Back
Aug 10, 2026
4
CrackEmail

Someone Signed Into My Account: How to Tell and What to Do

Every service keeps a list of active sessions. What it shows, why revoking comes before changing the password, and where attackers leave a foothold.

Someone Signed Into My Account: How to Tell and What to Do | CrackEmail

The notification arrives at an odd hour: a new sign-in from a city you have never visited. Or nothing arrives at all, and you only notice because a message you never wrote is sitting in a chat. Either way the question is the same — is someone actually in there, and what is still under your control.

[[answer]]Every major service keeps a list of active sessions with device, location and time. Open it before changing anything: the list tells you whether the intrusion is real and how long it has been going on. Then close the sessions, then change the password — in that order, or the intruder simply keeps their session.[[/answer]]

Why the order matters more than the password

A password change does not, by itself, throw anyone out. Most services keep existing sessions alive: the person holding one stays signed in, sometimes for weeks, while you sit there believing the problem is solved. That is why the sequence is check, then revoke, then change — and why "I changed my password" is not an answer to "is anyone still inside".

The session list is also the only honest evidence you have. Notification emails can be faked — a message claiming "unusual sign-in, click here" is the oldest phishing template there is. The list inside your account cannot be faked, because you reached it yourself.

[[steps]] Open the session list :: Google, Apple, Meta, Telegram and WhatsApp all keep one in security settings. Look at device, approximate location and last activity. Judge what you see :: Your own phone abroad on a VPN looks alarming and is not. An unfamiliar device model at 4 a.m. is a different matter. Revoke everything except this device :: Every service has a "sign out of all other sessions" action. Use it before touching the password. Change the password :: A new one, not a variation of the old. If the old password was reused elsewhere, those accounts need it too. Re-check the recovery settings :: The most common trick is not staying signed in — it is quietly adding a recovery email or phone that belongs to someone else. Turn on a second factor :: An app or a hardware key, not SMS, for the reasons in the section below. [[/steps]]

Where the session lists live

The wording differs, the idea does not. Google puts it under Your devices in account security; Apple shows signed-in devices in the Apple ID settings on any of your devices; Meta calls it "Where you're logged in" inside Password and Security. Telegram has Devices, WhatsApp has Linked devices — both let you end other sessions from the phone in your hand.

Two of these deserve a second look even when nothing seems wrong. Linked devices in messengers is where a forgotten laptop session lives for years. And recovery settings is where an attacker leaves their foothold, because changing a password does not remove a recovery address someone else added.

What the intruder was probably after

Contrary to the mental image, most account intrusions are not personal. The account is a means: to reach a payment card, to send the same scam to your contact list, or to collect confirmation codes for something else. This is worth knowing because it tells you what to check next.

  • Sent messages and archived chats. Scams sent from your account are usually deleted right after, but the archive keeps them.
  • Filters and forwarding rules in mail. A rule that silently forwards everything, or deletes messages from your bank, survives a password change and is invisible unless you look for it.
  • Connected apps and third-party access. An app authorised months ago keeps its own token; revoking sessions does not revoke it.
  • Payment methods and delivery addresses. A changed address on a shopping account is the quiet version of theft.

[[post:what-is-spyware-programs|If the device itself might be compromised]], the picture is different: a password changed on an infected phone is a password the attacker watches you type.

SMS is the weakest second factor

It is better than nothing and worse than everything else. A code sent by SMS travels through the operator's network, and that network was designed in an era when trust between carriers was assumed. It can also be moved to another SIM entirely — the technique known as SIM swapping, where someone persuades a carrier to reissue your number.

[[compare]] Method | Works offline | Resists phishing | Resists SIM swap | Effort SMS code | no | no | no | none Authenticator app | yes | no | yes | one-time setup Push approval | no | partly | yes | none Hardware key | yes | yes | yes | buy a key Passkey | yes | yes | yes | one-time setup [[/compare]]

The practical reading of that table: move off SMS where the service allows it, and prefer an app to push approvals, because a push notification arriving at 3 a.m. gets approved by a half-asleep person more often than anyone likes to admit.

When the account is already gone

Everything above assumes you can still sign in. If the password has been changed and the recovery address swapped, the official recovery flow is the first stop — it works more often than people expect, especially within the first days, while the service still has your device history as evidence. [[post:messenger-account-recovery-methods|What to do when the number itself is gone]] is a separate question with its own answers.

[[faq]] A sign-in alert came from another country — was I hacked? :: Not necessarily. VPNs, roaming and provider routing all move the apparent location. Check the session list; a device you recognise is more meaningful than the city. Should I click the link in the security email? :: No. Open the service yourself, by typing the address. Security notifications are the single most imitated email type there is. Does changing the password sign everyone out? :: On most services, no. Sessions survive unless you end them explicitly, which is why revoking comes first. How long do old sessions live? :: Often indefinitely on desktop apps. A laptop signed in three years ago is still signed in unless someone ended it. Is it worth deleting the account and starting over? :: Rarely. You lose history and the recovery paths that prove the account was yours, and the underlying leak — usually a reused password — travels with you. [[/faq]]

Afterwards

Two habits prevent most repeats, and neither takes long. Look at the session list of your main account once in a while — the same way you glance at a bank statement. And stop reusing the password of your mail account anywhere else: it is the key that unlocks every reset link for everything you own.

Did this answer your question?