Your Parent's Account Was Hacked: The 60-Minute Response
Someone got into a parent's email, bank, or phone account. The next hour decides how bad this gets: here's the order of operations, and what to say so they tell you about the next one instead of hiding it.
contain before investigate
The compromised account map
The account may be under someone else's control. The sequence is containment first from a trusted device, email first when it is affected, and the 60-minute order that locks the doors before investigating.
- Do this firstContain from a trusted deviceUse a different, trusted device and the provider's official app or typed address, then start its account-recovery process. Do not use a link or number from the alert, and never reuse the new password elsewhere.
- Email firstBecause email unlocks the restIf email is compromised, recover it first: reset with a long unique password, review devices and sign out everything unfamiliar, and check for forwarding rules that quietly copy mail to the attacker.
- The 60-minute orderPhone, banks, freezeCall the carrier about a possible SIM swap and add port-out protection, change the online banking password and call the number on the card, and consider a free credit freeze at the three bureaus.
- What to preserveEvidence, not passwordsKeep alert emails, screenshots, dates, unfamiliar devices, and forwarding rules, and follow the scam recovery plan if money, a code, or remote access was shared.
What happened
An email, bank, shopping, or phone account may be under someone else's control
Contain the account from a trusted device before investigating how it happened. If email is involved, recover that first because it may control password resets for other accounts.
Do this first
Use a different, trusted device. Open the provider's official app or type its address yourself, then start its account-recovery process.
Do not do this
Do not use a link or phone number from the alert, confront the intruder, delete evidence, or reuse the new password anywhere else.
Buy anything?
No. Start with the provider's free recovery controls. A paid security product cannot replace account recovery, sign-out, and checking what changed.
What to preserve
Keep alert emails, screenshots, dates, unfamiliar devices or forwarding rules, changed recovery details, and any transaction records. Never put passwords or verification codes in the family notes.
Choose the account that unlocks the others
- Email is compromised: recover email first, replace unknown recovery details and forwarding rules, sign out other sessions, then reset any account that used the same password or received a suspicious reset.
- Email is secure and another account is compromised: recover that account through the provider's official app or website, sign out other sessions, review changes and transactions, then replace any reused password.
- The phone suddenly lost service: call the carrier from another phone using its official number and report a possible SIM swap. Ask the carrier to restore service and add an account PIN or port-out protection.
- Money, a code, or remote access was shared: use the scam recovery plan as well. Account containment does not replace contacting the bank or payment company.
Send the part they need
Why email first
Many accounts use email for password resets, alerts, and verification. An attacker who controls that mailbox may be able to reset other accounts, which is why email comes first when it is affected.
The 60-minute sequence
- Use a device you trust. Use a different personal device, not the phone or computer that may be compromised. If remote-access software was installed on the affected device, disconnect it from the internet until the software is removed and the device is checked.
- Lock the email. Use "forgot password" on a trusted device to reset it, or the account-recovery flow. Change to a long, unique password. Use the provider's security settings to review devices and sign out sessions you do not recognize; if it offers a sign-out-everywhere control, use it.
- Check for forwarding rules. Attackers quietly add rules that forward copies of incoming mail to themselves: check settings for any forwarding address that isn't theirs, and delete it. Also check recovery phone/email and change them if tampered with.
- Lock the phone account. Call the carrier and ask what account PIN, number-lock, or port-out protection it supports. If the phone suddenly lost service without an expected outage, report a possible SIM swap immediately.
- Banks and cards. Change the online banking password, then call the number on the back of the card (or visit a branch) and tell them the account was compromised. Ask what they see: new payees, transfers, changed contact info. Freeze cards if anything looks wrong.
- Credit freeze. If the attacker obtained information that could be used for identity theft, consider a free credit freeze at Equifax, Experian, and TransUnion. The FTC's credit freeze guidance explains what a freeze does and how to place one.
- Change the important passwords. Email, bank, phone carrier, and anything with saved payment methods. The family vault guide has the full setup, but even just unique passwords on these four is a huge step up.
- Turn on two-factor for the email and bank, using the strongest method the provider supports and a phone number or device the attacker does not control. This adds an important barrier if a password is exposed again.
What to check in the following days
- Sent mail and deleted items: attackers often use the account to send phishing from the parent's own address (to their contacts!). Warn contacts if you see that.
- Saved payment methods: remove any card the parent doesn't recognize from shopping accounts.
- Account contact info: confirm the recovery phone/email on each important account is the parent's, not the attacker's.
- Statements for the next 2-3 months: small test charges sometimes come before the big ones.
- The phone bill: new lines or device changes on a shared plan can mean the carrier account was used.
The conversation that matters most
How you react can make it easier or harder for a parent to tell you about the next attempt. Keep the conversation focused on recovery instead of blame:
- "You did nothing wrong: you were targeted." A compromised account is a security incident, not a character test.
- "Thank you for telling me." This is the sentence that saves the next account.
- "We're fixing it together, and here's the rule from now on." One rule: if a call or message asks for codes, money, or account info, hang up and call back on a number you looked up yourself. See the full playbook for the rest.
And if money was already moved: don't try to recover it alone. Follow the scam recovery guide, which covers the payment-channel-specific steps and reporting in order.
Prevent the next one
- Set up the family password vault: unique passwords everywhere, recovery chain in place.
- Teach the verify-independently habit: do not trust contact details supplied by an unexpected message.
- Set up the family safe word, for the voice-clone follow-up that often arrives after a hack.
- Run the Scam Risk Check: check the next suspicious message before acting on it.
Sources & verification
This page is checked against the standards in our editorial policy, preferring government sources for security guidance. Reviewed August 2026:
- CISA: Use Strong Passwords (retrieved August 2026)
- FTC: Credit Freezes and Fraud Alerts (retrieved August 2026)
- FTC: What To Do If You Were Scammed (retrieved August 2026)
- FBI IC3: Internet Crime Complaint Center (retrieved August 2026)
Found an error? Report it: we log and correct material mistakes publicly.