Limit harm first
If money, a card or a bank account is at risk, contact your bank immediately through an official number or app. Do not wait for email recovery or an incident report response. For a work account, inform your internal IT or security team and follow their instructions.
Use another trusted device if you suspect the current one is infected or under someone else’s control. Record times, unfamiliar actions and messages. Preserve evidence without delaying account protection; do not forward passwords or codes.
Use the official recovery route
Our service-by-service recovery guide lists official starting addresses and explains the controls.
Open the provider’s known website or app. If you cannot sign in, begin its recovery process. If you search for instructions, check the domain before entering information. Do not rely on someone who messages you promising guaranteed recovery.
Recovery options depend on the service and the evidence available to you. No process can guarantee in advance that access will be restored.
Once you regain access
- Change the password to a new, unique one. Change it on other accounts where you reused it too.
- Review devices and active sign-ins. Follow the provider’s instructions to sign out other sessions and remove unfamiliar connected apps; changing a password may not revoke every form of access.
- Review the phone number, backup email and other recovery details. Remove changes you did not make.
- For email, check filters and automatic forwarding. An unfamiliar rule may send copies of messages to someone else.
- Enable or securely reconfigure 2FA and store any supported backup codes securely.
For devices, recovery codes and forwarding checks, follow your service’s settings. Use official support for services not covered; labels and available options differ.
Check the consequences and warn others
Review connected banking and shopping accounts and monitor new notifications. Through another trusted channel, warn contacts if messages requesting money or information were sent in your name. Update the systems and apps on devices you use.
If you suspect fraud or theft, contact your bank and the relevant police authority. You can report an incident to FIN-CSIRT with a description, timing and relevant evidence. This does not replace provider, bank or internal IT support and does not guarantee recovery of an account or money.
Check your knowledge · 3
of 5
Your turn to choose the next step.
Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.
Questions and explanations are also available without JavaScript.
Without JavaScript, the full bank of 5 questions is shown.
You cannot open your email and notice an unfamiliar bank transaction. What takes priority?
Why does this matter? Losing email access and seeing a suspicious transaction require related but different actions. Recovering email does not itself stop misuse of banking services.
-
Finish all email recovery steps first.
You need to limit financial harm without that delay. While you work through the provider’s process, the bank may still lack the information needed to assess protection for your money.
-
Contact the bank immediately through an official channel, then continue recovery.Correct answer
The bank needs to know about the suspicious transaction promptly. This starts the financial-risk assessment with the institution operating those services, before you continue email recovery.
-
Wait for a FIN-CSIRT report response before contacting the bank.
Reporting to FIN-CSIRT does not replace urgent contact with the bank. A cyber incident team’s response is not a prerequisite for reporting an unauthorised transaction to the bank.
You changed the compromised email password. What else should you review?
Why does this matter? A password is only one route into an account. Existing sessions, connected apps or a mail-forwarding rule can leave other routes to access or read messages.
-
Sessions, connected apps, forwarding rules and recovery details.Correct answer
This checks other ways access may have been retained. Checking each of these places looks for access and settings that changing one password may not have removed.
-
Only the appearance of the home page.
The page’s appearance does not show who still has access. The home page can look entirely unchanged while copies of messages continue to reach someone else.
-
Nothing; a password change guarantees everyone is signed out.
Session behaviour depends on the service; follow its instructions. Check what the particular service revokes rather than assuming that every form of access has automatically ended.
Someone in a message guarantees account recovery if you send a backup code. What should you do?
Why does this matter? Losing an account creates pressure to accept any available help. Someone requesting a backup code may use the very recovery method meant to restore your access.
-
Send it because it is not a normal password.
A backup code is confidential access information. A different name does not make it less sensitive: a backup code can provide entry when the usual confirmation is unavailable.
-
Pay in advance to speed up recovery.
The offer is not evidence that the person can or should recover the account. Payment does not verify the offeror’s authority and may add financial loss to the loss of account access.
-
Do not share the code; use the provider’s official process.Correct answer
The provider defines recovery; do not give a stranger the means to sign in. The official process handles account-ownership checks instead of handing an unknown person a means of signing in.
After recovering the account, you find an unfamiliar mail-forwarding rule. What do you do?
Why does this matter? A forwarding rule can keep sending new messages to an attacker after the password changes.
-
Remove it, review other access settings and preserve details of the change.Correct answer
This closes another access route while retaining information needed for incident assessment.
-
Leave it because the password has already changed.
A password change may not remove an existing forwarding rule.
-
Forward the rule to colleagues so they can see it.
Forwarding may disclose addresses and other sensitive information.
The provider offers several recovery routes. Which should you use?
Why does this matter? Safe recovery should verify ownership without handing codes or access to an unknown person.
-
The official process opened through a known app or manually entered address.Correct answer
A known official channel reduces the risk of a fake recovery page.
-
The first advertised account-recovery service.
An advertisement does not establish authority or control of the account.
-
A link sent by someone claiming to have found the account.
An unknown person may use urgency to take the remaining recovery methods too.
No registration. Your answers are not sent; the result is just for you.