Skip to content
All guides

Account Security

Unknown Device Logged Into My Account: What Should I Do?

An unknown device alert deserves quick review, but it can also be caused by travel, VPNs, shared devices, or approximate location data. Check the official account activity page, end sessions you do not recognize, change reused passwords, and enable multifactor authentication.

By the 4safer teamUpdated August 29, 20265 minutes read

Start with the official activity page

Open the service directly and review recent sign-ins from the account settings. Do not click a login alert link unless you are confident it is genuine.

Compare the time, device type, browser, and successful action. IP-based location can be wrong, especially with mobile networks and VPNs.

  • Check time and device.
  • Check whether access succeeded.
  • Avoid links from unexpected messages.

When is it urgent?

Treat the alert as urgent if the sign-in succeeded, the device remains active, settings changed, messages were sent, payment details were used, or you cannot log in anymore.

  • Successful unknown login
  • Changed recovery settings
  • Sent messages
  • Payment activity

What evidence helps?

Take screenshots of the device list, sign-in history, email alerts, and changed settings. Keep them private and do not post account details publicly.

End unknown sessions

Use the service's sign-out option to remove devices you do not recognize. If the account offers a global sign-out, use it after changing the password.

  • Remove unknown devices.
  • Sign out everywhere.
  • Review remembered browsers.

Change the password if needed

Change the password when the login succeeded, the password was reused, or you do not recognize activity. Use a new unique password and update every account where the old password was reused.

  • Create a unique password.
  • Replace reused copies.
  • Store it safely.

Add stronger sign-in controls

Enable multifactor authentication, review backup codes, remove unknown recovery options, and turn on login alerts. Never share one-time codes with anyone who contacts you.

  • Enable MFA.
  • Review recovery methods.
  • Turn on alerts.

Check exposure context

A known data exposure can explain why an attacker guessed or reused credentials, but it does not prove account access. 4safer results should be used as context alongside official account activity.

Frequently asked questions

Can the wrong city appear in a real login alert?

Yes. Login locations can be approximate, so review device, browser, time, and whether the login succeeded.

Should I change my password after every alert?

Change it if the login succeeded, the password was reused, or you do not recognize related activity.

Is ending the session enough?

No. Also change risky passwords, review recovery settings, and enable multifactor authentication.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.