Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Unfamiliar sign-ins, changed account settings, messages you didn’t send, or unauthorized purchases are reasons to investigate and act quickly—but none alone proves your computer or phone has malware. Start by securing the affected account through its official recovery process, then check for misuse and address a device separately if there is evidence it may be infected.
What signs could mean an account has been compromised?
The signs below are examples drawn from Google Account Help’s guidance on suspicious Google Account, Gmail, and linked-product activity. They are useful signals to investigate, not proof by themselves, and other services may label their security and recovery pages differently. Check the official help pages for the service involved. If an unexpected security alert arrives by email or text, go to the service directly through its known address or saved official app rather than following a link in the message.
Account access and security controls
- A sign-in alert or new-device notification you cannot explain.
- A device appears in the account’s signed-in device list that you do not recognize.
- Your password no longer works, or you learn it changed without your action.
- An unfamiliar recovery phone number is listed.
- An unfamiliar recovery email or alternate contact address is listed.
- Your account name or another important profile detail changed.
- Two-step verification or its methods changed without your knowledge.
- An app or service you do not recognize has access to the account.
Email, content, and connected services
- Friends say they received strange messages from your account.
- You find sent messages you did not write.
- Expected email stops arriving, or messages disappear unexpectedly.
- Email forwarding, filters, delegates, or other settings have changed.
- Unfamiliar videos, comments, posts, or profile changes appear on a linked service.
- Drive files or Photos sharing settings show activity you do not recognize.
Money and identity
- You see a purchase, payment method, advertising spend, or other financial activity you did not authorize.
Google’s guidance on securing a hacked or compromised Google Account describes these kinds of warning signs across its products. For a non-Google account, use that provider’s official security and recovery guidance.
What should you do first if you suspect an account takeover?
Secure the account before trying to clean a device. If you suspect malware, use a different trusted device that you control for recovery and password changes; avoid entering new credentials on a device you believe may be compromised.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Open the provider’s official recovery route. If you can’t sign in, type the provider’s known address or use its saved official app to reach account recovery. Google directs locked-out users—including people whose password or recovery details changed—to its account recovery process.
- Review recent security events and signed-in devices. Identify activity that wasn’t yours, remove devices you don’t recognize, and follow the provider’s security prompts. Google recommends reviewing suspicious events and unfamiliar devices.
- Correct account controls that were changed. Check recovery numbers and email addresses, profile details, authentication methods, and third-party app access. Remove unfamiliar access and restore details you recognize.
- Change passwords and turn on multifactor authentication. Change the affected password and any other passwords reused elsewhere. Prioritize your email account and accounts that can reset access to other services. CISA’s account-compromise advice recommends making associated password changes from a different computer under your control. Where available, turn on multifactor authentication (MFA); Google’s 2-Step Verification can use a phone, security key, or printed code.
What account settings and activity should you check?
After reclaiming access, look for changes that could let someone keep using the account or conceal activity. The exact menu names depend on the provider and product.
- Email: Review forwarding, filters, delegates, scheduled messages, sent items, and missing messages. Remove rules or access you did not set up.
- Connected apps and devices: Check apps, services, and sessions with account access; revoke anything unfamiliar.
- Files and sharing: Review files, shared folders or albums, and their sharing permissions for changes you did not make.
- Payments: Check saved payment methods and recent transactions for changes or charges you cannot account for.
- Linked services: Look for unexpected posts, comments, profile edits, or other activity associated with the compromised account.
How do you limit financial or identity harm?
Act promptly if the compromised account exposes payment or identity information. Contact the bank, retailer, or card issuer connected to the suspicious activity and explain what you found. CISA’s account-compromise guidance advises contacting the relevant financial institution or store; Google likewise advises contacting a bank or local authorities if saved financial or identity information may have been exposed. Report the account takeover to the platform through its official support route. If you are dealing with identity theft, use IdentityTheft.gov. What protections or liability rules apply depend on the provider, financial institution, and jurisdiction.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
When should you treat this as a device-malware problem?
An unexpected account setting or login does not, by itself, show that your phone or computer is infected. Account takeover and malware can overlap, but they need separate checks: account recovery restores control of an online identity, while device remediation addresses potentially harmful software.
Malware is software that can steal sensitive information. If there is a credible reason to suspect it, use another trusted device for account recovery, keep the affected device’s operating system, browser, and security software up to date, and seek help from a reputable security expert or use a legitimate security program. CISA’s Malware Tip Card supports those steps. A scan is not proof that a device is clean.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Google lists removing harmful software as a possible need and mentions a factory reset or operating-system reinstall as options. Those are not universal first responses. Before a reset, back up files you need; if you are unsure whether the backup or device is safe, ask a reputable expert before restoring data.
Quick Recap
Best Value
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How do you reduce the chance of another takeover?
- Change any other account passwords that reused the compromised password, especially email and accounts that can reset other passwords.
- Use MFA where it is offered. Google lists a security key as one possible 2-Step Verification method; it is an optional security measure, not a recovery fix.
- Consider a password manager to create and keep distinct passwords. CISA recommends password managers as part of stronger account security.
- Keep your operating system, browser, and security software current.
- Watch for new unauthorized charges, sign-ins, messages, or account-setting changes. The cited guidance does not establish a fixed monitoring period, so continue checking as appropriate for the account and any activity you reported.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

