Most accounts are not “hacked” in the Hollywood sense. They are simply opened with the correct password — one that was reused across sites, guessed from public information, or bought from a breach dump for pennies.
That is good news: a handful of disciplined habits eliminates the vast majority of account takeover risk.
Key takeaways
- Secure your email first — it is the master key that resets everything else.
- Unique passwords + MFA remove you from the pool of easy targets.
- Reset alerts and MFA prompts you didn’t trigger are reconnaissance — not noise.
Start with the accounts that unlock everything else
Whoever controls your primary email can reset almost every other password you own. Secure it first, then your password manager, then banking, then cloud storage, then social media.

The checklist
- Unique passwords everywhere, via a password manager — one breached site should never unlock another.
- MFA on every account that offers it. Prefer authenticator apps or hardware keys; SMS only as a last resort.
- Audit recovery options: old phone numbers and forgotten recovery emails are backdoors.
- Review connected apps & sessions — revoke what you don’t recognize.
- Check exposure with Have I Been Pwned; rotate breached passwords first.
Recognize a takeover in progress
Unexpected password-reset emails. MFA prompts you didn’t trigger. “New sign-in” alerts from unfamiliar places. These are probes — someone already has your password and is testing the second lock.
Never approve a prompt you did not initiate, and never enter credentials through a link in a message. Open the site directly instead.
One breached site should never unlock another.
If an account is compromised
- Change the password immediately from a trusted device — and everywhere it was reused.
- Revoke all sessions and third-party access, re-enable MFA.
- Check mail forwarding rules — attackers plant persistence there.
- Warn contacts if the account may have been used to phish them.
Altrixys provides authorized penetration testing, security hardening and compliance services from Athens, Greece. Want to know how your organization would hold up against a real attack? Request a free assessment.