Account Security
How to Tell If Someone Is Trying to Hack My Account
Unexpected login attempts, password reset requests, verification codes, MFA prompts, and unfamiliar sessions can indicate that an account is being targeted. Some attempts fail because your security is working. Learn how to separate attempted access from successful compromise and what to do next.
What are the clearest signs someone is targeting my account?
Some security signals deserve more attention than ordinary spam.
Common warning signs include:
The FTC specifically identifies unauthorized login notifications, password or contact changes, and losing access to an account as signs that someone may have hacked it.
But the details matter.
An attempted login and a successful login are not the same event.
- Login attempts you did not make
- Password-reset emails you did not request
- Verification codes you did not request
- MFA approval prompts you did not initiate
- Security alerts from unfamiliar devices
- A successful login from a device you do not recognize
- Recovery information being changed
- Password changes you did not make
- Being suddenly locked out
- Messages or posts you did not create
Someone tried to log in — does that mean they know my password?
An attacker may only know your:
They may be guessing passwords or testing credentials obtained elsewhere.
Some login alerts are triggered even when authentication fails.
Read the message carefully.
Look for wording such as:
versus:
The first may mean an unsuccessful attempt.
The second deserves immediate review.
- Email address
- Username
- Phone number
Why would someone know which account to target?
Email addresses and usernames are widely used as identifiers.
They can become known through:
Knowing your identifier does not automatically provide access.
Security should be designed with the assumption that usernames and email addresses may eventually become known.
The secrets and authentication methods behind them matter more.
- Ordinary public profiles
- Previous data exposures
- Old accounts
- Marketing lists
- Phishing
- Public contact information
- Other online activity
Can an old data breach cause new login attempts?
This is especially important when passwords are reused.
Imagine your email and password were exposed through an old account several years ago.
If the same password still protects another account, someone can try the old credentials there.
CISA warns that malicious actors take advantage of passwords reused across systems, while NIST recommends unique passwords to reduce the ability to use credentials compromised elsewhere.
The service receiving the attack does not need to have suffered a breach.
The credential can come from somewhere completely different.
What does an unexpected password reset mean?
Many account-recovery systems allow someone to start a reset using an email address or username.
That means a person may be able to trigger a reset email without knowing your existing password.
The reset request alone usually does not mean they can complete the process.
The important question is whether they also control your recovery channel.
If your email account is secure, a reset message arriving in your inbox may simply show that someone knows the account identifier.
Do not automatically click the link in an unexpected reset message.
Open the official service separately and review activity there.
What does an unexpected verification code mean?
A code you did not request may mean someone reached a stage of authentication or recovery that requires additional verification.
Do not give the code to anyone.
Do not approve an unexpected MFA prompt.
A scammer might call or message you and claim:
The code may be precisely what prevents them from finishing the login.
Treat it like a temporary authentication secret.
- They are investigating fraud
- They work for technical support
- The code was sent accidentally
- They need the code to cancel a transaction
- They need it to protect your account
What if I keep getting MFA prompts?
Repeated MFA requests can occur when someone has enough information to reach the second step of authentication.
Never approve a prompt simply to make the notifications stop.
CISA recommends MFA broadly and explains that it significantly raises the difficulty of account takeover when passwords are compromised. It also recommends stronger phishing-resistant authentication where available.
- Open the account directly.
- Review recent authentication activity.
- Change the password if you believe it may be compromised.
- Sign out unfamiliar sessions.
- Confirm recovery settings.
- Keep MFA enabled.
How can I tell whether an attempt actually succeeded?
Review the account's security dashboard.
If the account is email, also check:
The FTC recommends reviewing these settings after suspected email compromise because someone with access may create forwarding rules or make other changes designed to preserve access.
- Successful logins
- Active sessions
- Signed-in devices
- Recent security changes
- Connected applications
- Recovery email changes
- Recovery phone changes
- Password changes
- Sent messages
- Deleted messages
- Forwarding rules
- Filters
- Delegated access
What if the location in the login alert is wrong?
Location information is not always exact.
Internet providers, VPNs, corporate networks, mobile networks, and IP geolocation can make legitimate activity appear to come from another city or region.
Do not judge the alert solely by location.
Compare:
A completely unfamiliar device at an impossible time deserves more attention than a slightly unexpected city associated with your own phone.
- Device
- Browser
- Operating system
- Time
- Whether you were actively logging in
- Whether the attempt succeeded
Should I change my password after a failed login attempt?
Not automatically.
If you use a unique password, MFA is enabled, and there is no evidence the credential itself was exposed, a failed attempt may simply mean someone tried and failed.
If you change it, use a genuinely new password.
NIST recommends password managers because they can generate long, unique credentials and remove the temptation to reuse memorable passwords.
- An unfamiliar login succeeded
- The password may have appeared in an exposure
- You reused it elsewhere
- You entered it into a phishing site
- Security settings changed unexpectedly
- You suspect someone knows the credential
Why password reuse creates repeated attacks
Attackers do not necessarily need to guess a complex password.
If that exact complex password was already exposed somewhere else, complexity no longer makes it secret.
A user creates a 20-character password.
That is good.
But they use it on six websites.
One of those websites experiences an exposure.
Now the same 20-character password can potentially be tested against the other five.
The issue is no longer password strength.
It is password reuse.
Unique credentials ensure that one breached service does not create a working key for another.
Should I use a password manager?
For accounts that still use passwords, password managers can solve one of the biggest practical problems: remembering unique credentials.
NIST highly recommends password managers and explains that they can generate and store unique passwords for individual accounts.
Secure the password manager itself carefully.
Use strong authentication and enable MFA if supported.
Because the manager protects many credentials, it deserves stronger protection than an ordinary low-value account.
What about passkeys?
Passkeys can substantially change this risk.
Traditional passwords can be:
Passkeys use unique cryptographic credentials associated with a legitimate service.
NIST explains that passkeys are phishing-resistant and do not create the same reusable-secret problem as passwords.
If an account you frequently worry about supports passkeys, consider adopting one.
Primary email accounts are particularly strong candidates.
- Reused
- Guessed
- Phished
- Exposed
- Entered into fake websites
Why email should be secured first
Email is often the center of your digital identity.
It receives:
If someone gains access to it, they may be able to attack other accounts more easily.
The FTC warns that control of an email account can allow an attacker to receive password-reset links for other services.
Protect your email with:
- Password resets
- Login alerts
- Verification messages
- Account recovery emails
- Financial notifications
- Security warnings
- A unique password
- MFA
- A passkey if available
- Updated recovery information
- Login alerts
- Session review
- No unknown forwarding rules
Could the “security alert” itself be fake?
This is one of the most important traps.
Someone is trying to hack your account.
The natural reaction is to click immediately.
That urgency may be the attack.
The FTC warns that phishing messages commonly claim there is suspicious activity or an account problem and then direct the victim to a fake website. It advises contacting the company independently instead of using unexpected links.
So if you receive a security alert:
An attacker should not be able to turn your concern about account security into the method they use to steal your password.
- Do not panic.
- Avoid the message link if you are unsure.
- Open the service's trusted app or type its address yourself.
- Review security activity inside the real account.
What if I clicked a suspicious security link?
If you only opened a page and did not enter information, the appropriate response depends on what happened.
If you entered your password:
If you installed something or gave someone access to your device, take the device risk seriously.
The FTC recommends updating security software, running a scan, deleting identified threats, changing passwords, and enabling two-factor authentication when scammers may have gained access to a computer or phone.
In June 2026, the FTC also warned about fake CAPTCHA scams that can trick users into running commands that install malware capable of stealing login information; its advice included disconnecting, scanning the device, changing passwords, and enabling two-factor authentication from a different device if necessary.
- Change it through the real service
- Change reused copies
- Review sessions
- Enable MFA
What if someone actually got into my account?
Take control first.
If you can still sign in:
The FTC recommends these basic recovery actions after an account takeover.
If you cannot sign in, use the provider's official account-recovery process.
Do not pay strangers claiming they can recover the account for you through unofficial methods.
- Change the password.
- Sign out all other sessions.
- Enable or reset MFA.
- Review recovery information.
- Remove unknown applications or devices.
- Check for unauthorized changes.
- Review what the person may have accessed.
What if someone stole personal information from the account?
Account takeover can become an identity problem if the account contained sensitive information.
If you discover actual misuse involving personal information, IdentityTheft.gov can provide a recovery plan based on your circumstances. The FTC directs consumers there when stolen personal data may have been used for identity theft.
Again, do not assume every login attempt equals identity theft.
Escalate your response based on evidence.
See whether known exposure helps explain the attempts
4safer is intended to provide another piece of the security picture.
For someone asking “Is someone trying to hack my account?”, the useful sequence is:
A positive result may provide context.
Practical checklist if someone may be targeting your account
- [ ] Verify security alerts through the official service
- [ ] Determine whether the login attempt succeeded
- [ ] Review active sessions
- [ ] Review signed-in devices
- [ ] Check recovery email and phone information
- [ ] Check for unknown connected apps
- [ ] Check your email or username for known exposure
- [ ] Change the password if it may be compromised
- [ ] Replace reused versions of the password
- [ ] Use a password manager
- [ ] Enable MFA
- [ ] Never approve an unexpected MFA prompt
- [ ] Consider phishing-resistant MFA
- [ ] Consider a passkey
- [ ] Secure your primary email first
- [ ] Check email forwarding rules
- [ ] Keep login alerts enabled
- [ ] Avoid unexpected security links
- [ ] Scan your device if malware is suspected
- [ ] Use official account-recovery channels
Frequently asked questions
How can I tell if someone is trying to hack my account?
Unexpected login attempts, password-reset requests, verification codes, MFA prompts, and repeated security alerts can indicate targeting. Confirm what actually happened through the service's official security dashboard.
Does a failed login attempt mean someone knows my password?
No. They may only know your email or username and be guessing or testing old credentials.
What does an unexpected MFA prompt mean?
It may mean someone initiated an authentication attempt. Never approve a prompt you did not start.
Should I change my password after a failed login?
Change it if you believe the password itself may be exposed, reused, phished, or otherwise compromised. A failed attempt alone does not always require a change.
Why does the login alert show another city?
IP-based location can be approximate. Check the device, browser, time, and whether the login succeeded before deciding that it was unauthorized.
Can old leaked passwords be used years later?
Yes, if you still use them. Historical breach information can remain useful when credentials are never retired or are reused elsewhere.
How do I know whether someone actually got into my account?
Look for successful unfamiliar sessions, password changes, recovery changes, messages you did not send, new connected applications, or other unauthorized activity.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
