A security notification.
WHAT TO DO IMMEDIATELY
If it was not you, change the password for that account now.
Enable two-factor authentication if it is not already active.
Check for changes: new administrator users, altered settings, unfamiliar files, new cron jobs.
IF IT WAS YOU
Confirm the location and device make sense. Mobile networks frequently show unexpected locations, which is normal.
CHECKING FOR DAMAGE
Review the user list in your application. Any administrator you do not recognise is a compromise.
Check recently modified files in File Manager, sorted by date.
Check cron jobs for entries you did not add.
Run a malware scan.
IF YOU FIND ANYTHING
Treat it as a full compromise: change every credential, clean thoroughly, close the entry point.
PREVENTING IT
Two-factor authentication on hosting, application administrators, email and your domain registrar.
Unique passwords everywhere. A password reused from a breached service is the most common route in.