Been hacked? Do this, in this order.
Pick the situation closest to yours. The first step is the one that limits the damage; the rest follow in the order that matters. Nothing you select is stored or sent.
The first minutes after an incident decide most of the damage. Choose the situation closest to yours; each plan opens with the one action that cuts off the attacker's access, then works through clean-up, reporting and the lesson for next time. All six plans are on this page.
You clicked a phishing link
What matters is whether you entered anything. If you only clicked, the risk is lower; if you typed a password or card number, treat that account as compromised and move fast.
- Disconnect if a download startedIf a file downloaded or your device is behaving strangely, turn off Wi-Fi and mobile data now to stop anything talking out, then run a full scan with your built-in security tool.
- Change the password you enteredFrom a device you trust, go to the real site through your bookmark and change that password. If you reuse it anywhere, change it there too — that reuse is the real exposure.
- Turn on two-factor sign-inOn that account, so a stolen password alone can no longer get in. Prefer an authenticator app or passkey.
- Check for changes the attacker may have madeLook at your recovery email and phone, any mail-forwarding rules, and recent sign-in activity. Remove anything you did not set.
- Watch payment accountsIf you entered card details, contact your bank, watch for unfamiliar charges, and consider a replacement card.
- Report itForward the message to your email provider’s reporting address and, at work, to whoever handles IT so colleagues can be warned.
- Do not use any link or phone number from the original message to “sort it out”.
- Do not keep using the same password anywhere else.
Your email account is compromised
Email is the master key: password resets for almost everything else land here. Act on it before anything else, because whoever holds it can reach the rest.
- Change the email password nowFrom a device you trust, using a new, long, unique password. If you cannot sign in, use the provider’s account-recovery process.
- Sign out everywhereUse the “sign out all sessions / devices” option in your email security settings to kick the attacker out.
- Turn on two-factor sign-inAn authenticator app or passkey. This is what stops them walking back in with the old password.
- Remove what they addedCheck for mail-forwarding rules, filters that delete or hide messages, added recovery addresses or phone numbers, and connected apps. Delete anything unfamiliar.
- Secure the accounts email can resetBank, social, shopping. Change passwords on anything important that shares this email, starting with money.
- Warn your contactsA hijacked inbox is used to phish the people who trust you. Tell them to ignore recent unusual messages.
- Do not assume changing the password is enough — forwarding rules and app connections survive it.
- Do not reuse the old password anywhere.
Money was taken
Speed matters: some transfers can still be stopped or recalled in the first hours. Contact the bank, then preserve evidence, then report.
- Call your bank immediatelyUse the number on the back of your card or their official site. Ask them to stop or recall the payment and to freeze or watch the account.
- Change online banking accessNew password, and two-factor sign-in if it was not already on. Assume the credentials are known.
- Preserve the evidenceScreenshot the messages, emails, numbers and payment references. Do not delete anything; you will need it for the report.
- Report it to the authoritiesReport to your national fraud or cybercrime reporting service and get a reference number. Your bank will often ask for it.
- Check for wider accessIf the scam involved your email or a remote-access app they asked you to install, secure your email and remove that app.
- Tell someone you trustScammers rely on shame and isolation to keep you paying. Talking to someone breaks the spell and is a step, not a weakness.
- Do not send any further payment, including a “release fee” or “tax” to get your money back — that is the same scam continuing.
- Do not keep the conversation going in the hope of recovering it yourself.
Ransomware has locked your files
Your files are encrypted and there is a demand for payment. Paying is discouraged and never guaranteed. The priority is to contain the spread and recover from backup.
- Isolate the deviceDisconnect it from Wi-Fi, unplug the network cable, and unplug any external or backup drives so the encryption cannot spread to them or to shared folders.
- Do not pay yet, and do not wipe itPaying funds crime and often yields nothing. But do not erase the device either — keep it as-is; a decryption tool may exist or become available.
- Identify and seek a free decryptorNote the ransom-note text and file extensions. Reputable projects (such as the No More Ransom initiative) publish free decryptors for many strains. Check from a clean device.
- Rebuild from a clean backupIf you have an offline or cloud backup made before the infection, wipe the machine, reinstall the system, then restore your files.
- Report itReport to your national cybercrime service. For a business, treat it as an incident and get professional help; there may be reporting obligations.
- Close the way inIt usually arrives via phishing or an unpatched system. Once clean, update everything and review how it got in before reconnecting.
- Do not reconnect the infected device to your network or backups until it is wiped and rebuilt.
- Do not assume paying restores your files — often it does not, and it marks you as willing to pay.
Your device was lost or stolen
The order is: lock and locate it, then protect the accounts signed in on it. A screen lock buys you time; the accounts are the real prize.
- Use find-my-device to lock itFrom another device or a browser, mark it lost. This locks the screen, shows a contact message, and lets you erase it remotely if needed.
- Change your email password firstThen the other important accounts that were signed in on the device. This signs the thief out of the sessions on it.
- Sign out of sessions remotelyIn each major account’s security settings, use “sign out all devices” so saved logins on the lost device stop working.
- Contact your mobile carrierFor a phone, have them suspend the SIM to prevent calls, texts and — importantly — the interception of text-message codes.
- Erase it remotely once you have secured accountsIf it is clearly gone, trigger a remote wipe. Modern devices are encrypted, so a locked device is already hard to get into.
- Report and, if insured, claimReport the theft to the police for the reference number, and to your insurer if relevant.
- Do not arrange to meet whoever “found” it from a tracking ping — involve the police instead.
- Do not delay changing passwords in the hope of recovering it.
Your social account is hijacked
It is posting or messaging as you. Regain control, remove the attacker’s foothold, and warn the people being targeted through your name.
- Recover accessUse the platform’s “forgot password / account recovery” flow. If your email was the way in, secure that first — it comes before the social account.
- Change the password and sign out everywhereA new unique password, then use “log out of all sessions” to remove the attacker.
- Turn on two-factor sign-inAn authenticator app or passkey, so the recovered account cannot be taken again with the old password.
- Remove what they changedCheck the linked email and phone, connected/third-party apps, and any auto-posting tools. Revoke anything you do not recognise.
- Warn your followersPost that you were compromised and to ignore recent messages — especially any asking for money, codes or clicks. Your contacts are the real targets.
- Report the impersonationUse the platform’s reporting tools for any scam posts or messages sent in your name.
- Do not pay anyone promising to “restore” your account — use the platform’s own recovery.
- Do not skip the connected-apps check; that is often how they keep getting back in.
In the first minutes after an incident the attacker still has whatever access they gained, and every minute is a chance for them to add a forwarding rule, reset another account or move money again. Each plan above starts with the action that closes that access, then moves to clean-up, then to the reporting and the lessons. Panic tends to invert that order.
Kasspar is educational material, not incident response for a specific case. For a business, a regulated organisation or a large sum of money, get professional help as well.