Knowledge · Data leaks · 8 minutes
Someone hacked my account: what to do, step by step
Someone hacked your account or changed the password and email? How to check sessions, recover the account via official help, and act after a data breach.
Last updated: October 6, 2026
Someone hacked my account: where do I start?
An account takeover is when a stranger signs in to your account because they obtained your password, a code or a saved session. According to CERT Polska, the Polish national CSIRT, the most common causes are phishing, reusing a password that then leaked from another service, malware that steals passwords and sessions (infostealers), and an earlier takeover of your mailbox.
Order matters. Secure your email first, because password reset links for other services arrive there. Then the account that was taken over, and finally the others that shared the same password. Do it from a device you trust. If you suspect malware on your computer, change passwords from your phone, and the other way round.
How to check if someone has hacked my account
Signs according to CERT Polska: unknown sessions and devices in your sign-in list, apps and tools connected to the account that you do not recognise, password change attempts, and posts or messages you did not send. Friends asking about a strange request for money or a payment code are a sign too.
Where to check. In your Google Account: Security & sign-in, the recent security events section, and the device list at myaccount.google.com/device-activity. On Facebook and Instagram: the list of places where you are signed in, in the account security settings. CERT Polska has collected instructions for Facebook, Instagram, X and LinkedIn in its guide on hijacked accounts.
In your email, also check forwarding rules and filters. An attacker can set up automatic forwarding of your mail to their own address and keep reading it even after you change the password. Google lists this among the things to check after a hack.
Still have access? Secure the account in fifteen minutes
1. Change the password to a new, long and unique one. We explain how in how to create a strong password.
2. Sign out of all active sessions. CERT Polska stresses that ending sessions after a password change cuts off an attacker who is already signed in.
3. Check your recovery details: phone number, backup email address, two-factor methods. Remove anything you do not recognise.
4. Remove unknown apps and devices connected to the account. In Google, the permissions list is at myaccount.google.com/permissions.
5. Turn on two-factor authentication, preferably with an authenticator app, a passkey or a hardware key, and save the backup codes.
6. Change the password everywhere you used the same or a similar one. Warn your friends if messages were sent from your account: hijacked accounts are mainly used to get money from people close to you.
Someone changed my password and email: how do I recover the account?
If the attacker changed the password but you still control the linked email, use the normal password reset. If they changed the email too, CERT Polska advises contacting the service. Check your old mailbox: services often send a notice about changed details to the previous address, sometimes with a way to undo the change.
Official entry points listed by CERT Polska: for Facebook, facebook.com/hacked; for Instagram, the hacked account page in Meta's help centre; for X and LinkedIn, their access recovery forms. You recover a Google Account through the account recovery page (accounts.google.com/signin/recovery), which Google points to in its help on compromised accounts. For OLX, Netflix and other services, look for the form in their official help centre, for example pomoc.olx.pl. Type the help address yourself.
CERT Polska does not recover accounts: the procedures depend entirely on the service. Beware of people and "companies" in comment threads offering paid account recovery. Anyone who asks for your password, a code or a transfer to "recover" the account is running another scam. You can check the address of a suspicious recovery offer for free.
What to do after a personal data breach
A data breach is when your data held by a company or service ends up with people who should not have it. According to CERT Polska's guide (updated 2 September 2026), first establish exactly what leaked, because the next steps depend on it. Reliable sources are the company's own notice, your bank, a government office, the Polish data protection authority (UODO) or CERT Polska. Beware of "breach notice" emails with a link: after high-profile incidents they are a common phishing lure.
Steps by type of data. PESEL (Polish national ID number) or ID card details: freeze your PESEL in the mObywatel app or at mobywatel.gov.pl, and if a scan of your ID card leaked, consider cancelling it. Card details: block the card in your banking app and order a new one. Passwords: change them there and everywhere they were the same or similar. Phone number: switch important accounts from text codes to an app or a passkey, because of the risk of number hijacking (SIM swap). According to CERT Polska, a frozen PESEL blocks the issue of a duplicate SIM card.
We explain how to check whether your data is in known breaches (bezpiecznedane.gov.pl, Have I Been Pwned) in how to check if my data has leaked.
Medical data or ID number leaked: what now?
Medical data, your address or date of birth cannot be changed or frozen. What remains is vigilance. CERT Polska warns that criminals use breach data to make scams credible: a caller "from the bank" quotes your address or the last digits of your card, and a text about a "parcel problem" starts with your first name. The fact that someone knows your data does not prove they are who they claim to be.
If someone threatens to publish your data and demands payment, do not pay, keep the messages and report it to the police.
Your rights come from the GDPR. When a breach is likely to result in a high risk to you, the company must inform you without undue delay and describe its likely consequences and the measures it has taken or proposes to mitigate them (Article 34). You can ask which of your data it processes (Article 15) and, if you believe it broke the rules, lodge a complaint with the supervisory authority, in Poland the President of UODO (Article 77). You are entitled to compensation for damage (Article 82).
Over the following months, review your statements and sign-in history. According to CERT Polska, breach databases are sometimes used many months after the incident. In the mObywatel app you can turn on alerts from the Bezpiecznie w sieci (Safe online) service about major threats.
Where to report a hacked account
To the service: through its official recovery and reporting process. To your bank: immediately, if the break-in involves online banking, a card, or the mailbox that receives confirmations. To CERT Polska: through the form at incydent.cert.pl, which helps warn others. To the police: if you lost money or someone is impersonating you. If the break-in started with a fake message, also read how to recognise phishing.
In short
- Start with your email: whoever controls your mailbox can reset passwords for your other accounts.
- After changing a password, always sign out of all sessions and remove unknown devices, apps and mail forwarding rules.
- If you lose access, use only the service's official process. No outsider can recover the account for you.
- After a breach, first establish what leaked. Freeze your ID number and ID card, block cards, change passwords.
- After the incident, turn on two-factor authentication, preferably without text messages.
Have a website, app or email address that looks suspicious?
Frequently asked questions
Someone hacked my Facebook account and changed the password and email. What should I do?
Go to facebook.com/hacked, Meta's official page for compromised accounts, and follow the steps. Also check your old mailbox for a notice about the changed address, and secure that mailbox.
Can CERT Polska help me recover my account?
No. CERT Polska explains that recovery procedures depend entirely on the service. It is still worth reporting the incident at incydent.cert.pl to help protect others.
How do I check if someone is signing in to my Google Account?
Open your Google Account settings, go to Security & sign-in and review recent events. The device list is at myaccount.google.com/device-activity. Remove any unknown device and change your password.
My PESEL number leaked. What should I do?
Freeze your PESEL in the mObywatel app, at mobywatel.gov.pl or at a municipal office. It is free, takes effect immediately, and you can lift it temporarily when you take out a loan yourself.
Am I entitled to compensation after a data breach?
Article 82 GDPR gives a right to compensation for damage caused by a breach of the rules. Whether you get it, and how much, is decided by a court in each case. You can complain about the company to the data protection authority.
Someone hacked my OLX or Netflix account. Where do I report it?
In the service's official help centre (for OLX, pomoc.olx.pl), typing the address yourself. If a card was linked to the account, also call your bank and check recent payments.
Sources
- CERT Polska: Hijacked social media account (updated 2 September 2026, in Polish)
- CERT Polska: Hijacked mailbox (updated 2 September 2026, in Polish)
- CERT Polska: Social media account security (in Polish)
- CERT Polska: Data leaks, response guide (updated 2 September 2026, in Polish)
- Google Help: Secure a hacked or compromised Google Account
- Meta: Page for hacked Facebook accounts
- Regulation (EU) 2016/679 (GDPR), Articles 15, 34, 77 and 82
- CERT Polska: Report an incident
Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.