Illustration of a focused adult child at a desk with a laptop and phone while an older parent stands beside them with a hand on the desk

the next hour decides how bad this gets

The 60-minute response starts with the password, not the panic.

Someone got into a parent's email, bank, or phone account. The order of operations in the first hour contains the damage: secure the account, check what was touched, and make it safe to tell you about the next one.

Your Parent's Account Was Hacked: The 60-Minute Response

Someone got into a parent's email, bank, or phone account. The next hour decides how bad this gets: here's the order of operations, and what to say so they tell you about the next one instead of hiding it.

Last reviewed August 2026 Reading time: 9 minutes

contain before investigate

The compromised account map

The account may be under someone else's control. The sequence is containment first from a trusted device, email first when it is affected, and the 60-minute order that locks the doors before investigating.

  1. Do this firstContain from a trusted deviceUse a different, trusted device and the provider's official app or typed address, then start its account-recovery process. Do not use a link or number from the alert, and never reuse the new password elsewhere.
  2. Email firstBecause email unlocks the restIf email is compromised, recover it first: reset with a long unique password, review devices and sign out everything unfamiliar, and check for forwarding rules that quietly copy mail to the attacker.
  3. The 60-minute orderPhone, banks, freezeCall the carrier about a possible SIM swap and add port-out protection, change the online banking password and call the number on the card, and consider a free credit freeze at the three bureaus.
  4. What to preserveEvidence, not passwordsKeep alert emails, screenshots, dates, unfamiliar devices, and forwarding rules, and follow the scam recovery plan if money, a code, or remote access was shared.

What happened

An email, bank, shopping, or phone account may be under someone else's control

Contain the account from a trusted device before investigating how it happened. If email is involved, recover that first because it may control password resets for other accounts.

Do this first

Use a different, trusted device. Open the provider's official app or type its address yourself, then start its account-recovery process.

Do not do this

Do not use a link or phone number from the alert, confront the intruder, delete evidence, or reuse the new password anywhere else.

Buy anything?

No. Start with the provider's free recovery controls. A paid security product cannot replace account recovery, sign-out, and checking what changed.

What to preserve

Keep alert emails, screenshots, dates, unfamiliar devices or forwarding rules, changed recovery details, and any transaction records. Never put passwords or verification codes in the family notes.

Choose the account that unlocks the others

  • Email is compromised: recover email first, replace unknown recovery details and forwarding rules, sign out other sessions, then reset any account that used the same password or received a suspicious reset.
  • Email is secure and another account is compromised: recover that account through the provider's official app or website, sign out other sessions, review changes and transactions, then replace any reused password.
  • The phone suddenly lost service: call the carrier from another phone using its official number and report a possible SIM swap. Ask the carrier to restore service and add an account PIN or port-out protection.
  • Money, a code, or remote access was shared: use the scam recovery plan as well. Account containment does not replace contacting the bank or payment company.

Send the part they need

Text to Mom or Dad

Thank you for telling me. Please stop using that account for now and do not click any more alert links. We will use a different device, open the real provider ourselves, and recover it together. Please keep the messages and screenshots, but do not send me a password or verification code.

Text to a sibling

I am recovering Mom/Dad's affected account from a trusted device. Please make a checklist of the other accounts tied to that email or reused password, note any unfamiliar transactions or setting changes, and contact the phone carrier if service disappeared. Do not ask for or record passwords or codes. Reply with completed tasks and anything that still needs an owner.

Why email first

Many accounts use email for password resets, alerts, and verification. An attacker who controls that mailbox may be able to reset other accounts, which is why email comes first when it is affected.

The 60-minute sequence

  1. Use a device you trust. Use a different personal device, not the phone or computer that may be compromised. If remote-access software was installed on the affected device, disconnect it from the internet until the software is removed and the device is checked.
  2. Lock the email. Use "forgot password" on a trusted device to reset it, or the account-recovery flow. Change to a long, unique password. Use the provider's security settings to review devices and sign out sessions you do not recognize; if it offers a sign-out-everywhere control, use it.
  3. Check for forwarding rules. Attackers quietly add rules that forward copies of incoming mail to themselves: check settings for any forwarding address that isn't theirs, and delete it. Also check recovery phone/email and change them if tampered with.
  4. Lock the phone account. Call the carrier and ask what account PIN, number-lock, or port-out protection it supports. If the phone suddenly lost service without an expected outage, report a possible SIM swap immediately.
  5. Banks and cards. Change the online banking password, then call the number on the back of the card (or visit a branch) and tell them the account was compromised. Ask what they see: new payees, transfers, changed contact info. Freeze cards if anything looks wrong.
  6. Credit freeze. If the attacker obtained information that could be used for identity theft, consider a free credit freeze at Equifax, Experian, and TransUnion. The FTC's credit freeze guidance explains what a freeze does and how to place one.
  7. Change the important passwords. Email, bank, phone carrier, and anything with saved payment methods. The family vault guide has the full setup, but even just unique passwords on these four is a huge step up.
  8. Turn on two-factor for the email and bank, using the strongest method the provider supports and a phone number or device the attacker does not control. This adds an important barrier if a password is exposed again.

What to check in the following days

  • Sent mail and deleted items: attackers often use the account to send phishing from the parent's own address (to their contacts!). Warn contacts if you see that.
  • Saved payment methods: remove any card the parent doesn't recognize from shopping accounts.
  • Account contact info: confirm the recovery phone/email on each important account is the parent's, not the attacker's.
  • Statements for the next 2-3 months: small test charges sometimes come before the big ones.
  • The phone bill: new lines or device changes on a shared plan can mean the carrier account was used.

The conversation that matters most

How you react can make it easier or harder for a parent to tell you about the next attempt. Keep the conversation focused on recovery instead of blame:

  1. "You did nothing wrong: you were targeted." A compromised account is a security incident, not a character test.
  2. "Thank you for telling me." This is the sentence that saves the next account.
  3. "We're fixing it together, and here's the rule from now on." One rule: if a call or message asks for codes, money, or account info, hang up and call back on a number you looked up yourself. See the full playbook for the rest.

And if money was already moved: don't try to recover it alone. Follow the scam recovery guide, which covers the payment-channel-specific steps and reporting in order.

Prevent the next one

The next thing your family needs

Give every critical account a unique password and a recovery owner

Once the affected account is contained, remove the shared-password chain that can turn one compromise into several.

Set up the family password vault

Then: practice independent verification, set a family safe word, or check the next suspicious message.

Sources & verification

This page is checked against the standards in our editorial policy, preferring government sources for security guidance. Reviewed August 2026:

Found an error? Report it: we log and correct material mistakes publicly.