
Rules
Account security problems: password reuse, phishing, SIM swaps and stale sessions
Spot password reuse, phishing, SIM swaps and stale sessions, then contain each account takeover vector, repair the access paths and verify the fix held.
What to take away
- A password change alone leaves attacker sessions open, so revoke sessions in the same sitting.
- Treat the carrier number, the recovery address and the password manager as part of the account, not as backups to it.
- Preserve alerts, case numbers and transaction records before you wipe a device or delete messages.
- Move high-value accounts off text codes wherever the service supports a stronger method.
- Test the repair from a second device before you trust it.
Account problems travel along dependencies. A stolen email session resets other services. A SIM swap intercepts every text code. A photographed recovery sheet bypasses a strong primary method. Diagnose the entry path, then every access path it could have changed.
Password reuse
Signs: A breach alert names a reused password, several services log failed attempts, or one exposed credential opens a second account.
Contain a reused password
- Secure primary email and password manager
- Change password everywhere it was reused
- Trailing digit is not a new password
- Generate unique passwords, revoke sessions
- Inspect recovery addresses and connected apps
Contain: From a known-clean device, secure the primary email and the password manager first. Change the password everywhere it was reused. Cosmetic variations such as a trailing digit do not count as a new password.
Repair: Generate unique passwords, revoke sessions, and inspect recovery addresses and connected apps. A password change on its own may leave an attacker's session open.
Phishing prompts
Signs: A push request you did not trigger, a login page reached through a message, an urgent request for a verification code, or a domain that is nearly right.
Contain: Reject the prompt. Close the page and open the app or type the address yourself. If you entered a credential or a code, treat both as exposed now, not later.
Repair: Change the credential at the real service, revoke sessions, and check for new authenticators and changed recovery details. Report the message through the provider's own reporting channel.
SIM swaps
Signs: The phone loses calls, texts and data at once, or the carrier reports a SIM or device change you did not request.
Contain a SIM swap
- Call carrier from a different line or store
- Restore control of the number
- Add account PIN or port protection
- Protect email and financial accounts
- Use another trusted device meanwhile
Contain: Call the carrier from a different line or walk into a store. Restore control of the number and add the account PIN or port protection the carrier offers. Use another trusted device to protect email and financial accounts while the number is out.
The FTC's alert on SIM swap scams walks through the loss of service, the takeover of calls and texts, carrier contact, account PINs, and the stronger alternatives to text codes. Carrier procedures and legal remedies vary, so follow your provider's current instructions and your jurisdiction's rules.
Repair: Replace exposed credentials, end sessions, review transactions, and move high-value accounts to a stronger method where the service supports one.
Exposed recovery codes
Signs: Codes turn up in a photo backup, an email folder, a shared drive, a printout left in public, or an unprotected export.
Exposed vs replaced recovery codes
Exposed set
- Location
- Photo backup, shared drive
- Validity
- Confirm old set fails
- Labeling
- Identifiable to a finder
- Account events
- Check for changes
New set
- Location
- Protected vault or offline
- Validity
- Generated at real service
- Labeling
- Identifies service, vague to others
- Account events
- Watch for recovery edits
Contain: Generate a new set at the genuine service and confirm the old set no longer works. Check account events for recovery or authenticator changes you did not make.
Repair: Store the new set in a protected vault or a secure offline location. Label it well enough that you can identify the service, and vaguely enough that a casual finder cannot.
Stale sessions
Signs: An old phone, a shared browser, a former contractor or an unfamiliar location stays signed in after a password change.
Contain: Screenshot the unknown sessions first, then use global sign-out or revoke them one by one. Remove remembered-device status, third-party tokens, app passwords and delegated access.
NIST's account of authenticator threats covers disclosure of knowledge factors, loss or cloning of possession factors, unauthorized binding, recovery abuse and session attacks. It supports looking past the password. It does not describe how any particular provider logs a session.
Repair: Reauthenticate trusted devices only after the primary and recovery paths are clean. Turn on session alerts and shorten the trust window where the service allows it.
Account lockout
Signs: The only phone is lost, a security key fails, the recovery address is dead, or repeated attempts triggered a hold.
Contain: Stop guessing. Use the provider's official recovery page and keep every case number. Do not pay an unsolicited recovery service and do not hand codes to anyone claiming to be support.
Repair: Once access returns, bind a second independent authenticator, refresh the recovery details, replace used codes, and save the provider's official support path. Then work out why the backup failed.
Verify resolution
Run this check before you call the incident closed.
- Primary and backup methods both work, tested in separate sessions.
- Old sessions, authenticators, recovery addresses and tokens are gone.
- Sent messages, forwarding rules, transactions, administrators and exports reviewed.
- Alerts confirmed to reach you, not an address you no longer control.
- A short timeline written down with the provider's confirmation.
Keep the timeline. If the same account is targeted again, the record shows what was already tried.
Common questions
Should I change every password after one account is phished?
Change the exposed password and every place it was reused or closely copied. Work in this order: email, password manager, carrier, financial accounts, then everything else.
Does restoring phone service finish a SIM-swap response?
No. The number is only the first layer. Review every account that used it for recovery or text codes, plus financial activity and open sessions. Some damage appears weeks after service returns.
Can a recovery code be used twice?
Many are single-use, but designs vary by provider. Replace the whole set whenever a code, or a photo of the set, may have been seen.
Why stop repeated recovery attempts?
Extra attempts can extend a hold, muddy the evidence and trip fraud controls. Follow the provider's official process and keep the case number.






