I think someone got into my account: what to do in the first hour

If you suspect someone got into your account, change the password of the account’s e-mail first, then the Meu Interweb one, and only then check what was touched. The order matters: whoever controls the account e-mail can request recovery of all your other passwords, and changing only the Meu Interweb one leaves the back door open.

The signs it was not your imagination

What you saw What it usually is
An e-mail about a password or details change you did not ask for Someone tried, or managed, to touch the account. Keep the e-mail.
A service, domain or invoice you do not recognise An order placed by someone else, or a renewal you forgot. Check before paying.
A contact or sub-account you did not create The door someone left open to come back through.
Mail being forwarded without your knowing A forwarding rule or filter created by whoever got in.
A message saying your account is at risk and asking for details Almost always a scam. Do not click. See how to tell whether an e-mail really came from us.

The first hour, in order

1 Use a device you trust. If your computer may be infected, change the passwords from another one (the phone will do) and run the antivirus on the first one afterwards.
2 Change the password of the e-mail that is on the account, at the mail service you use, and check there for forwarding rules you did not create.
3 Change the Meu Interweb password. If you can no longer sign in, use recovery: how to recover access to your account. Pick a new password, long, that you use nowhere else.
4 Turn on two-factor authentication. It is what stops a stolen password being enough to get in. See how to enable two-factor authentication.
5 Check the registration details and sub-accounts. In the profile, confirm that the e-mail and phone are yours, and in the contacts and sub-accounts list remove the ones you do not recognise. See how to manage sub-accounts.
6 Go through services, domains and invoices. Look for anything you did not ask for, and check on the domains that the nameservers are the ones you expect. Do not pay anything you do not recognise.
7 Change the cPanel password too, and those of the mailboxes you think are at risk, and check in Forwarders and Email Filters (in cPanel) for forwards or filters you did not create. See how to change your cPanel password.
8 Talk to us. Open a ticket with the time you noticed, what looked strange and what you have already changed. If you can no longer sign in, use one of the direct channels on the contact page.
Do not delete anything before talking to us: not the change e-mails, not the strange sub-accounts, not the invoices. They help work out how they got in. Changing passwords and removing access is what you do now; clearing up the traces comes later.
To avoid a repeat: a different password for every site, in a password manager, two-factor authentication on and a recovery e-mail only you control. If the problem is the website and not the account, see how to tell if your site has been compromised.

Think someone got in? Tell us when you noticed and what looked strange. We will never ask for your password.

Open a support ticket

SEE ALSO

How to recover access to your account

How to enable or disable two-factor authentication (2FA)

Locked out: password, two-step authentication and the recovery e-mail

How to clean up a compromised site

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $5.36/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?