Knowledgebase

Handling Compromised Accounts Print

  • 0

When an account is taken over.

WHAT INDICATES IT

Sign-ins from unexpected locations Actions the person did not perform Changes to recovery details Messages sent that they did not send Reports from others

WHY CHANGED RECOVERY DETAILS

It is the first thing an attacker alters, to retain access.

WHAT TO DO IMMEDIATELY

Disable the account or force a sign-out Change the password Reset the second factor Check and correct recovery details Review what the account could reach

WHY THE SECOND FACTOR

An attacker may have registered their own.

WHAT TO CHECK

Whether additional factors or devices were added Whether forwarding or rules were created Whether permissions were granted Whether other accounts were accessed from it

WHY FORWARDING RULES

They are a standard method of retaining access to communications after the account is recovered.

WHAT TO ESTABLISH

What the account accessed during the period.

WHY

It determines the scope of the incident.

WHAT TO ASSESS

What data was reachable Whether anything was taken Whether other accounts were reached Whether payments or changes were made

WHAT TO DO ABOUT OTHER ACCOUNTS

Assume any credential stored or accessible from that account is compromised.

WHAT TO CHANGE

Those, too.

WHAT TO ESTABLISH ABOUT NOTIFICATION

Whether you must inform anyone.

WHY

Personal data exposure carries notification obligations with short deadlines.

WHAT TO RECORD

Everything, with times.

WHAT TO ADDRESS

How the compromise occurred.

WHAT THE USUAL CAUSES ARE

Reused password exposed elsewhere A deceptive message obtaining credentials No second factor Credentials in a shared location


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot