Humanity · Recover In The Right Order

For being locked out, hacked, or holding a phone that is gone · 14 minutes

People do not lose their accounts because recovery is impossible. They lose them by doing the steps in the wrong order — resetting the bank while somebody else is still reading the email the reset link lands in.

Almost every account you own is reachable through one email address, and that email address is reachable through one phone number. That is the whole shape of the problem: there is an order, the order is not obvious, and the wrong order burns the routes you still had. This page does one narrow thing. You mark what you still hold — the number, a password, printed codes, a signed-in laptop, your ID — and which accounts you need back, and it works out the sequence: what can be done now, what is waiting on an earlier step, what has no route at all with what you hold, and which single missing thing is blocking the most.

The email is the keystonenearly every other reset lands in it
The number is the weak linka swapped SIM re-takes anything behind a text code
A new password evicts nobodysessions, forwarding rules and app passwords survive it
The one thing worth doing before you read any further: if a phone or a number is involved, ring the network and get the number locked. Everything behind a text-message code is currently somebody else's, and every minute of that is a minute in which a password change achieves nothing.

The order, worked out from what you still hold

Nothing is saved and nothing leaves the page. Mark the things you genuinely still have — not the ones you think you could get — and the accounts you need back. If money is moving right now, ring the bank's fraud number while you read.

What has happened?

What do you still hold?

What do you need back?

Why the order is the whole thing

Evicting somebody, which is not the same as changing the password

Do it in this order and it holds: password, sign out everywhere, then the settings sweep, then a new second factor. The reason the settings sweep comes after the sign-out is that a session with the settings page open can undo your work while you do it. And the reason a new second factor comes last is that adding one before the sweep just gives you a second thing to check.

When nothing you hold opens anything: the identity route

What genuinely cannot be recovered, and what to salvage instead

The twenty minutes that make all of this unnecessary

What people believe, and what is so

Believed

  • Change every password as fast as possible
  • Start with the bank, it matters most
  • A new password locks the intruder out
  • Text-message codes are two-factor, so I am covered
  • Delete the hacked account and start again
  • The provider will restore my password manager vault
  • If nothing I have works, nothing can be done

Actually

  • Change them in dependency order, email first
  • The bank reset emails a link to the compromised inbox
  • Sessions, forwarding rules and app passwords survive it
  • A number can be moved to another SIM by a stranger
  • Deleting destroys the route back and the evidence
  • They cannot read your vault, so they cannot restore it
  • ID at a phone shop and the provider's form both work

The drill: 16 lockouts

Sixteen ordinary evenings — the stolen phone with the authenticator on it, the reset email that never arrived because a filter was deleting them, the friend whose account is messaging everybody, the vault whose master password is gone. Each has an obvious first move that costs you the account. Pick the order; every answer explains why.

The card

Print it, fill in the top two lines now, and put it with your passport. It is worth more before anything happens than after.

LOCKED OUT: THE ORDER

FILL IN NOW, WHILE YOU CAN

  • Main email address: ____________________________
  • Second address I control: ____________________________
  • Recovery codes are kept: ____________________________
  • Network / phone account PIN set? ______ Port freeze? ______

IF IT HAPPENS, IN THIS ORDER

  • 1. Network: lock the number. 2. A clean device to work from.
  • 3. The email account. 4. Sign out everywhere. 5. The settings sweep.
  • 6. Platform account (Apple/Google). 7. Bank by card and counter, not by email.
  • 8. Social and shopping. 9. Work IT desk. 10. Tell your contacts.

THE SWEEP, AFTER THE PASSWORD

  • Sign out of all sessions · forwarding rules · filters that delete
  • Recovery addresses and numbers · app passwords · connected apps
  • Enrolled authenticators and passkeys · login history

DO NOT

  • Do not delete the account. Do not reset from the suspect device.
  • Do not reset the bank before the email. Do not reuse the leaked password.
The email is the keystone, the number is the weak link, and a new password on its own evicts nobody.