← All playbooks

Incident Playbook

Account Takeover

SIIRF-PB-02Accounts and accessTypical severity: HighVersion 1.0 · October 2026

Summary

An unauthorised person has accessed or taken control of an email, messaging, social media or cloud account.

Category
Accounts and access
Typical severity
High
Response led by
Incident lead, with technical support and communications

First 15 minutes

  1. Use the platform's official recovery process from a trusted device. Search for it yourself rather than using links sent to you.
  2. Warn contacts on another channel not to trust messages from the account or send money.
  3. Once back in, change the password and sign out all other sessions and devices.

1. Overview

An account takeover is when someone else gains control of an email, social media, messaging or cloud account. They can read private messages and files, scam your contacts, post in your name, or lock you out entirely. Organisation accounts are especially valuable because of the trust and audience they carry.

2. How it happens

  • Passwords reused across sites are tried on other services after a data leak (credential stuffing).
  • People are tricked into sharing a verification code, often by someone posing as support staff.
  • A SIM swap moves your phone number, and every SMS code, to the attacker's SIM.
  • A phishing page captures a password, or malware steals saved passwords and session cookies.
  • Sessions are left signed in on shared, borrowed, lost or seized devices.
  • Former staff or volunteers still have access to shared accounts.

3. Indicators

Signs that this incident may be happening:

  • Alerts about new log-ins, password changes or changed recovery details that you didn't make.
  • Contacts receive messages, posts or payment requests you didn't send.
  • You're suddenly logged out, or your password no longer works.
  • Unfamiliar devices, apps or forwarding rules appear in your account settings.
  • Your phone suddenly shows "No service" while others nearby have signal.

4. Triage questions

Answer these first to understand scope and severity:

  1. Which account is affected, and is it personal or organisational?
  2. Can the owner still log in?
  3. What can the account reach: email, files, contacts, payments, other accounts?
  4. Has the attacker sent messages, made posts, or changed settings?
  5. Is there any sign of a SIM swap (sudden loss of mobile service)?

5. Severity guide

Use your plan's severity levels. As a guide for this incident:

LevelTypical situation
LowSuspicious log-in attempt blocked; no access gained.
MediumAccess to a personal account with little organisational data, now recovered.
HighAn organisational email or cloud account accessed, or a public account posting in your name.
CriticalAccess to sensitive data, finances or admin accounts, or the account used to target partners or communities.

6. Response steps

Work through these in order. Record every action, with the time and who did it, in your incident log.

  1. Use the platform's official recovery process from a trusted device. Search for it yourself rather than using links sent to you.
  2. Warn contacts on another channel not to trust messages from the account or send money.
  3. Once back in, change the password and sign out all other sessions and devices.
  4. Remove unknown recovery details, forwarding rules, connected apps and admins.
  5. If you suspect a SIM swap, call your mobile operator from another phone to block the SIM, and alert your bank.
  6. Turn on 2-step verification if it wasn't already on.
  7. Record what you see, with screenshots and times, before you change things.

7. Communication

Who to inform, and when:

  • Incident lead and technical support, immediately.
  • Contacts and followers, through other channels, warning them not to trust messages or send money.
  • Partners or communities if the account was used to contact them.
  • The platform, through its official reporting and recovery process.
  • Your mobile operator and bank if a SIM swap is suspected.

8. Evidence to preserve

Keep these before making changes, wherever it's safe to do so:

  • Screenshots of security alerts, unusual messages and posts.
  • Account activity and log-in history, including IP addresses and devices.
  • Changes made: recovery details, forwarding rules, connected apps, admins.
  • The time the owner first noticed, and when access was lost or regained.
  • Messages sent by the attacker, and who received them.

9. Recovery and review

  • Check what the attacker read, sent, deleted or changed while they had access.
  • Tell anyone affected, such as contacts who were sent scams or people whose data was in the account.
  • Change passwords on any other account that shared the same password.
  • Review admin access on all organisation accounts.
  • Record the incident and how the attacker got in, and close that gap.

10. Prevention checklist

  • Use a unique, strong password for every account, stored in a password manager.
  • Turn on 2-step verification everywhere, preferring an authenticator app or security key over SMS.
  • Set a PIN for two-step verification on messaging apps, and a SIM lock or port-out PIN with your mobile operator.
  • Keep at least two trusted admins on organisation pages, and remove people who no longer need access.
  • Keep recovery email addresses and phone numbers up to date, and store backup codes safely.
  • Keep a list of every organisation account, who owns it and who has access.