Phishing Protection
How to Recognize an Account Recovery Scam
Account recovery scams imitate support teams and claim they can restore a hacked account. They often request a password, authentication code, payment, or remote access. Use only the provider's official recovery process and verify every contact independently.
How does a recovery scam work?
A scammer may contact you after seeing a public post, a genuine security alert, or an unrelated exposure. They claim to be support staff and offer urgent help. Their goal is usually to obtain a login, code, payment, or remote access.
- Unsolicited support message
- Urgent deadline
- Request for a code
- Request for remote access
What does real support usually not need?
A legitimate provider should not need your current password or one-time authentication code sent to your private device. Be cautious with anyone who wants you to install remote-control software or pay in gift cards or cryptocurrency.
- Never share a one-time code.
- Do not install remote-access tools for strangers.
- Do not pay to unlock an account.
How should I verify a message?
Do not reply or click first. Open the provider's official app or type its website address manually. Check account notifications there and use the published support process.
Stop the conversation and preserve evidence
Do not continue negotiating with the sender. Save the message, sender details, payment request, and links without opening them. Report the account or message through the platform.
- Save screenshots.
- Do not open suspicious links.
- Report the sender.
Use official account recovery
Start recovery from the provider's own site or app. If you already disclosed a password or code, change the password immediately and tell the provider through its verified support channel.
- Use official recovery.
- Change disclosed passwords.
- Notify the provider.
Secure your other accounts
If the disclosed password was reused, replace it everywhere. Protect your email, enable multifactor authentication, and review financial accounts for unauthorized changes.
- Change reused passwords.
- Secure email first.
- Monitor financial activity.
Understand exposure-check limits
A 4safer result can provide context about known exposure of an owned identifier. It cannot authenticate a support message or prove who contacted you. A negative result is not a guarantee of safety.
Frequently asked questions
Will real support ask for my authentication code?
You should not share a one-time code with an unsolicited contact. Use the provider's official support flow instead.
Are paid account recovery services safe?
Treat unsolicited recovery offers as suspicious. Use the provider's published process and avoid services requesting passwords or remote access.
What if I already shared a code?
Change the password, end active sessions, restore recovery settings, and contact the provider immediately through an official channel.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
