For being locked out, hacked, or holding a phone that is gone · 14 minutes
People do not lose their accounts because recovery is impossible. They lose them by doing the steps in the wrong order — resetting the bank while somebody else is still reading the email the reset link lands in.
Almost every account you own is reachable through one email address, and that email address is reachable through one phone number. That is the whole shape of the problem: there is an order, the order is not obvious, and the wrong order burns the routes you still had. This page does one narrow thing. You mark what you still hold — the number, a password, printed codes, a signed-in laptop, your ID — and which accounts you need back, and it works out the sequence: what can be done now, what is waiting on an earlier step, what has no route at all with what you hold, and which single missing thing is blocking the most.
The email is the keystonenearly every other reset lands in it
The number is the weak linka swapped SIM re-takes anything behind a text code
A new password evicts nobodysessions, forwarding rules and app passwords survive it
The one thing worth doing before you read any further: if a phone or a number is involved, ring the network and get the number locked. Everything behind a text-message code is currently somebody else's, and every minute of that is a minute in which a password change achieves nothing.
The order, worked out from what you still hold
Nothing is saved and nothing leaves the page. Mark the things you genuinely still have — not the ones you think you could get — and the accounts you need back. If money is moving right now, ring the bank's fraud number while you read.
What has happened?
What do you still hold?
What do you need back?
Why the order is the whole thing
One account is the master key. Your main email is where the reset links for everything else arrive. So do not start with the bank, the shopping account or the social account: that sends a fresh set of keys to whoever is holding the inbox.
The phone number is the softest second factor there is. A number can be moved to a new SIM by somebody with a plausible story and a few of your details, and text-message codes then arrive at their phone. That is why the first call is to the network and not to the bank.
Changing a password does not remove anybody. Existing sessions can survive it, and so can a forwarding rule, a filter that deletes the alerts, an added recovery address, an app password, a connected app, and a second authenticator the attacker enrolled. The eviction is a separate job from the password.
The reset you cannot undo is the one done from the compromised device. If a phone or laptop might have something on it, every password typed into it is the next password they get. Use a different device, or a device you have just reinstalled.
Deleting the hacked account destroys the way back in. It also destroys the evidence, the message history somebody may need, and any chance the provider can help. Suspend, lock, revoke — do not delete.
The slow route exists and it is worth starting early. Every large provider has an identity-based recovery process for people with nothing left. It takes days, it is worth beginning on day one rather than day four, and it needs a second address, ID, and the details of the account's own history.
Evicting somebody, which is not the same as changing the password
Sign out everywhere. Every provider has a list of active sessions and devices, and a button that ends all of them. Do this after the password change, not before, or the new password walks straight into the old session.
Read the forwarding, the filters and the rules. A single forwarding rule keeps a copy of every message flowing after you have locked everything else. Filters that delete security alerts are the second thing to look for.
Check the recovery addresses and phone numbers on the account. An added one is a permanent way back in, and it is the single most commonly missed item on this list.
Revoke app passwords and connected apps. Anything that logs in without a second factor — old mail clients, third-party apps, calendar and file integrations — keeps working after every password change until it is revoked.
Look at the second factors themselves. An extra authenticator, an extra passkey, a printed set of codes that is not yours: enrolled second factors are the quiet way an attacker keeps an account they have been evicted from.
Then change the password, on a clean device, to something not used anywhere else. And check the account's own security or login history afterwards, because it tells you whether you actually finished.
Do it in this order and it holds: password, sign out everywhere, then the settings sweep, then a new second factor. The reason the settings sweep comes after the sign-out is that a session with the settings page open can undo your work while you do it. And the reason a new second factor comes last is that adding one before the sweep just gives you a second thing to check.
When nothing you hold opens anything: the identity route
Start the provider's own recovery form on day one. It is slow, it is often the only route, and the clock starts when you file it rather than when you give up on the other ways.
Have the account's history ready. Roughly when it was created, the last password you remember, recovery addresses you set, the devices you used, a payment made through it, an old label or folder name. Providers weigh these, and vague answers are what fail.
Use a second address you control for the reply. If you do not have one, make one first, on a clean device, with a second factor that is not a text message.
The phone shop is the fastest counter of all. ID in person usually puts your number on a new SIM the same day, and that alone re-opens every reset that runs by text.
Banks and work accounts do not need the email at all. A card and ID at a counter, or the fraud line; and an IT desk that can lock and reissue in minutes. Both of these are worth doing in parallel rather than after.
Tell the people who will be targeted next. The account being used is being used against your contacts, and a one-line message to them is faster than any recovery process.
What genuinely cannot be recovered, and what to salvage instead
A password manager's master password. The whole point of the design is that the provider cannot read your vault, which means they cannot restore it either. The emergency kit, the recovery code you printed at setup, or a second person with emergency access are the only routes; without them the vault is gone and the work is resetting every account it held, in this page's order.
A cryptocurrency seed phrase. There is no recovery, no support desk and no reversal, and anybody offering to recover one is running the second scam on top of the first.
An account whose email address no longer exists. If the address was with a provider you have left, or a domain that lapsed, the reset has nowhere to go and the provider's identity route is the only way.
Money already sent by bank transfer. Sometimes recallable in the first hours, often not; the fraud line and the reporting reference matter for the reimbursement question, which is separate from the recovery question.
Messages, photos and files deleted by whoever got in. Some providers keep a recycle bin for weeks. That is worth checking early, because the window closes quietly.
The time this takes. Every hour spent guessing passwords is an hour not spent on the two things that always work: the phone shop with your ID, and the provider's own form.
The twenty minutes that make all of this unnecessary
Print the recovery codes for your main email and keep them where you keep your passport. This is the single highest-value thing on the page. Codes bypass every second factor, they cost nothing, and they work when your phone is at the bottom of a canal.
Move off text-message codes for the email and the bank. An authenticator app or a passkey cannot be taken by moving your number. Keep a text-message fallback only where nothing else is offered.
Put a PIN or a port freeze on the phone account. One phone call, and it is the difference between a SIM swap being a phone call and being impossible.
Set a second email address you control as the recovery address — and check it still exists. A recovery address pointing at an account you abandoned is worse than none, because it looks like a route and is not.
Write down which accounts sit behind which email. Not the passwords: the list. It is what turns a two-week recovery into an afternoon, and it is the thing nobody has when they need it.
Tell one other person where the codes are. The emergency-access feature in a password manager, or an envelope. Somebody being unreachable is the other way this becomes unrecoverable.
What people believe, and what is so
Believed
Change every password as fast as possible
Start with the bank, it matters most
A new password locks the intruder out
Text-message codes are two-factor, so I am covered
Delete the hacked account and start again
The provider will restore my password manager vault
If nothing I have works, nothing can be done
Actually
Change them in dependency order, email first
The bank reset emails a link to the compromised inbox
Sessions, forwarding rules and app passwords survive it
A number can be moved to another SIM by a stranger
Deleting destroys the route back and the evidence
They cannot read your vault, so they cannot restore it
ID at a phone shop and the provider's form both work
The drill: 16 lockouts
Sixteen ordinary evenings — the stolen phone with the authenticator on it, the reset email that never arrived because a filter was deleting them, the friend whose account is messaging everybody, the vault whose master password is gone. Each has an obvious first move that costs you the account. Pick the order; every answer explains why.
The card
Print it, fill in the top two lines now, and put it with your passport. It is worth more before anything happens than after.
LOCKED OUT: THE ORDER
FILL IN NOW, WHILE YOU CAN
Main email address: ____________________________
Second address I control: ____________________________
Recovery codes are kept: ____________________________
Network / phone account PIN set? ______ Port freeze? ______
IF IT HAPPENS, IN THIS ORDER
1. Network: lock the number. 2. A clean device to work from.
3. The email account. 4. Sign out everywhere. 5. The settings sweep.
6. Platform account (Apple/Google). 7. Bank by card and counter, not by email.
8. Social and shopping. 9. Work IT desk. 10. Tell your contacts.
THE SWEEP, AFTER THE PASSWORD
Sign out of all sessions · forwarding rules · filters that delete
Recovery addresses and numbers · app passwords · connected apps
Enrolled authenticators and passkeys · login history
DO NOT
Do not delete the account. Do not reset from the suspect device.
Do not reset the bank before the email. Do not reuse the leaked password.
The email is the keystone, the number is the weak link, and a new password on its own evicts nobody.