Act from a trusted device and avoid irreversible changes before preserving the information already available.

01

Start with the connected identity

From a trusted device, secure the email address or identity provider connected to the affected service. Review recovery methods and active sessions before changing the compromised account itself.

02

Record what changed

Preserve provider alerts, unfamiliar login details, changed recovery information, messages, purchases, and the approximate time each event occurred.

03

Use the official recovery route

Navigate to the provider directly rather than following links in messages. Submit concise ownership evidence, retain case numbers, and treat unsolicited recovery offers as suspicious.

Remember

No legitimate recovery assessment requires your password, one-time code, wallet seed phrase, or private key. Verify providers independently.