Your account
was hacked.
The order you do things in matters. Secure your email first — it is the master key to every other account you own. Then work outward. Here is the sequence.
In this order
Do not skip ahead. The sequence is what makes it work.
1 · Secure your email first
Change the password, from a device you trust. Everything else depends on this and nothing else matters until it is done.
2 · Sign out everywhere
Changing a password does not always end existing sessions. Find “sign out of all devices” in security settings and use it.
3 · Turn on two-factor
On email first, then everywhere else. An authenticator app beats SMS.
4 · Check recovery settings
Attackers add their own recovery email or phone so they can return later. Remove anything you do not recognise.
5 · Check mail forwarding rules
A quietly added forwarding rule copies your mail to them indefinitely. Frequently missed, and it undoes everything else.
6 · Then the other accounts
Banking, then anything with saved payment details, then social. Unique passwords on each.
Stopping it happening again
The clean-up matters as much as the recovery.
Find the entry point
Reused password, phishing email, or malware on the device. Without knowing which, it tends to recur.
Check the device itself
If a keylogger is running, new passwords are compromised the moment you type them. Worth ruling out before you trust the machine.
Stop reusing passwords
One breach elsewhere becomes a breach everywhere. A password manager solves this permanently.
Watch for follow-up scams
Compromised accounts get sold. Expect targeted phishing referencing real details for a while afterwards.
Quick answers
Which account should I secure first?
Email, always. Password resets for nearly every other account you own get sent there, so whoever controls your email can take everything else regardless of how strong those passwords are.
Should I change every password immediately?
Secure email first, then work outward by importance: banking, then anything storing payment details, then social media. Changing other passwords while your email is still compromised accomplishes nothing.
How do I know if they are still in my account?
Most services show active sessions and recent login locations in security settings. Sign out of all sessions after changing the password — otherwise an existing session can stay logged in.
Will two-factor authentication actually stop this?
It stops the overwhelming majority of account takeovers, because a stolen password alone is no longer enough. An authenticator app is meaningfully stronger than SMS codes, which can be intercepted.