Seeing an unknown device signed in to an important account is a high-risk warning that someone else may have access to your email, bank, cloud drive, or social media. Quick, correct action can lock them out before they change recovery settings or move money. This guide shows you what to do immediately, how to investigate safely, and how to harden your accounts so it does not happen again.
First: Confirm What You’re Seeing
Before you act, make sure the “unknown device” really is unfamiliar and not simply mislabeled by the service.
- Check the device name, operating system, browser, IP location, and last active time. Many services show this in “Security,” “Devices,” or “Where you’re signed in.”
- Compare with your actual usage: Did you log in from a hotel or mobile hotspot? Did you recently reinstall a browser or use private browsing? These can change the signature.
- When in doubt, treat it as unauthorized. It is safer to remove a legitimate session than to leave a bad one active.
Immediate Actions to Lock Out Intruders
Every minute matters. Prioritize shutting off access, then changing credentials and securing recovery paths.
- Revoke all active sessions
- Use “Sign out of all devices,” “Log out everywhere,” or “Remove device.” This invalidates tokens that keep an attacker logged in even if they don’t know your new password.
- Change the password from a safe, uncompromised device
- Use a strong, unique password you haven’t used anywhere else. Consider a password manager to generate and store it.
- If the device you’re using might be compromised, change the password from a separate, trusted device.
- Enable or strengthen two-factor authentication (2FA)
- Prefer an authenticator app or a hardware security key over SMS. Attackers can trick SMS or intercept codes.
- If available, add passkeys or security keys, which resist phishing and token theft.
- Update recovery methods
- Verify recovery email and phone number are yours and current.
- Remove any unfamiliar backup codes, devices, or additional recovery addresses.
- Check and remove suspicious app connections
- Review “Connected apps,” “Third-party access,” “OAuth tokens,” or “API keys.” Revoke anything you do not recognize or no longer use.
What If You’re Locked Out?
If the attacker changed your password or recovery settings, use the account’s official recovery process immediately.
- Use “Forgot password” and choose the most secure recovery path available.
- If recovery fails, contact the provider’s support with proof of identity and account ownership (billing info, IDs where applicable, old recovery codes).
- Act fast if it’s a financial or work account. For banks and brokerages, call the fraud line, freeze transactions if possible, and document the timeline.
Investigate: What Could Have Let Them In?
Understanding the root cause helps you prevent a repeat incident.
- Phishing or social engineering: Did you click a link and enter credentials recently? Were you prompted for a 2FA code unexpectedly?
- Password reuse: Was this password used on multiple sites? A breach elsewhere can give attackers the same login.
- Malware or keyloggers: Unusual CPU spikes, new extensions, pop-ups, or system instability can be signs of compromise.
- Leaked session tokens: Some attacks steal browser tokens to bypass passwords and 2FA. Signing out of all devices invalidates these.
- Compromised recovery paths: If someone controlled your email or SMS, they could reset your password.
Review Account Activity for Damage
Look for evidence of misuse so you can undo changes and report what happened.
- Security logs: Review login locations, IPs, and devices. Capture screenshots or export logs for your records.
- Settings changes: Check forwarding rules, filters, inbox rules, linked accounts, and security alerts. Attackers often forward or hide messages.
- Financial activity: For banking, payments, or shopping accounts, review transactions, payout methods, and saved payees. Report suspicious entries immediately.
- Messages and content: On email and social apps, check sent messages, drafts, DMs, and posted content for impersonation.
- Data download: If your account stores files or personal data, see whether exports or large downloads occurred.
Secure the Devices You Use
Closing the account hole is not enough if your device is compromised.
- Update your operating system, browser, and apps: Apply all security updates and restart.
- Remove suspicious browser extensions: Uninstall anything you do not recognize or no longer need. Consider rebuilding your browser profile if you suspect token theft.
- Run reputable anti-malware scans: Use built-in tools and one or two trusted on-demand scanners (not multiple real-time products at once).
- Review Wi‑Fi and router security: Update your router firmware, change admin credentials, and use WPA2/WPA3 with a strong passphrase.
- Check for unauthorized profiles or remote-access tools: Review system profiles, mobile device management profiles, and remote software you did not install.
Harden Your Most Important Accounts
Some accounts deserve extra protection because they unlock everything else.
- Primary email: This is the recovery hub for most logins. Use a unique, very strong password, 2FA with an authenticator or security key, and review forwarding rules and app passwords regularly. For a deeper dive on why it matters so much, see our guide: Why Your Primary Email Account Deserves Stronger Protection Than Most Other Accounts.
- Financial accounts: Enable alerts for every sign-in, transfer, or transaction. Use security keys if supported. Consider separate devices or profiles for banking.
- Cloud storage: Enable 2FA, review shared folders and links, and audit third-party app access.
- Password manager: Protect it with a long, unique master password and 2FA. If compromised, rotate the most sensitive account passwords first.
Strengthen Authentication
Move beyond basic passwords wherever possible.
- Adopt phishing-resistant methods: Passkeys and FIDO2 security keys prevent many token theft and phishing attacks.
- Use app-based 2FA: If passkeys are not available, use a time-based authenticator app. Avoid SMS when you can.
- Store backup codes securely: Keep them offline in a password manager’s secure notes or a locked physical location.
- Rotate recovery email/phone if exposed: If an attacker saw your recovery info, consider changing it and removing old methods.
Check for Ecosystem Risks
Sometimes the problem comes from a related account or tool that has broad access.
- Browser sync: If your browser syncs passwords, history, or extensions, ensure that account is secured with strong 2FA and a unique password. If sync may be compromised, pause it, reset the sync data, and re-add devices carefully.
- Extensions and add-ons: Malicious or over-privileged extensions can read tokens and passwords. Learn how they create account risk here: How Can a Malicious Browser Extension Put Your Accounts and Identity at Risk?.
- Shared devices: Avoid signing in to sensitive accounts on shared or public computers. If you must, use a private window and sign out completely, then change your password from a trusted device afterward.
Set Up Ongoing Monitoring and Alerts
Early detection minimizes damage if someone tries again.
- Security alerts: Turn on notifications for new logins, password changes, and new devices.
- Email rules: Create a filter to flag security emails so they never get missed or auto-archived by malicious rules.
- Financial monitoring: For any sign of identity misuse, monitor credit and account changes closely for new accounts, inquiries, or address changes.
If you want a simple way to keep an eye on your credit and identity-related financial activity after an incident, you can evaluate SmartCredit as an optional next step.
When to File Reports and Seek Help
Some incidents warrant official reports or professional support.
- Financial loss or fraud: Report to your bank or card issuer immediately to limit liability, then file a police report if required.
- Account takeover of social media or email: Use the platform’s account recovery and impersonation reporting tools. Preserve evidence with screenshots and timestamps.
- Identity theft indicators: Unexpected credit inquiries, new accounts, or address changes should prompt fraud alerts or credit freezes with the major bureaus in your country.
Build a Personal Incident-Response Checklist
Write down these steps so you can act quickly next time:
- Revoke sessions and sign out everywhere.
- Change password from a trusted device.
- Enable 2FA (prefer keys or app), update recovery info.
- Remove unknown connected apps and devices.
- Audit account activity, rules, and transactions; document evidence.
- Secure your devices: updates, extension review, malware scans.
- Harden priority accounts (email, financial, password manager).
- Turn on security alerts; monitor credit and identity signals.
- Report fraud promptly if any losses or impersonation occurred.
Practical FAQs
Should I just change the password?
No. First revoke all sessions, then change the password. Otherwise, an attacker with a valid session token can stay logged in even after a password change.
What if the unknown device could be mine?
If the time, IP location, or device signature does not align with your actual use, remove it. You can always sign in again if it was yours.
Is SMS 2FA enough?
It is better than nothing but vulnerable to SIM-swap and interception. Prefer an authenticator app or security keys, or set up passkeys if offered.
Do I need to wipe my computer?
Usually not immediately. Start with updates, extension review, and malware scans. If strong signs of compromise remain, back up files, then consider a full reset and clean reinstall.
What if this happened on a work account?
Notify your IT or security team immediately. Follow your organization’s incident-response procedures and do not attempt risky changes that could affect evidence or compliance.
Conclusion
Finding an unknown device on an important account is a serious warning, but you can regain control quickly. Revoke all sessions, change the password from a trusted device, and lock the account with strong 2FA or passkeys. Then investigate what let the intruder in, secure your devices, and harden your most critical accounts—especially your primary email—so recovery paths are safe. Turn on alerts and monitor for suspicious financial or identity activity so you can respond immediately if someone tries again. With a calm, methodical approach, you can reduce damage now and make future intrusions far less likely.
Good to Know
If you're unsure whether a device is yours, compare its last activity time and location with your actual travel and usage history before removing it. When in doubt, remove it—legitimate access can be re-added, but a bad actor should not remain signed in.