The first 60 minutes after a hack often decide whether you recover quickly or lose access permanently. Attackers move fast — they change your password, then your recovery email, then enable their own 2FA to lock you out for good. This guide gives you the exact actions to take, minute by minute, in the first hour after discovering your account was compromised.
0–5 Minutes: Stop the Bleeding
Do not panic. From a clean device you have not used recently (a different phone or laptop), open the affected platform’s password-reset page and request a reset to your recovery email. If you still have any access, change the password immediately to a long, unique one. Every minute counts here — the goal is to beat the attacker to your recovery settings.
5–15 Minutes: Secure Related Accounts
Most hacks are one link in a chain. If your Facebook is compromised, the attacker will probe your linked email, banking, and other social accounts next. Change passwords, in this order, on: your email account first (it controls all resets), then banking, other social media, payment apps (PayPal, Cash App, Venmo), and your Apple ID or Google account.
15–30 Minutes: Revoke Active Sessions
On each platform, open “Active Sessions” or “Where you’re logged in” (usually under Settings → Security) and log out of every device you do not recognize. This kicks the attacker out even if they still know the password — a step most people forget.
30–45 Minutes: Enable 2FA Everywhere
Turn on two-factor authentication using an authenticator app (Authy, Google Authenticator), not SMS — SMS is vulnerable to SIM-swap. Generate backup codes and save them in a password manager immediately, so a lost device never locks you out again.
45–60 Minutes: Document and Report
Screenshot suspicious emails, messages, and unauthorized posts — you will need them for appeals. File a report through the platform’s hacked-account flow. If money is involved, call your bank’s fraud department, and in the US file an FBI IC3 complaint at ic3.gov. In the EU/UK, notify your bank and data-protection authority.
What NOT to Do
- Do not engage with or negotiate with the hacker.
- Do not pay any ransom demand — payment rarely returns access.
- Do not use a device that may itself be infected.
- Do not reuse the same password across the accounts you are resetting.
When You Are Already Locked Out — How AccRevert Helps
If the attacker already changed your recovery email and phone and enabled their own 2FA, the self-service tools will fail — and that is exactly when professional escalation matters. AccRevert prepares a documented ownership case and works through the platform’s security channels. You start with a flat $299 Legal Prep fee and pay the success-based balance only once your account is back.
Frequently Asked Questions
What should I do in the very first minute after a hack?
From a clean device, request a password reset and change the password if you still can — before the attacker changes your recovery email. Speed is the biggest single factor in recovery.
Why change my email password if only my social account was hacked?
Because your email controls password resets for every other account. If the attacker reaches it, they can cascade into all your services. Secure the email first.
Should I pay if the hacker demands a ransom?
No. Paying rarely restores access and marks you as a willing target. Pursue platform recovery and professional escalation instead.
The hacker changed everything — is it too late?
No. Accounts are recoverable even after email, phone, and 2FA were changed, using ownership evidence and escalation. The sooner you start, the better the odds.
Final Checklist
- Reset the password from a clean device immediately.
- Secure your email first, then banking and other accounts.
- Revoke all unknown sessions and enable authenticator 2FA.
- Document evidence and report to the platform and your bank.
Locked out completely? Submit your case to AccRevert for a fast assessment — pay only on success.









