, social media, online shops, even government portals — uses that address to reset a forgotten password. An attacker who controls the mailbox can work their way back into everything else, one account at a time. That's why I always start there with a client, before even looking at whatever triggered the alert.
Check the mail settings for any auto-forwarding rule you didn't set up — a quiet attacker will often add a silent forward of every incoming email to another address, letting them keep reading your mail even after you've apparently taken the account back. Check the signature and auto-reply text too; both are sometimes edited to point your contacts toward a fraudulent link.
Bank accounts and government logins: what changes in France
If the hacked account is a bank account, or a card number or IBAN was sitting somewhere in the compromised account — a statement attached to an email, for instance — call your bank directly, using the number on the back of your card, never a number received by text as part of the incident. Ask explicitly for a card block ("faire opposition" in France) if a card may have been exposed: it stops any new payment immediately. The national hotline (0 892 705 705) works outside branch hours too.
For French tax and healthcare portals — impots.gouv.fr and Ameli — a fraudulent login potentially exposes your tax number, declared income, direct-debit bank details, or medical history. Change the password, check the login history, and contact the relevant office if a change to your banking details looks suspicious. Speed matters more than a perfect process: a client near the 17th called me on a Saturday evening after an unfamiliar login alert on her tax account, and we changed the password and reviewed the history in under ten minutes from her phone, before touching the computer that may have been the entry point.
Warning your contacts before they get caught too
An attacker who controls your email or a social account rarely uses it against you directly — they use it to scam the people who trust you: an urgent wire-transfer request, a fake fundraiser link, a "just this once" gift-card ask. Warn your friends, family and business contacts as soon as you can, through a different channel — a call, a text — and be explicit that they should ignore any instruction that appears to come from you until you say otherwise. It's the step that prevents the most collateral damage: a friend who sends €200 because they believed an urgent message "from you" almost never gets that money back.
When the problem is the computer itself
If the hacked password was typed or intercepted on an infected computer, changing it isn't enough — the attacker just grabs the next one the same way. Unplug the network cable or turn off Wi-Fi, then run a full antivirus scan — I cover the full method, quarantine included, in my guide on how to remove a virus from your computer. Until that scan is confirmed clean, any password typed on that machine is still at risk.

Some account hacks start with a fake support call or a full-screen scam alert that talks the victim into installing remote-access software — my article on spotting tech-support scams covers the warning signs to catch earlier. For a small business, one compromised laptop can expose an entire shared inbox — a companion piece on protecting a business against cyberattacks covers the right precautions, and most of the work happens before the incident, with current backups, which I cover in my guide to backing up important data.
Paris pricing
A remote check to gauge how far a hack has spread — active sessions, forwarding rules, login history — usually runs €39 to €59, wrapped up in under an hour by phone or video call. If a full antivirus scan is needed, expect closer to €69 to €89. For a broader clean-up — securing several accounts, a password manager, two-factor authentication everywhere — I charge €89 to €149 depending on how many accounts are involved. For a home visit within central Paris, the call-out is included in the quoted price; for a trickier case, an IT troubleshooting visit is usually possible the same day. Businesses on a small business IT maintenance plan get priority review whenever an alert comes in.
Frequently asked questions
Should I file a police report if my account was hacked?
Not required for a simple password change with no real consequence, but worth doing once money was lost, your identity was used to scam people you know, or sensitive data was exposed. cybermalveillance.gouv.fr points you to the right process, and a bank or insurer often requires a report for a refund.
Can the hacker still read my email after I've changed the password?
Yes, if a session is still open elsewhere or an auto-forwarding rule was added. Changing the password isn't enough on its own: you also need to revoke every active session and check that no silent forward is sending copies of your email elsewhere.
How do I know if my passwords leaked on the dark web?
Have I Been Pwned checks an email address against known data breaches for free in about thirty seconds. Dark-web monitoring tools built into some antivirus suites or password managers go further, comparing your credentials continuously.
How long does it take to secure a hacked account?
The first-hour checklist — new password, revoked sessions, checked recovery details, two-factor authentication — takes fifteen to twenty minutes once you know where to click. Securing every linked account usually takes an hour or two.