Symptoms
- Email or text alert about a sign-in from an unknown device or city
- Unfamiliar device listed in your account's active sessions
- Account settings changed that you didn't make
- Emails you didn't send appear in your sent folder
Likely causes
- CommonSomeone obtained your password from a data breachReused passwords are often tested against many sites after a breach elsewhere.
- PossibleYour own device or a VPN triggered the alertUsing a VPN, traveling, or a new device or browser can look 'unfamiliar' to the service even though it's you.
- PossiblePhishing gave away your passwordA fake login page may have captured your credentials recently.
- PossibleAccount genuinely compromisedAn attacker is actively logged into your account.
What to do
- Change the account password immediately from a device you trust, using a strong unique password.
- Review the account's 'active sessions' or 'recent devices' list and sign out of anything unfamiliar.
- Check account recovery settings (backup email, phone number) for changes you didn't make and revert them.
- Turn on two-factor authentication if it isn't already active.
- Check other accounts that share the same password and change those too.
- Run a malware scan on your device in case a keylogger captured the password.
- Review recent account activity, sent messages, and connected apps for anything unauthorized.
When to call a pro
If financial accounts or sensitive personal data were accessed, contact the company's fraud department and consider a credit freeze.
Safety
Generally low risk
Generally low risk for a careful person. Stop if anything looks different from what this guide describes.