First hour after a suspicious sign-in alert: contain and secure access
For customers who received a suspicious sign-in alert and need to act fast without deep technical knowledge. This guide walks you through the first hour: confirm the alert, lock down access, revoke active sessions, rotate the most important passwords, and verify that only you can sign in again.
TL;DR — If you got a suspicious sign-in alert, treat it as real until you prove otherwise. In the first hour, sign in from a trusted device, change the account password, sign out all other sessions, turn on multi-factor authentication (MFA, a second proof like an app code), and check for forwarding rules or new admin users the attacker may have added. Reading time: ~5 min
Goal
By the end of this guide, your account will have a new strong password, all unknown sessions will be signed out, MFA will be enabled, any obvious attacker persistence (like mail forwarding or extra admins) will be removed, and you will have a short record of what happened for follow-up.
Prerequisites
- Your account login for the affected service
- Access to your email inbox for password resets and security notices
- Your phone for MFA setup with an authenticator app (for example Google Authenticator, Microsoft Authenticator, or 1Password)
- A trusted device and network you control (your own laptop/phone on your normal home or office connection)
- If this is a work account: access to your company admin portal, or the contact for whoever has admin access
- A password manager if you use one
- 10 minutes with no interruptions so you can finish the lockout steps in one pass
Steps
Step 1: Confirm the alert details from a trusted device
Open the security alert email or app notification on a device you trust. Then go to the provider's security page in your browser. In your provider's dashboard, look for a path similar to:
Account avatar → Account settings → Security
Then open the sections commonly named:
Security → Recent activity
Security → Devices
Security → Sign-in history
What you should see when this succeeds: a list of recent sign-ins with time, device, browser, and approximate location; you can identify whether the alert matches your own activity.
Step 2: If the sign-in was not you, change the password immediately
In the same security area, open the password screen. The path is usually:
Account settings → Security → Password → Change password
Set a new password with these literal rules:
Length: 16+ characters
Type: randomly generated in your password manager
Reuse: do not reuse any previous password
If you do not use a password manager, use a generated passphrase from the provider's built-in generator if offered.
What you should see when this succeeds: a confirmation message such as "Password changed" or "Your password was updated," and your old password no longer works.
Step 3: Sign out all other sessions and remove unknown devices
In the security area, open active sessions or devices. The path is commonly:
Account settings → Security → Your devices
Account settings → Security → Sessions
Use the literal action labeled one of these:
Sign out all other sessions
Revoke all sessions
Remove device
Sign out
If there is no bulk option, remove every device you do not recognize one by one.
What you should see when this succeeds: only your current device remains signed in, or the session list is empty until you sign in again.
Step 4: Turn on MFA and save backup codes
In the security area, open MFA or two-step verification. The path is usually:
Account settings → Security → Two-factor authentication
Choose this option first if available:
Authenticator app
Then scan the QR code with your authenticator app and enter the 6-digit code shown in the app. After MFA is enabled, open the backup codes screen and save them.
Account settings → Security → Two-factor authentication → Backup codes → Generate
Store the backup codes in your password manager.
What you should see when this succeeds: MFA status shows "On" or "Enabled," and you have a saved list of backup codes.
Step 5: Check for attacker changes inside the account
Attackers often add a way back in after the first sign-in. Check these exact areas if they exist in your service:
Account settings → Security → Recovery email
Account settings → Security → Recovery phone
Account settings → Security → Connected apps
Account settings → Users or Team → Members
For email accounts, also check:
Settings → Mail → Forwarding
Settings → Mail → Rules or Filters
Remove anything you do not recognize:
Unknown recovery email → Remove
Unknown phone number → Remove
Unknown connected app → Revoke access
Unknown team member/admin → Remove or suspend
Unknown forwarding address → Delete
Unknown mail rule/filter → Delete
What you should see when this succeeds: only your own recovery methods, known apps, expected users, and expected mail rules remain.
⚠️ If this is a work admin account or the account controls billing, domains, production systems, or customer data, stop using only self-service steps after this point and notify your internal owner or incident contact immediately. Admin accounts can affect other users and systems.
Step 6: Reset passwords for other accounts that reused the same password
If the old password was reused anywhere else, change those next. Start with these account types in this order:
Email
Password manager
Work identity provider
Banking or payments
Cloud hosting
Domain registrar
Use the same menu path pattern in each service:
Account settings → Security → Password → Change password
What you should see when this succeeds: each service confirms the password change and prompts for sign-in again on other devices.
Step 7: Save a short incident note
Create a note in your ticket system, notes app, or document with these exact fields:
Date and time of alert:
Service affected:
Was the sign-in yours? Yes/No
Approximate location/device shown in alert:
Password changed: Yes/No and time
All sessions revoked: Yes/No and time
MFA enabled: Yes/No and time
Unknown recovery methods/apps/rules removed: Yes/No
Need provider support or internal escalation: Yes/No
What you should see when this succeeds: you have a complete one-screen summary ready if you need support, compliance, or internal follow-up.
Verify it works
Run these checks end to end:
- Sign out of the account on your current device.
- Sign in again with the new password.
- Complete the MFA prompt with your authenticator app.
- Return to the security page and review recent activity and devices.
Use these menu paths:
Account settings → Security → Recent activity
Account settings → Security → Your devices
Expected result:
- The new password works.
- MFA is required at sign-in.
- No unknown devices or sessions remain.
- No unknown recovery email, phone, connected app, forwarding rule, or extra admin remains.
- You receive either no new suspicious alerts or only alerts for your current sign-in.
Common pitfalls
You changed the password but did not revoke existing sessions
Mistake: only updating the password and leaving active sessions alive.
Symptom: the attacker may stay signed in even after the password change.
One-line fix: go to Account settings → Security → Sessions and click Sign out all other sessions.
You enabled SMS MFA when an authenticator app was available
Mistake: choosing text-message codes first.
Symptom: weaker protection if your phone number is ported or intercepted.
One-line fix: go to Account settings → Security → Two-factor authentication and switch the primary method to Authenticator app.
You ignored mail forwarding rules and filters
Mistake: securing the password but not checking inbox rules.
Symptom: copies of your email still go to an unknown address, or important security mail is hidden.
One-line fix: open Settings → Mail → Forwarding and Settings → Mail → Rules or Filters and delete anything you did not create.
You only checked the suspicious account, not reused passwords elsewhere
Mistake: leaving the same old password active on other services.
Symptom: more alerts appear on email, hosting, or billing accounts later the same day.
One-line fix: change reused passwords starting with Email, Password manager, Cloud hosting, and Domain registrar.
You stayed on an untrusted device while fixing the account
Mistake: doing recovery on a shared, public, or possibly infected device.
Symptom: password changes do not help because the device keeps exposing the new credentials.
One-line fix: move to your own laptop or phone on your own network, then repeat the password change and session revocation.
You did not escalate a compromised admin account
Mistake: treating an admin or billing account like a normal personal account.
Symptom: other users, systems, invoices, or domains may be changed even after your own sign-in is fixed.
One-line fix: notify your internal owner or incident contact immediately after the first containment steps and review admin logs together.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI