Once you suspect a real breach, speed matters. You do not need a perfect plan. You need the right order.

Start here:

  1. secure the email account if possible
  2. change the password from a trusted device
  3. check recovery email, phone, and trusted devices
  4. sign out other sessions if the service allows it
  5. change passwords on linked critical accounts

If you cannot get into the email, use the service’s recovery tools immediately. Save any confirmation screens or messages.

This level is different because the goal is not just “avoid the phish.” The goal is “contain the spread.”

A quick example: you see messages leaving your email that you did not send. Start with email recovery and linked accounts first, not with less critical sites.

What to do:

  • Work from highest-leverage account outward.
  • Use a trusted device and official sites only.
  • Document what changed and when.

This lesson is part of Email & Online Accounts from Lumoset Foundation, Fort Wayne, Indiana – free, always, with no account and no catch.