HackWatch

Recovery center

Phishing Recovery Center and Account Takeover Guides

Use this recovery center when someone already clicked a phishing link, entered credentials on a fake page, noticed account takeover or needs a clear response path after a scam.

The recovery center is built around the highest-urgency user questions: am I exposed, what should I do right now, how do I regain access and what must I lock down next.

Best for: phishing recovery, hacked Google or Microsoft accounts, Facebook or Instagram takeover, breached credentials, identity-theft spillover and scam incidents that moved from messages into real account or payment risk.

Start here after phishing

  • Change the password from a clean device.
  • Review active sessions, recovery options and MFA settings.
  • Check inbox rules, unknown devices and linked payment or support fraud.

What this recovery center is built for

This workflow is centered on phishing, account takeover, data breach fallout, identity theft and scam recovery, because users usually need a step-by-step action plan instead of another general security article.

google | high

Recover a Google account after suspicious sign-in or takeover

Use Google's recovery flow first, then revoke risky sessions, app passwords and recovery changes.

Recovery steps

  1. Go to Google's account recovery flow and start with the last password you remember.
  2. Review recovery email, phone number and recent security activity for changes you did not make.
  3. Sign out of other sessions and revoke suspicious third-party app access.
  4. Change the password, enable 2-Step Verification and generate fresh backup codes.
  5. Check Gmail filters, forwarding rules and delegated mailbox access for persistence.

Prevention

  • Use a strong unique password and passkeys where available.
  • Keep recovery options current and protected by another secure mailbox.
  • Review Google security checkup monthly.

Official links

microsoft | high

Recover a Microsoft account after phishing or unauthorized access

Secure the sign-in channel, review alias and MFA changes, then inspect mailbox rules and Azure/consumer sessions.

Recovery steps

  1. Run Microsoft's account recovery and verify your identity with known recovery methods.
  2. Change the password and review recent sign-in history for unfamiliar locations or devices.
  3. Remove unknown aliases, app passwords and trusted devices.
  4. Enable Microsoft Authenticator or another MFA method and save recovery codes.
  5. Inspect Outlook inbox rules, forwarding, automatic replies and connected apps for abuse.

Prevention

  • Turn on MFA and passwordless sign-in where possible.
  • Disable legacy authentication if you manage a work tenant.
  • Review security alerts in the Microsoft account dashboard regularly.

Official links

meta | high

Recover a Meta account after Facebook or Instagram compromise

Use Meta's compromised account path and immediately remove attacker persistence from sessions, ads and linked accounts.

Recovery steps

  1. Start from Meta's compromised account recovery page for Facebook or Instagram.
  2. Reset the password and review email, phone and two-factor settings for unauthorized changes.
  3. Log out of suspicious sessions and remove unknown linked accounts or Business Manager access.
  4. Check ad accounts, payment methods and page roles for malicious additions.
  5. Secure the mailbox connected to Meta because attackers often pivot through email access.

Prevention

  • Enable two-factor authentication with an authenticator app.
  • Review page roles and business permissions often.
  • Keep backup codes and trusted contact options updated.

Official links

banking | critical

Respond to suspected banking fraud or fake bank login pages

Contact the bank through official numbers first, freeze risky actions fast, then document the fraud timeline for escalation.

Recovery steps

  1. Call the bank using the number from the official app, card or website, not from the message you received.
  2. Freeze the card or account features that may be at risk and challenge suspicious transfers immediately.
  3. Change banking passwords and secure the email account tied to financial alerts.
  4. Preserve screenshots, sender IDs, URLs, timestamps and transaction identifiers.
  5. Ask the bank about fraud claims, chargeback options and whether a police report is recommended.

Prevention

  • Never approve push requests you did not initiate.
  • Set up transaction alerts and transfer limits.
  • Use the banking app directly instead of message links.

Breach response

Review exposed mailbox and password reuse risk

Move from general recovery into a breach-specific action plan with credential rotation, MFA hardening, account review and fraud monitoring priorities.

Open breach checker

Identity theft

Build a timeline after leaked personal data

Use the identity theft planner when phishing or a breach has turned into document exposure, fraud alerts, carrier problems or suspicious financial activity.

Open identity theft planner

Link triage

Inspect the phishing URL or domain

Use the URL checker to review redirects, DNS, TLS, hosting and domain context when recovery starts from a fake login page or redirector.

Open URL checker

How this tool helps

Built for real phishing and takeover moments

This hub is for people who already clicked, already signed in, already shared a code or already noticed unusual sessions, inbox rules, password resets or payment activity. It is designed for action, not theory.

  • Clicked a suspicious link or opened a fake login page
  • Lost access to Google, Microsoft, Meta or banking access
  • Suspect stolen credentials, breach exposure or identity theft

What the recovery center covers

Each guide is mapped to the situations users report most often after phishing, scams and breaches: account recovery, mailbox cleanup, session review, fraud containment and next-step escalation.

  • Immediate containment after phishing and fake support scams
  • Account recovery workflows for Google, Microsoft, Meta and banking incidents
  • Breach and identity-theft response priorities for the first 24 hours

What to do first after a phishing hit

The first move is usually containment: change passwords from a clean device, revoke sessions, review recovery methods, check inbox rules, remove unknown devices and contact the impacted provider before the attacker extends access.

  • Reset passwords from a trusted device
  • Sign out suspicious sessions and remove unknown devices
  • Review MFA, recovery email, recovery phone and mailbox rules

Where breach exposure and identity theft fit in

Recovery does not end at login access. If credentials were reused, mailbox data leaked or identity documents were exposed, the next steps include password rotation, fraud monitoring, bank contact, documentation and evidence retention.

How this supports SEO and user intent

This page is structured for the urgent questions users actually search: what to do after clicking a phishing link, how to recover a hacked account, what to do after a breach and how to respond to identity theft or scam pressure.

Official recovery links still matter

The center combines editorial triage with provider recovery paths, because readers need both: practical containment guidance and official account restoration workflows.

  • Official recovery links by provider
  • Session, mailbox and MFA checks
  • Fraud containment and reporting steps

High-intent searches this page is built for

I clicked a phishing link what do I do now

This page is structured to answer this urgent user question with practical steps, tool output and related recovery workflows already visible in server-rendered HTML.

how to recover hacked Google account after phishing

This page is structured to answer this urgent user question with practical steps, tool output and related recovery workflows already visible in server-rendered HTML.

how to recover Microsoft account after suspicious sign-in

This page is structured to answer this urgent user question with practical steps, tool output and related recovery workflows already visible in server-rendered HTML.

what to do after entering password on fake website

This page is structured to answer this urgent user question with practical steps, tool output and related recovery workflows already visible in server-rendered HTML.

what to do after banking phishing scam

This page is structured to answer this urgent user question with practical steps, tool output and related recovery workflows already visible in server-rendered HTML.

Response playbook

First 15 minutes

  1. Move to a clean device before changing passwords or opening recovery links.
  2. Reset the primary password and sign out active sessions if the provider allows it.
  3. Check recovery email, recovery phone and MFA methods for changes you did not make.

First 24 hours

  1. Review mailbox rules, delegates, OAuth app access and new trusted devices.
  2. Secure connected banking, cloud and password manager accounts if the mailbox was exposed.
  3. Document the timeline, screenshots and every provider action in one recovery log.

Next 7 days

  1. Monitor new sign-in alerts, password reset prompts and payment warnings.
  2. Rotate reused credentials and remove legacy access paths left behind by the attacker.
  3. Escalate to provider support if suspicious sessions or fraudulent changes return.

Official references and recovery paths

Google account recovery

Official guidance or recovery documentation that supports the containment and next-step workflow on this page.

Open reference

Microsoft compromised account help

Official guidance or recovery documentation that supports the containment and next-step workflow on this page.

Open reference

Facebook hacked account

Official guidance or recovery documentation that supports the containment and next-step workflow on this page.

Open reference

Instagram compromised account help

Official guidance or recovery documentation that supports the containment and next-step workflow on this page.

Open reference

Frequently asked questions

What should I do immediately after entering my password on a phishing page?

Start with containment from a clean device: change the password, review recovery options, sign out active sessions, check MFA settings and scan the device used during the incident.

Why is this a recovery center instead of only account guides?

Because real incidents cross categories. Phishing can become mailbox compromise, identity theft, payment fraud or fake support scams within minutes, so users need one response hub instead of scattered pages.

Does this page help after a data breach even if the account is not locked yet?

Yes. Many recovery decisions begin before a lockout happens. If an email, password or personal data was exposed, you should still rotate credentials, enable MFA, review reuse risk and document the incident path.

Why include banking and identity-theft scenarios in a cyber recovery hub?

Because the user problem is not only technical compromise. Many phishing and scam incidents lead directly to payment fraud, credit abuse or identity theft, so the recovery path has to cover those consequences too.

Related workflows

Scam checker

Scam Checker for Suspicious Messages

Check suspicious SMS, fake delivery updates, payment prompts and urgent verification messages to spot scam pressure before you click, pay or reply.

Open tool page

Email review

Email Reputation and Sender Review

Review suspicious senders, domain clues and phishing language to triage risky email campaigns before anyone opens links, attachments or login pages.

Open tool page

Email header analyzer

Email Header Analyzer for SPF, DKIM, DMARC and Reply-To Mismatch

Analyze suspicious email headers for SPF, DKIM, DMARC, Reply-To mismatch, Return-Path mismatch and relay-chain clues before trusting a message.

Open tool page

Email posture

Email Security Posture Checker (SPF, DKIM, DMARC, MX)

Check SPF, DKIM, DMARC and MX records to find email spoofing gaps, strengthen domain trust and improve business email security posture.

Open tool page

URL checker

Free Phishing Link Checker and Domain Intelligence Report

Check suspicious links before you click with hostname, redirects, DNS, TLS, ASN, hosting provider and phishing-pattern analysis in one report.

Open tool page

Brand impersonation

Brand Impersonation Checker for Lookalike Domains and Fake Support Pages

Check suspicious domains, senders and fake support portals for brand impersonation, lookalike patterns, punycode, typosquatting and recent-registration risk.

Open tool page

Breach checker

Breach Exposure Checker for Email and Password Reuse Risk

Check whether exposed email or reused passwords create real breach risk, then follow a practical 24-hour containment plan and next-step checklist.

Open tool page

Identity theft planner

Identity Theft Recovery Planner

Build a step-by-step identity theft response plan after exposed personal data, fraudulent accounts, mailbox compromise, SIM swap or document leaks.

Open tool page

Crypto scam checker

Crypto Scam Checker for Fake Investments and Recovery Fraud

Check suspicious crypto projects, fake exchange messages, guaranteed-return claims and recovery-fee demands before sending funds or identity documents.

Open tool page

Ransomware triage

Ransomware Triage and Decryptor Finder

Triage encrypted-file incidents with isolation steps, ransom-note analysis, extension review, backup checks and decryptor guidance before recovery decisions.

Open tool page

Report incident

Incident Report Intake

Submit suspicious phishing pages, malicious senders, brand impersonation attempts and emerging attack patterns so new scam clusters surface faster.

Open tool page