A compromised account is one that someone else can get into without your permission, usually because your password was stolen in a phishing attack, captured by malware or reused from an old breach. You detect it by looking for activity you didn’t do: sign-in alerts from new devices, password reset emails you never asked for, messages in your sent folder, or settings such as forwarding rules and MFA that changed without you.
Hacked or compromised accounts lead to unauthorized access to personal information and to financial loss. If your password appears on the NCSC’s list of the most hacked passwords, change it today. Its breach analysis found 23.2 million victim accounts worldwide that used 123456.
What does “account compromised” mean?
It means an unauthorized person has, or had, working access to the account. The attacker might be reading your email, sending messages as you, buying things with saved cards, or using the account to reset passwords on other services. A platform warning that your account is “compromised” or “flagged” usually means its systems saw sign-ins or behavior that didn’t match your normal pattern, and it locked the account or forced a password reset to protect you.
Accounts usually get compromised in one of these ways:
- Phishing: you entered your password on a fake login page.
- Password reuse: a password leaked in one breach is tried on your other accounts, a technique called credential stuffing.
- Infostealer malware: malware on your computer copies saved passwords and session cookies.
- SIM swap: the attacker moves your phone number to their SIM and receives your SMS codes.
Infostealers can do damage years later. In 2024, Mandiant investigated a campaign against Snowflake customers in which the attacker logged in with credentials stolen by infostealer malware, some from infections dating back to 2020. The affected accounts didn’t have MFA enabled, and Mandiant and Snowflake notified about 165 potentially exposed organizations, as detailed in Mandiant’s UNC5537 report.
Signs your account has been compromised
Most of these can be checked in your account’s security or activity settings.
Notifications for unusual logins
A sign-in from a new device, location or browser can mean a compromised account. If the details are odd, such as a sign-in while you were asleep or from a country you haven’t visited, assume your password is known and change it at once.
You can’t get into the account
Failed sign-ins and password reset notices suggest an attacker may have changed your password. If you get back in, check whether MFA is still enabled. Attackers often turn it off, or add their own phone or authenticator app, so they can keep access after you reset the password.
Strange emails in your sent folder
Not every attacker locks you out. Some just use the account quietly, to send spam or phishing to your contacts or to learn more about you. Check your sent folder for messages you don’t remember writing.
New forwarding or inbox rules
A rule that forwards your mail to an outside address, or moves messages from your bank or boss into an obscure folder, is a classic sign of a hijacked email account. It lets the attacker read everything while you see nothing unusual.
Complaints from your contacts
When friends, family or colleagues tell you they’re getting odd messages from you, and the reports keep coming, it’s much more likely that your account has been hacked than that someone is merely spoofing your address.
Connected apps you don’t recognize (shadow IT)
Once an intruder is in, they can link third party apps to keep access or extend the attack. A single unknown app with access to your mail or files can expose your whole organization. Review connected apps and remove anything you don’t recognize.
Unexpected password reset emails
Watch for reset emails you didn’t request. An attacker with access to your inbox can use it to find out which banks, shopping sites and other services you use, then try to take those over too. Be wary of calls or emails that seem to come from your bank asking for more details.
How organizations detect compromised accounts
For a security team, compromised account detection means looking for behavior that doesn’t fit the user. The signals worth alerting on:
- Sign-ins from two distant locations too close together for the user to have traveled (“impossible travel”).
- Repeated MFA prompts the user didn’t trigger, which can mean someone already has the password.
- New mailbox forwarding rules, new MFA methods or new OAuth app consents.
- Unusual downloads, mass file access or sign-ins from hosting providers and anonymizing networks.
- Employee credentials appearing in breach dumps, infostealer logs or criminal forums. TIKAJ’s dark web monitoring watches for these so you can reset passwords before they’re used.
What to do if your account is compromised
- Change the password from a device you trust. If you can’t get in, use the account recovery option, and contact customer support as early as you can if that fails.
- Sign out all other sessions, and check the recovery email, phone number and MFA methods. Remove anything that isn’t yours.
- Turn on two factor authentication if it wasn’t already on. Some providers let you require a second “factor”, such as an app code or security key, before access is given to the account.
- Delete unknown forwarding rules and connected apps.
- Scan your computer for malware. Attackers may have got in through spyware or a keylogger, so run an antivirus scan and update your software and apps.
- Change the same password anywhere else you used it, and tell your contacts if the account sent scams in your name.
- For a compromised bank account, call the bank on the number printed on your card and ask them to block transactions and reissue credentials.
You can check whether your email address appears in known breaches on Have I Been Pwned.
How to prevent account compromise
MFA is the biggest single improvement. A study by Microsoft researchers of Azure Active Directory accounts found that MFA reduced the risk of compromise by 99.22% across the whole population, and by 98.56% for accounts whose credentials had leaked, as reported in their 2023 paper. CISA’s MFA guidance explains the options, from authenticator apps to phishing resistant security keys.
After that:
- Use a different password for every account, kept in a password manager. Our post on the importance of strong passwords covers how to choose them.
- Turn on sign-in alerts and other security options your provider offers, such as alerts for new locations and the ability to sign out lost devices remotely.
- Be suspicious of any message that asks you to log in from a link. Type the address yourself.
- Keep devices updated and run antivirus, so infostealers don’t get the chance to collect your saved passwords.
FAQ
What does compromised account mean?
A compromised account is one that an unauthorized person can access, usually with a stolen, guessed or reused password, or a stolen session cookie. The attacker may read your messages, send scams as you, make purchases or use the account to reset passwords elsewhere. You should change the password, sign out all sessions and enable MFA straight away.
How do you detect a compromised account?
Look for activity you didn’t do: sign-in alerts from new devices or countries, password reset emails you didn’t request, sent messages you didn’t write, new forwarding rules, unknown connected apps and changed MFA settings. Organizations add automated checks such as impossible travel alerts, unexpected MFA prompts and monitoring for leaked employee credentials.
What does it mean if my bank account is compromised?
It means someone may have your online banking login, card details or one-time codes and could move money or make purchases. Call your bank on the number printed on your card, ask them to freeze transactions and reissue credentials, check recent statements, and change your banking password. Never share an OTP with anyone who calls you.
Can an account be compromised even with MFA?
Yes, though it’s much harder. Attackers can trick users into approving repeated MFA prompts, steal session cookies with infostealer malware, or relay codes through a real time phishing page. Phishing resistant MFA such as security keys or passkeys, along with alerts on new sessions, closes most of these gaps.
