Recovering a Hacked Email or Social Media Account: The NCSC’s Step-by-Step Guide

Losing access to an email, social media or shopping account can be stressful, and a hacked account is often used to reach other accounts and contacts. The National Cyber Security Centre (NCSC), the UK government’s technical authority for cyber security, publishes a step-by-step recovery guide, first published on 17 December 2018 and last reviewed on 24 August 2022, alongside separate advice on 2-step verification. This article summarises both. It applies UK-wide, with the reporting route for Scotland noted below.

How to tell an account has been hacked

The NCSC advises checking online accounts for unauthorised activity. Signs it lists include:

  • being unable to log in;
  • changes to security settings;
  • messages or notifications sent from the account that the owner does not recognise;
  • logins or attempted logins from strange locations or at unusual times;
  • unauthorised money transfers or purchases from online accounts.

Step 1: contact the account provider

The NCSC says to go to the provider’s website and search its help or support pages, since the recovery process is likely to differ for each account. If nothing is found, a search-engine query such as “How do I recover my Twitter account” can lead to the right instructions.

Step 2: check the email account

The NCSC says to check email filters and forwarding rules. A common tactic used by cyber criminals is to set up a forwarding rule, so that a copy of every email sent to the account is automatically sent to them, which would allow them to reset passwords. The guide notes that detailed instructions can be found on the email provider’s website.

Step 3: change passwords, in the right order

Once it is confirmed there are no unwanted forwarding rules, the NCSC says to change the password for the hacked account and for any other account using the same password. Both steps matter because criminals know many people reuse passwords and will try the hacked password across multiple accounts.

Step 4: log out every device and app

After changing passwords, the NCSC says to log all devices and apps out of the account, usually from the settings, privacy or account options, so that anyone still logged in is prompted for the new password.

Step 5: turn on 2-step verification

The NCSC says 2-step verification (2SV), also called two-factor authentication or 2FA, means that even if a criminal knows a password they will not be able to access the account. Its separate guidance calls turning on 2SV one of the most effective ways to protect online accounts, and says the most important accounts, such as email, banking, social media and online shopping, should be protected. It explains that after setup, a PIN or code, often sent by SMS or email, must be entered to prove identity, and that other forms include a fingerprint, face scan or authenticator app. A mobile phone is not essential: some organisations allow a landline number, a separate device such as a card reader or a USB stick. Depending on the setup, the code may only be needed when suspicious activity is detected, such as a login from a different device or a request to change the password. A related guide on this site covers passwords, 2FA and data breaches.

The NCSC also explains why passwords can be stolen even when strong. The most common way, it says, is when an organisation holding a person’s details suffers a data breach, after which criminals try the stolen passwords on other accounts, a technique known as “credential stuffing”. Criminals may also trick people into revealing passwords by sending links to scam websites by email, text or direct message.

Steps 6 to 9: updates, contacts, money and reporting

  • Update devices. The NCSC says to apply app and software updates as soon as available and to turn on automatic updates if possible.
  • Notify contacts. Friends and followers should be told about the hack and advised to treat recent messages from the account with suspicion.
  • Check bank statements and shopping accounts. A hacked email account can lead to compromises elsewhere, so unauthorised purchases and unusual transactions should be looked for, using official websites or app, or typing the address directly, not links in messages.
  • Report it. If money has been lost, the NCSC says to tell the bank and report the crime to Report Fraud, and in Scotland to contact the police by dialling 101.

Other routes for reporting scams are covered in where to report a scam in the UK.

If the account cannot be recovered

The NCSC says that in some cases recovery with the online service is not possible and a new account has to be created. Contacts should then be given the new details and told the old account has been abandoned, and bank, utility and shopping websites should be updated with the new details.

The bottom line

The NCSC’s guidance follows a clear order: contact the provider, look for email forwarding rules, change passwords, log out all devices, turn on 2-step verification, update devices, warn contacts, watch bank and shopping accounts and report any loss. The forwarding-rule check and the reuse of passwords are the two easily missed points, and 2-step verification is the single step that most reduces the chance of a repeat.

Sources