Sun, Jul 12, 2026NY 8:00 PM EDTLA 5:00 PM PDTLON 1:00 AM GMT+1PAR 2:00 AM GMT+2DXB 4:00 AM GMT+4SIN 8:00 AM GMT+8TOK 9:00 AM GMT+9SYD 10:00 AM GMT+10UTC 12:00 AM UTCPayment alerts updated guide pathsScam watch official links firstConsumer alertsSupport-scam watchMoney help deskHow-to guides
Strangely Useful

Payment problems, online safety, browser privacy, AI tools, and everyday tech choices.

Browse the site
Topic hubsFake support guideWrong Cash App paymentLatest storiesTopicsPayment helpSearch
All sections
Internet & CultureTech & AISecurity & TrustPractical TechnologyMoney & PaymentsBrowser & PrivacyAI ToolsSoftware & ServicesInternet Culture & Everyday WorkflowsHidden HistoryUseful ThingsEntertainmentQuizzesAboutHow we workHow guides are madeFollow by RSS
Security & Trust - story

Build an Account Recovery Plan Before a Lockout

Make a short recovery record now, use only official provider routes, and know what to inspect after access returns.

By Strangely Useful EditorsReviewed by the Strangely Useful Security & Trust deskPublished July 11, 2026Updated August 20, 20265 sources6 min read
Quick answer

Make a safe recovery record, choose the correct provider route, and remove hidden access after a hacked or locked account is recovered.

An account recovery plan beside a phone, backup security key, session review cards and a contact notification signal.
A recovery plan records the official route, backup factors and checks to make after access returns. Strangely Useful generated editorial illustration.
In this story5 sectionsMake the plan in 10 minutesIf something happens, choose your branchUse the provider's own recovery routeAfter access returns, remove the ways back inKeep the plan usable

An account-recovery plan is a short record you make while you can still sign in. It tells you where to start, which backup factors you control, and what to inspect after access returns. It should reduce decisions during a stressful lockout without becoming a file full of passwords or one-time codes.

If an email account is being used to reset other accounts right now, move to the first-hour email takeover checklist. This guide is for building the broader plan and choosing the correct provider route.

Make the plan in 10 minutes

  1. Start with accounts that can reset other accounts. Include your primary email, mobile carrier, password manager, domain registrar, and any account that stores payment or identity information.
  2. Save the official recovery page. Type the provider's domain yourself or reach it from the provider's app or help center. Do not make a search ad, pop-up, phone number, or alarming message your recovery route.
  3. Record the recovery contacts you recognize. Note only enough to identify the recovery email address or phone number. Confirm that you can still access it.
  4. List backup factors without copying their secrets. Record that a recovery code set, security key, passkey, or authenticator exists and where it is protected. Do not paste codes into this plan.
  5. Name the dependency. Write down what the account can reset, bill, publish, or administer. That tells you which account to contain first if several are affected.
A safe recovery-plan record
RecordKeepDo not keep here
Official routeThe provider's typed or bookmarked help URLA support number copied from search results
Recovery contactA masked hint you recognize and can accessA mailbox password or verification code
Backup factorIts type and protected storage locationThe recovery code, key PIN, or authenticator seed
Account dependencyWhat this account can reset or controlFinancial account numbers or identity documents

If something happens, choose your branch

  • You can still sign in: stay inside the official app or typed provider site. Follow the provider's security workflow, change the password from a trusted device, remove unfamiliar sessions or devices, repair recovery information, and inspect connected access.
  • You are locked out: use the provider's official recovery flow. When the provider recommends it, use a familiar device, browser, and location. Do not pay someone who claims they can bypass the provider's recovery checks.
  • The device may be infected: follow the provider's device-cleanup guidance or use a different trusted device before changing credentials. Microsoft specifically tells people recovering a compromised Microsoft account to scan the PC before changing the password.
  • Money or identity information may be exposed: preserve transaction and notification evidence, then contact the financial institution through its own app, card, or statement. Account recovery does not reverse an unauthorized payment by itself.

Use the provider's own recovery route

Official starting points checked August 20, 2026
ProviderOfficial starting pointImportant difference
GoogleSecure a hacked or compromised Google AccountBranches immediately on whether you can sign in, then checks security events, devices, recovery details, apps, and product-specific changes such as Gmail forwarding rules.
MicrosoftRecover a hacked or compromised Microsoft accountStarts with its sign-in helper and says to scan a possibly infected PC before changing the password; Outlook users should inspect forwarding, connected accounts, and automatic replies.
AppleIf you think your Apple Account has been compromisedDirects locked-out users to iforgot.apple.com and tells recovered users to verify account details, devices, email addresses, phone numbers, and the Apple Accounts signed in across services.
Facebookfacebook.com/hackedAsks you to start on a device you have used for Facebook before.

For another provider, begin at the provider's app or typed domain and find its account-security or recovery page. The FTC maintains a broader list of official recovery instructions for popular email and social services. If a result offers a phone number before it proves the provider's domain, use the real-support checklist before making contact.

After access returns, remove the ways back in

A password change is one containment step, not proof that the account is clean. The FTC tells recovered users to sign out other devices, turn on two-factor authentication, verify recovery information, inspect email forwarding, review sent and deleted messages, and warn contacts. Provider pages add service-specific checks.

  1. Review recovery information first. Remove email addresses, phone numbers, or authentication methods you do not recognize.
  2. Review sessions and devices. Sign out unfamiliar devices or all other sessions when the provider offers that option.
  3. Inspect persistent access. Check forwarding rules, filters, delegates, connected apps, app passwords, passkeys, security keys, and third-party sign-ins. The exact list varies by provider.
  4. Check what the intruder did. Review sent, deleted, purchase, sharing, and security activity. Save useful evidence before deleting it; the evidence screenshot guide explains what to capture.
  5. Protect the next account. Change any reused password, review accounts reset through the compromised mailbox, and notify contacts if messages or requests were sent in your name.
  6. Update the plan. Replace obsolete recovery contacts and record any new dependency or official route you discovered.

Keep the plan usable

Store the plan offline or in a protected location that does not depend only on the account it is meant to recover. Review it when you change phone numbers, email addresses, devices, password managers, or authentication methods. A twice-yearly check is a practical reminder, but provider changes and personal changes should trigger an earlier review.

Work or school accounts may use an administrator-controlled process, so record the internal help route before an incident. If the provider says recovery is not possible, preserve the old account name and tell contacts which new account is legitimate. Never turn a failed automated recovery attempt into permission for an unknown paid recovery service to handle your codes or identity documents.

Sources used5 sources checked for this guide
  1. How To Recover Your Hacked Email or Social Media AccountFederal Trade Commissiongovernment-guidance - Retrieved Aug 20, 2026 - record checked

    Used forThe FTC directs people who regain a hacked email or social account to change the password, sign out other devices, enable two-factor authentication, verify recovery information, inspect forwarding and message activity, and notify contacts.

  2. Secure a hacked or compromised Google AccountGoogle Account Helpofficial-support - Retrieved Aug 20, 2026 - record checked

    Used forGoogle separates locked-out recovery from post-access security review and directs users to inspect recent security events, devices, recovery details, connected apps, and product-specific settings.

  3. How to recover a hacked or compromised Microsoft accountMicrosoft Supportofficial-support - Retrieved Aug 20, 2026 - record checked

    Used forMicrosoft tells people recovering a compromised Microsoft account to scan a potentially infected PC before changing the password and to review connected accounts, forwarding, and automatic replies.

  4. If you think your Apple Account has been compromisedApple Supportofficial-support - Retrieved Aug 20, 2026 - record checked

    Used forApple directs people who cannot reset or sign in to start account recovery at iforgot.apple.com, then verify account information, devices, contact channels, and signed-in services after regaining control.

  5. Recover a hacked Facebook accountFacebook Help Centerofficial-support - Retrieved Aug 20, 2026 - record checked

    Used forFacebook directs people with a hacked account to facebook.com/hacked on a device they have used to sign in before.

Guide feedback

Was this guide useful?

No personal details are collected here. Use corrections for factual issues.