When an account is taken over.
WHAT INDICATES IT
Sign-ins from unexpected locations Actions the person did not perform Changes to recovery details Messages sent that they did not send Reports from others
WHY CHANGED RECOVERY DETAILS
It is the first thing an attacker alters, to retain access.
WHAT TO DO IMMEDIATELY
Disable the account or force a sign-out Change the password Reset the second factor Check and correct recovery details Review what the account could reach
WHY THE SECOND FACTOR
An attacker may have registered their own.
WHAT TO CHECK
Whether additional factors or devices were added Whether forwarding or rules were created Whether permissions were granted Whether other accounts were accessed from it
WHY FORWARDING RULES
They are a standard method of retaining access to communications after the account is recovered.
WHAT TO ESTABLISH
What the account accessed during the period.
WHY
It determines the scope of the incident.
WHAT TO ASSESS
What data was reachable Whether anything was taken Whether other accounts were reached Whether payments or changes were made
WHAT TO DO ABOUT OTHER ACCOUNTS
Assume any credential stored or accessible from that account is compromised.
WHAT TO CHANGE
Those, too.
WHAT TO ESTABLISH ABOUT NOTIFICATION
Whether you must inform anyone.
WHY
Personal data exposure carries notification obligations with short deadlines.
WHAT TO RECORD
Everything, with times.
WHAT TO ADDRESS
How the compromise occurred.
WHAT THE USUAL CAUSES ARE
Reused password exposed elsewhere A deceptive message obtaining credentials No second factor Credentials in a shared location