A door left ajar with light falling on a smartphone on the floor drawn in blue binary digits on a dark background, beside the headline Someone Logged In? Do This First.

Someone Logged Into My Account: What to Do Now

Someone logged into your account from another location? Log them out, secure your email first, check recovery details and turn on 2FA before you lose access.

11 min read
Short answer

Act while you can still sign in. Secure your email account first, because whoever controls that inbox can reset your social accounts. Then log out the unknown device, change the account password, check the recovery email and phone are still yours, and turn on two-factor authentication. If you are already locked out, use the platform's own recovery page.

Summary
  • An unrecognised login means someone may have your password or an active session, but while you can still sign in, you usually hold the advantage.
  • Secure your email account first, because whoever controls that inbox can reset every social account linked to it.
  • Then log out the unknown device, change the account password, check that the recovery email and phone are still yours, and turn on two-factor authentication.
  • If an email says your address was changed and you did not do it, check that it is genuine, then use the reverse link Facebook or Instagram sent to your old address.
  • Nobody legitimate asks for your password, login codes or backup codes, so ignore any caller or message offering to secure the account for you.
  • If you are already locked out, only the platform's own recovery route can return the account, and some taken accounts do not come back.
Table of contents14 sections
  1. 01What Should You Do If Someone Logged Into Your Account?
  2. 02Was It Really Someone Else?
  3. 03How Much Control Do You Still Have?
  4. 04Why Your Email Comes Before Everything Else
  5. 05Step by Step: Facebook
  6. 06Step by Step: Instagram
  7. 07Step by Step: Google and Gmail
  8. 08What If an Email Says Your Address Was Changed?
  9. 09What Attackers Change Quietly
  10. 10If Money or a Code Was Involved in Malaysia
  11. 11Mistakes That Turn an Unknown Login Into a Lost Account
  12. 12If You Are Already Locked Out
  13. 13When Expert Recovery Help Makes Sense
  14. 14Frequently Asked Questions

You open your settings and see a phone you have never owned, logged in from a city you have never visited. Or Facebook, Instagram or Google emails you about a new sign-in that was not you. The account still works, your password still works, and you are not sure whether someone is inside right now.

Treat it as real until you can explain it, and move in this order: secure the email account, log out the unknown device, change the password, check the recovery email and phone, then turn on two-factor authentication. Doing these while you can still sign in is far easier than recovering an account after the attacker changes the details.

This guide covers how to tell a real intrusion from your own travel or a new phone, the exact steps on Facebook, Instagram and Google, what to check that attackers quietly change, and what to do in Malaysia if money or a code was involved.

Last checked: 29 September 2026.

#What Should You Do If Someone Logged Into Your Account?

Change the password on the email account linked to it first, then log out the unfamiliar session and change the account password from inside the app or official website. Next, confirm the recovery email and phone number are still yours and remove anything you did not add. Finally turn on two-factor authentication so a stolen password alone is no longer enough. If you already cannot sign in, go straight to the platform's recovery page: facebook.com/hacked, instagram.com/hacked or Google's account recovery page.

#Was It Really Someone Else?

Sometimes it is you. Location on login lists is often approximate, and your own devices can look strange. Google's page on devices with account access lists the common false alarms: a new device, a borrowed or public computer, a phone you reset, a place you only passed through such as an airport, or a nearby town shown instead of your exact location. A VPN can also make your own phone look as if it is abroad.

So check the device type, the browser or app, and the time together. If you cannot explain all three, act as if it was not you. A false alarm costs you one password change. Facebook's page on recovering a hacked account adds the signs of a real intrusion: posts or messages you did not write, a changed profile picture, a two-factor method that stopped working, or an email saying your password, email or phone number changed when you did nothing.

#How Much Control Do You Still Have?

Your next step depends on what still works. Find your row.

Unrecognised login situations and the first move for each, at the time of writing.
What you seeWhat it usually meansDo this now
An unknown device in the login list, but nothing else has changedSomeone has your password or a copied session, or it is your own device shown oddlySecure your email, log out the device, change the password, turn on 2FA
An email saying your account email or phone was changed, and you did not change itThe attacker is taking over the recovery detailsUse the reverse or "secure my account" link sent to your old address, from the real platform
Friends say you sent them strange messages or linksSomeone is using the account right nowChange the password to log them out, then warn contacts from another channel
Your password no longer worksThe attacker changed it, and may change the email nextGo to the platform's hacked account page from a device you have used before
Your email account also shows logins you do not recogniseThe inbox itself is compromised, so every linked account is exposedSecure the email first, then work through each linked account

#Why Your Email Comes Before Everything Else

Your email is the master key. Instagram's security tips page says anyone who can read your email can probably also access your Instagram, and tells you to change the passwords on all your email accounts so that no two are the same. The same logic applies to Facebook, TikTok and nearly every other service: the password reset lands in that inbox.

If your email is Gmail, Google's page on securing a compromised account tells you to remove any labels, filters or forwarding rules you did not set up. Attackers use forwarding and filters so that reset emails reach them, or vanish before you see them. Do this from a device you trust: if you suspect harmful software, Google suggests running trusted anti-virus software first.

#Step by Step: Facebook

Facebook keeps sessions in Accounts Center. Its page on logging out of another device gives these steps, at the time of writing:

  1. Open Accounts Center and choose "Password and security".
  2. Select "Where you're logged in" and pick your account to see every active session.
  3. Choose "Select devices to log out", tick the sessions you do not recognise, or "Select all", then tap "Log out" and confirm.
  4. Change your Facebook password to one you use nowhere else.
  5. Check the email addresses and phone numbers on the account and remove any you did not add.
  6. Turn on two-factor authentication under "Password and security", then "Two-factor authentication".

Facebook's page on how two-factor authentication works offers three methods: a security key, codes from an authentication app, or text message codes. It also says you can get 10 recovery login codes for when your phone is unavailable. Keep them offline. Our two-factor authentication guide compares the methods.

#Step by Step: Instagram

Instagram's page on recent login activity uses the same Accounts Center path: "Password and security", then "Where you're logged in", then "Select devices to log out". If your account still shows the older layout, open "Login Activity" instead and tap "This Wasn't Me" on the unknown login, which leads you to a password reset.

Changing the password does more than block the next attempt. Instagram's page on why your account may be at risk says that once you update your password, you are logged out of all other devices, so anyone logged into your account loses access. It names the usual causes: a password reused on a site that was breached, or an unauthorised third-party app.

Instagram's hacked account page lists what to do while you can still log in: change your password, turn on two-factor authentication, confirm the phone number and email in settings are correct, remove linked accounts you do not recognise in Accounts Center, and revoke access for suspicious third-party apps.

#Step by Step: Google and Gmail

Google puts both checks under "Security & sign-in" in your Google Account. Its compromised account page describes them:

  1. On the "Recent security events" panel, select "Review security events". For anything you did not do, choose "No, it wasn't me" and follow the steps.
  2. Open "Your devices", then "Manage all devices". If you see a device you do not know, choose "Don't recognize a device?" and follow the steps, or sign out of that session.
  3. Change your Google password, then change it on any other site where you used the same one.
  4. Correct anything you did not set: recovery phone, recovery email, apps with access, and Gmail forwarding, filters, delegation or IMAP and POP access.

Several sessions with the same device name may be one device or several, Google notes, so if unsure, sign out of all of them. For the second step, Google's page on turning on 2-Step Verification recommends passkeys or Google prompts, and notes that codes sent by text or call can be vulnerable to phone number based hacks.

#What If an Email Says Your Address Was Changed?

Use the reverse link, but only after checking the email is genuine. Facebook's hacked account page says that when the email on your account changes, it sends a message with a special link to the previous address, and that link lets you reverse the change and secure the account. Instagram's hacked account page says an email from [email protected] about an email change may let you undo it through "secure my account".

Fake versions of these emails exist. Facebook's page on checking an email is really from Facebook lists the only domains it sends from: fb.com, facebook.com, facebookmail.com, instagram.com, meta.com, metamail.com and global.metamail.com, plus their subdomains, and warns about misspelled copies. If you can still log in, look under "Password and security", then "Recent emails". Instagram's recent emails page shows security emails from the last 14 days and says Instagram never raises account security by Direct Message.

#What Attackers Change Quietly

A careful intruder leaves the account looking normal and sets up a way back in. After you log them out, check each item below. It is the step people most often skip.

  • Recovery email and phone on every account.
  • Email forwarding, filters and delegation.
  • Two-factor settings: an authenticator or security key you did not add lets the attacker pass the second step.
  • Linked accounts in Accounts Center and third-party apps with access.
  • Saved payment methods and recent statements.
  • Sent messages and posts, for scam links or money requests in your name.

If the attacker already messaged your friends asking for money or codes, our guide to a hacked account messaging your contacts covers what to tell them and what they should do.

#If Money or a Code Was Involved in Malaysia

If you typed banking details into a fake page, shared a code, or someone used your account to take money from others, call the National Scam Response Centre on 997. The government's NSRC page asks victims to call within 24 hours of discovering the scam so that bank accounts and transactions can be blocked, then to contact the bank and lodge a police report.

Google also asks you to check that nobody gave your bank instructions in your name, especially if cards are saved in Google Pay or Chrome. To report the phishing site or the incident, CyberSecurity Malaysia runs Cyber999, the national point of contact for computer security incidents, which takes reports by online form, email, phone and its mobile app.

One Malaysian check that is easy to miss: if your phone suddenly shows no signal around the time of the login, call your mobile carrier from another phone and ask whether your SIM was replaced. Text message codes follow the SIM, which is why an authentication app, passkey or security key is safer.

#Mistakes That Turn an Unknown Login Into a Lost Account

  • Changing the social media password but leaving the email account on its old password.
  • Logging out the device but not changing the password, so the attacker simply logs back in.
  • Clicking the "secure your account" button in an email without checking the sender.
  • Reusing the new password anywhere else.
  • Leaving an attacker's recovery email or authenticator in place because the account "looks fine".
  • Paying someone who offers to trace the intruder or "lock" the account. The platform tools above cost nothing.

#If You Are Already Locked Out

Stop trying to guess passwords and go to the official recovery route from a device you have used before, which Facebook specifically recommends. For Facebook that is facebook.com/hacked, for Instagram instagram.com/hacked, and for Google the account recovery page, which Google says to use if someone changed your password or recovery phone number. Our guide to the first hour after an Instagram hack walks through that sequence, and if the email and phone were both changed, see recovering an account without your old email or phone.

#When Expert Recovery Help Makes Sense

If you worked through the steps above, you have done what the platforms ask, and you did it yourself. A second pair of eyes helps when the intrusions keep coming back, when a business or several accounts share one compromised inbox, or when the login has already turned into a lockout. SocialSafe by AwareXone is our recovery and account security service. We look at your situation first and tell you plainly whether you still need help. Our account security service explains what that review covers, and our Trust Center lists what we will never ask you for.

#Frequently Asked Questions

Does changing my password log out the other person?
On Instagram, yes: its help centre says updating your password logs you out of all other devices. On Facebook and Google, log out unknown sessions from "Where you're logged in" or "Manage all devices" as well, so nothing is left open.
Can someone log into my account without my password?
Yes, if they have a copy of an active session, access through a third-party app you connected, or control of your email inbox to reset the password. That is why logging out sessions, revoking apps and securing your email matter as much as the password.
Why does my login list show a city I have never been to?
Locations are often approximate, and mobile data or a VPN can place your own phone somewhere else. Check the device type and time as well; if you still cannot explain it, log it out and change your password.
Should I delete my account if someone logged in?
Usually not. Securing the account keeps your messages, contacts and recovery history, and deleting it does not undo anything the intruder already saw or sent.
Can AwareXone find out who logged into my account?
No. We do not trace or identify intruders, and login lists show only an approximate location. If money was lost, report it to NSRC on 997 and lodge a police report.

Official sources

Need help with your account?

Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: Account security.