Incident Playbook
Account Takeover
Summary
An unauthorised person has accessed or taken control of an email, messaging, social media or cloud account.
- Category
- Accounts and access
- Typical severity
- High
- Response led by
- Incident lead, with technical support and communications
First 15 minutes
- Use the platform's official recovery process from a trusted device. Search for it yourself rather than using links sent to you.
- Warn contacts on another channel not to trust messages from the account or send money.
- Once back in, change the password and sign out all other sessions and devices.
1. Overview
An account takeover is when someone else gains control of an email, social media, messaging or cloud account. They can read private messages and files, scam your contacts, post in your name, or lock you out entirely. Organisation accounts are especially valuable because of the trust and audience they carry.
2. How it happens
- Passwords reused across sites are tried on other services after a data leak (credential stuffing).
- People are tricked into sharing a verification code, often by someone posing as support staff.
- A SIM swap moves your phone number, and every SMS code, to the attacker's SIM.
- A phishing page captures a password, or malware steals saved passwords and session cookies.
- Sessions are left signed in on shared, borrowed, lost or seized devices.
- Former staff or volunteers still have access to shared accounts.
3. Indicators
Signs that this incident may be happening:
- Alerts about new log-ins, password changes or changed recovery details that you didn't make.
- Contacts receive messages, posts or payment requests you didn't send.
- You're suddenly logged out, or your password no longer works.
- Unfamiliar devices, apps or forwarding rules appear in your account settings.
- Your phone suddenly shows "No service" while others nearby have signal.
4. Triage questions
Answer these first to understand scope and severity:
- Which account is affected, and is it personal or organisational?
- Can the owner still log in?
- What can the account reach: email, files, contacts, payments, other accounts?
- Has the attacker sent messages, made posts, or changed settings?
- Is there any sign of a SIM swap (sudden loss of mobile service)?
5. Severity guide
Use your plan's severity levels. As a guide for this incident:
| Level | Typical situation |
|---|---|
| Low | Suspicious log-in attempt blocked; no access gained. |
| Medium | Access to a personal account with little organisational data, now recovered. |
| High | An organisational email or cloud account accessed, or a public account posting in your name. |
| Critical | Access to sensitive data, finances or admin accounts, or the account used to target partners or communities. |
6. Response steps
Work through these in order. Record every action, with the time and who did it, in your incident log.
- Use the platform's official recovery process from a trusted device. Search for it yourself rather than using links sent to you.
- Warn contacts on another channel not to trust messages from the account or send money.
- Once back in, change the password and sign out all other sessions and devices.
- Remove unknown recovery details, forwarding rules, connected apps and admins.
- If you suspect a SIM swap, call your mobile operator from another phone to block the SIM, and alert your bank.
- Turn on 2-step verification if it wasn't already on.
- Record what you see, with screenshots and times, before you change things.
7. Communication
Who to inform, and when:
- Incident lead and technical support, immediately.
- Contacts and followers, through other channels, warning them not to trust messages or send money.
- Partners or communities if the account was used to contact them.
- The platform, through its official reporting and recovery process.
- Your mobile operator and bank if a SIM swap is suspected.
8. Evidence to preserve
Keep these before making changes, wherever it's safe to do so:
- Screenshots of security alerts, unusual messages and posts.
- Account activity and log-in history, including IP addresses and devices.
- Changes made: recovery details, forwarding rules, connected apps, admins.
- The time the owner first noticed, and when access was lost or regained.
- Messages sent by the attacker, and who received them.
9. Recovery and review
- Check what the attacker read, sent, deleted or changed while they had access.
- Tell anyone affected, such as contacts who were sent scams or people whose data was in the account.
- Change passwords on any other account that shared the same password.
- Review admin access on all organisation accounts.
- Record the incident and how the attacker got in, and close that gap.
10. Prevention checklist
- Use a unique, strong password for every account, stored in a password manager.
- Turn on 2-step verification everywhere, preferring an authenticator app or security key over SMS.
- Set a PIN for two-step verification on messaging apps, and a SIM lock or port-out PIN with your mobile operator.
- Keep at least two trusted admins on organisation pages, and remove people who no longer need access.
- Keep recovery email addresses and phone numbers up to date, and store backup codes safely.
- Keep a list of every organisation account, who owns it and who has access.