Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →If you received a state-sponsored attack warning or suspect an account was targeted, use the provider’s official recovery process, check the account’s own security activity, remove access you do not recognize, and strengthen login and recovery options. A targeting notification is serious, but it does not by itself prove an attacker signed in, changed settings, or that a particular government was responsible.
What does a state-sponsored hacking alert prove?
Keep three possibilities separate: a provider may have detected or warned about targeting; someone may have attempted to access the account; or an attacker may have successfully entered and changed something. An alert alone does not establish which occurred. Nor does it establish who was behind an attempt.
Treat the warning seriously, but verify it through the account’s own security activity and settings. Look for unfamiliar sign-ins or devices, changes to recovery information, and account actions you did not make. Provider guidance distinguishes suspicious-activity and sign-in notifications from the activity a user can review in their account.
What should you do first?
- Open the provider directly. Use its known official website or app; do not use links in a surprising alert to sign in or recover the account. If you have reason to think the device you normally use is compromised, use another device you trust for account recovery. This is a cautious operational step, not a universal provider-prescribed procedure.
- Use the official recovery flow if you cannot sign in. Follow the provider’s account-recovery instructions rather than trying workarounds from an alert or an unsolicited message.
- Review security activity and account settings. Check recent activity and alerts, devices, sign-in methods, recovery email and phone details, and settings that could redirect or expose messages. Google’s compromised-account guidance directs users to review recent security activity and Gmail settings for unfamiliar changes.
- Change the affected password. Set a strong, unique password. If you reused the old password on other accounts, change it there too, starting with the email account used to recover other accounts. CISA’s state-sponsored threat guidance recommends strong passwords that are not reused across accounts.
If Google identifies an unrecognized sign-in method as at risk, its guidance is to remove that method, immediately change the password, and review security settings. The names and locations of controls vary across providers, so follow the provider’s current official instructions.
How do you remove an attacker’s access?
After you regain access, inspect the account for changes an intruder could use to stay in or regain entry. Remove recovery details, devices, sign-in methods, or authentication factors you do not recognize. Review email forwarding and filters, as well as other settings that could hide or redirect account activity. Use the provider’s controls to sign out or revoke sessions you do not trust, if those controls are available.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Then check linked accounts, especially the recovery email account. If someone can access that mailbox, they may be able to reset other passwords. Change any compromised or reused credentials on those accounts and review their recovery settings too. Account screens and session-revocation options differ, so do not assume one provider’s instructions apply to another.
How should you strengthen sign-in and recovery?
Turn on the strongest multifactor authentication (MFA) your provider supports, preferably a phishing-resistant option such as a supported passkey or physical security key. CISA identifies security keys as a physical MFA option. Google describes security keys as its most secure listed verification step and recommends a passkey or physical key for sign-in methods it considers at risk.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Choose an option you can use reliably and recover if a device is lost. Passkeys may be stored on a device or in a password manager; how they sync or can be recovered depends on the provider and storage choice. Microsoft warns that losing a device can also mean losing its passkey if you have no other recovery method. Keep recovery information current, save recovery codes securely when offered, and retain a backup way to access the account. If considering a physical key, first confirm that the account supports it and plan a safe backup.
What if the account belongs to work or a government organization?
Contact your organization’s security or IT response team promptly and follow its instructions. This is especially important for work, government, and managed accounts: responders may need to investigate linked systems and coordinate containment. Do not use consumer account-help pages as a substitute for an organizational incident response.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
CISA’s April 2024 Emergency Directive 24-02 followed a state-sponsored compromise of Microsoft corporate email. The directive required affected federal agencies to investigate exposed content, reset credentials, and secure privileged accounts; those requirements applied to federal agencies, not to personal account holders. CISA advised other potentially affected organizations to contact Microsoft. In its April 11, 2024 alert about the directive, CISA said: “Regardless of direct impact, all organizations are strongly encouraged to apply stringent security measures, including strong passwords, multifactor authentication (MFA) and prohibited sharing of unprotected sensitive information via unsecure channels.”
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What records should you keep, and when should you get help?
Keep the original alert, its timestamp, related provider notifications, and relevant sign-in information. Do not delete potentially useful records. If an organization is handling the incident, avoid broad device or network changes unless its responders direct you to make them. CISA’s 2025 network advisory recommends that organizations try to establish the full scope of a suspected compromise before mitigation; that is enterprise technical guidance, not a home-user forensic checklist.
Contact the provider if you cannot recover the account or need help reviewing its security controls. If financial fraud is underway, contact your bank or relevant financial provider promptly. If sensitive information, work systems, or government accounts may be involved, notify the appropriate organization or authority. The right specialist or reporting route depends on what happened and cannot be determined from an alert alone.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchQuick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

