
Someone Logged Into My Account: What to Do Now
Someone logged into your account from another location? Log them out, secure your email first, check recovery details and turn on 2FA before you lose access.
Act while you can still sign in. Secure your email account first, because whoever controls that inbox can reset your social accounts. Then log out the unknown device, change the account password, check the recovery email and phone are still yours, and turn on two-factor authentication. If you are already locked out, use the platform's own recovery page.
Summary- An unrecognised login means someone may have your password or an active session, but while you can still sign in, you usually hold the advantage.
- Secure your email account first, because whoever controls that inbox can reset every social account linked to it.
- Then log out the unknown device, change the account password, check that the recovery email and phone are still yours, and turn on two-factor authentication.
- If an email says your address was changed and you did not do it, check that it is genuine, then use the reverse link Facebook or Instagram sent to your old address.
- Nobody legitimate asks for your password, login codes or backup codes, so ignore any caller or message offering to secure the account for you.
- If you are already locked out, only the platform's own recovery route can return the account, and some taken accounts do not come back.
Table of contents14 sections
- 01What Should You Do If Someone Logged Into Your Account?
- 02Was It Really Someone Else?
- 03How Much Control Do You Still Have?
- 04Why Your Email Comes Before Everything Else
- 05Step by Step: Facebook
- 06Step by Step: Instagram
- 07Step by Step: Google and Gmail
- 08What If an Email Says Your Address Was Changed?
- 09What Attackers Change Quietly
- 10If Money or a Code Was Involved in Malaysia
- 11Mistakes That Turn an Unknown Login Into a Lost Account
- 12If You Are Already Locked Out
- 13When Expert Recovery Help Makes Sense
- 14Frequently Asked Questions
You open your settings and see a phone you have never owned, logged in from a city you have never visited. Or Facebook, Instagram or Google emails you about a new sign-in that was not you. The account still works, your password still works, and you are not sure whether someone is inside right now.
Treat it as real until you can explain it, and move in this order: secure the email account, log out the unknown device, change the password, check the recovery email and phone, then turn on two-factor authentication. Doing these while you can still sign in is far easier than recovering an account after the attacker changes the details.
This guide covers how to tell a real intrusion from your own travel or a new phone, the exact steps on Facebook, Instagram and Google, what to check that attackers quietly change, and what to do in Malaysia if money or a code was involved.
Last checked: 29 September 2026.
#What Should You Do If Someone Logged Into Your Account?
Change the password on the email account linked to it first, then log out the unfamiliar session and change the account password from inside the app or official website. Next, confirm the recovery email and phone number are still yours and remove anything you did not add. Finally turn on two-factor authentication so a stolen password alone is no longer enough. If you already cannot sign in, go straight to the platform's recovery page: facebook.com/hacked, instagram.com/hacked or Google's account recovery page.
#Was It Really Someone Else?
Sometimes it is you. Location on login lists is often approximate, and your own devices can look strange. Google's page on devices with account access lists the common false alarms: a new device, a borrowed or public computer, a phone you reset, a place you only passed through such as an airport, or a nearby town shown instead of your exact location. A VPN can also make your own phone look as if it is abroad.
So check the device type, the browser or app, and the time together. If you cannot explain all three, act as if it was not you. A false alarm costs you one password change. Facebook's page on recovering a hacked account adds the signs of a real intrusion: posts or messages you did not write, a changed profile picture, a two-factor method that stopped working, or an email saying your password, email or phone number changed when you did nothing.
#How Much Control Do You Still Have?
Your next step depends on what still works. Find your row.
| What you see | What it usually means | Do this now |
|---|---|---|
| An unknown device in the login list, but nothing else has changed | Someone has your password or a copied session, or it is your own device shown oddly | Secure your email, log out the device, change the password, turn on 2FA |
| An email saying your account email or phone was changed, and you did not change it | The attacker is taking over the recovery details | Use the reverse or "secure my account" link sent to your old address, from the real platform |
| Friends say you sent them strange messages or links | Someone is using the account right now | Change the password to log them out, then warn contacts from another channel |
| Your password no longer works | The attacker changed it, and may change the email next | Go to the platform's hacked account page from a device you have used before |
| Your email account also shows logins you do not recognise | The inbox itself is compromised, so every linked account is exposed | Secure the email first, then work through each linked account |
#Why Your Email Comes Before Everything Else
Your email is the master key. Instagram's security tips page says anyone who can read your email can probably also access your Instagram, and tells you to change the passwords on all your email accounts so that no two are the same. The same logic applies to Facebook, TikTok and nearly every other service: the password reset lands in that inbox.
If your email is Gmail, Google's page on securing a compromised account tells you to remove any labels, filters or forwarding rules you did not set up. Attackers use forwarding and filters so that reset emails reach them, or vanish before you see them. Do this from a device you trust: if you suspect harmful software, Google suggests running trusted anti-virus software first.
#Step by Step: Facebook
Facebook keeps sessions in Accounts Center. Its page on logging out of another device gives these steps, at the time of writing:
- Open Accounts Center and choose "Password and security".
- Select "Where you're logged in" and pick your account to see every active session.
- Choose "Select devices to log out", tick the sessions you do not recognise, or "Select all", then tap "Log out" and confirm.
- Change your Facebook password to one you use nowhere else.
- Check the email addresses and phone numbers on the account and remove any you did not add.
- Turn on two-factor authentication under "Password and security", then "Two-factor authentication".
Facebook's page on how two-factor authentication works offers three methods: a security key, codes from an authentication app, or text message codes. It also says you can get 10 recovery login codes for when your phone is unavailable. Keep them offline. Our two-factor authentication guide compares the methods.
#Step by Step: Instagram
Instagram's page on recent login activity uses the same Accounts Center path: "Password and security", then "Where you're logged in", then "Select devices to log out". If your account still shows the older layout, open "Login Activity" instead and tap "This Wasn't Me" on the unknown login, which leads you to a password reset.
Changing the password does more than block the next attempt. Instagram's page on why your account may be at risk says that once you update your password, you are logged out of all other devices, so anyone logged into your account loses access. It names the usual causes: a password reused on a site that was breached, or an unauthorised third-party app.
Instagram's hacked account page lists what to do while you can still log in: change your password, turn on two-factor authentication, confirm the phone number and email in settings are correct, remove linked accounts you do not recognise in Accounts Center, and revoke access for suspicious third-party apps.
#Step by Step: Google and Gmail
Google puts both checks under "Security & sign-in" in your Google Account. Its compromised account page describes them:
- On the "Recent security events" panel, select "Review security events". For anything you did not do, choose "No, it wasn't me" and follow the steps.
- Open "Your devices", then "Manage all devices". If you see a device you do not know, choose "Don't recognize a device?" and follow the steps, or sign out of that session.
- Change your Google password, then change it on any other site where you used the same one.
- Correct anything you did not set: recovery phone, recovery email, apps with access, and Gmail forwarding, filters, delegation or IMAP and POP access.
Several sessions with the same device name may be one device or several, Google notes, so if unsure, sign out of all of them. For the second step, Google's page on turning on 2-Step Verification recommends passkeys or Google prompts, and notes that codes sent by text or call can be vulnerable to phone number based hacks.
#What If an Email Says Your Address Was Changed?
Use the reverse link, but only after checking the email is genuine. Facebook's hacked account page says that when the email on your account changes, it sends a message with a special link to the previous address, and that link lets you reverse the change and secure the account. Instagram's hacked account page says an email from [email protected] about an email change may let you undo it through "secure my account".
Fake versions of these emails exist. Facebook's page on checking an email is really from Facebook lists the only domains it sends from: fb.com, facebook.com, facebookmail.com, instagram.com, meta.com, metamail.com and global.metamail.com, plus their subdomains, and warns about misspelled copies. If you can still log in, look under "Password and security", then "Recent emails". Instagram's recent emails page shows security emails from the last 14 days and says Instagram never raises account security by Direct Message.
#What Attackers Change Quietly
A careful intruder leaves the account looking normal and sets up a way back in. After you log them out, check each item below. It is the step people most often skip.
- Recovery email and phone on every account.
- Email forwarding, filters and delegation.
- Two-factor settings: an authenticator or security key you did not add lets the attacker pass the second step.
- Linked accounts in Accounts Center and third-party apps with access.
- Saved payment methods and recent statements.
- Sent messages and posts, for scam links or money requests in your name.
If the attacker already messaged your friends asking for money or codes, our guide to a hacked account messaging your contacts covers what to tell them and what they should do.
#If Money or a Code Was Involved in Malaysia
If you typed banking details into a fake page, shared a code, or someone used your account to take money from others, call the National Scam Response Centre on 997. The government's NSRC page asks victims to call within 24 hours of discovering the scam so that bank accounts and transactions can be blocked, then to contact the bank and lodge a police report.
Google also asks you to check that nobody gave your bank instructions in your name, especially if cards are saved in Google Pay or Chrome. To report the phishing site or the incident, CyberSecurity Malaysia runs Cyber999, the national point of contact for computer security incidents, which takes reports by online form, email, phone and its mobile app.
One Malaysian check that is easy to miss: if your phone suddenly shows no signal around the time of the login, call your mobile carrier from another phone and ask whether your SIM was replaced. Text message codes follow the SIM, which is why an authentication app, passkey or security key is safer.
#Mistakes That Turn an Unknown Login Into a Lost Account
- Changing the social media password but leaving the email account on its old password.
- Logging out the device but not changing the password, so the attacker simply logs back in.
- Clicking the "secure your account" button in an email without checking the sender.
- Reusing the new password anywhere else.
- Leaving an attacker's recovery email or authenticator in place because the account "looks fine".
- Paying someone who offers to trace the intruder or "lock" the account. The platform tools above cost nothing.
#If You Are Already Locked Out
Stop trying to guess passwords and go to the official recovery route from a device you have used before, which Facebook specifically recommends. For Facebook that is facebook.com/hacked, for Instagram instagram.com/hacked, and for Google the account recovery page, which Google says to use if someone changed your password or recovery phone number. Our guide to the first hour after an Instagram hack walks through that sequence, and if the email and phone were both changed, see recovering an account without your old email or phone.
#When Expert Recovery Help Makes Sense
If you worked through the steps above, you have done what the platforms ask, and you did it yourself. A second pair of eyes helps when the intrusions keep coming back, when a business or several accounts share one compromised inbox, or when the login has already turned into a lockout. SocialSafe by AwareXone is our recovery and account security service. We look at your situation first and tell you plainly whether you still need help. Our account security service explains what that review covers, and our Trust Center lists what we will never ask you for.
#Frequently Asked Questions
Does changing my password log out the other person?
Can someone log into my account without my password?
Why does my login list show a city I have never been to?
Should I delete my account if someone logged in?
Can AwareXone find out who logged into my account?
Official sources
- Facebook Help Center: Log out of Facebook on another device (read 29 September 2026)
- Facebook Help Center: Recover your Facebook account if you were hacked (read 29 September 2026)
- Facebook Help Center: Check if an email is really from Facebook (read 29 September 2026)
- Facebook Help Center: How two-factor authentication works on Facebook (read 29 September 2026)
- Instagram Help Center: If you think your Instagram profile has been hacked (read 29 September 2026)
- Instagram Help Center: View your recent Instagram login activity (read 29 September 2026)
- Instagram Help Center: Why Instagram tells you your account is at risk (read 29 September 2026)
- Instagram Help Center: Secure your Instagram account (read 29 September 2026)
- Instagram Help Center: Review recent emails sent from Instagram (read 29 September 2026)
- Google Account Help: Secure a hacked or compromised Google Account (read 29 September 2026)
- Google Account Help: See devices with account access (read 29 September 2026)
- Google Account Help: Turn on 2-Step Verification (read 29 September 2026)
- Malaysian government: NSRC 997 hotline (read 29 September 2026)
- CyberSecurity Malaysia: Cyber999 overview (read 29 September 2026)
Need help with your account?
Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: Account security.




