What to Do If Someone Adds an Unknown Sign-In Method to Your Account
Removing an unfamiliar sign-in method can protect your account, but deleting it too soon can make recovery harder. I’ll walk you through a safer sequence for reviewing sessions, securing access, checking forwarding rules, and preserving useful evidence.
An unfamiliar sign-in method—such as a passkey, authenticator app, phone number, security key, or recovery email—can mean someone changed your account settings. It can also be a legitimate method you forgot about or one added during a device setup. The safest response is to investigate without giving up your own access.
Start from a device you trust, avoid links in unexpected messages, and work through the account’s security settings directly. Your exact menu names will vary, but the order matters: preserve evidence, check active access, secure the account, remove unfamiliar methods, and look for ways an intruder may continue receiving information.
First, protect your current access
If you’re still signed in, don’t sign out immediately. That session may be your easiest route back into the account, especially if the unfamiliar method has affected password resets or multi-factor authentication. Use a device and network you normally use when possible, and make sure the device itself is protected by a screen lock and up-to-date security software.
Open the service by typing its known web address or using its official app. Don’t use a sign-in or “secure your account” link from an email, text message, social-media message, or pop-up. Phishing messages often appear just after an attacker changes account settings because they can make the warning feel urgent and convincing.
If you can access the account, take screenshots or save relevant details before changing everything. Capture the unfamiliar method, its name, the date or approximate time it was added, recent sign-in locations, device names, security alerts, and any recovery changes. Don’t expose passwords, backup codes, full payment details, or private message content in those records.
Check the account’s current options: Security menus and recovery procedures change over time. Confirm the available sign-in methods, session controls, and support route in the provider’s official help documentation rather than relying on an old tutorial or a message that sent you there.
Review active sessions and connected devices
Look for a section named something like Your devices, Where you’re signed in, Active sessions, or Login activity. Review each entry carefully. An unfamiliar device, browser, location, or recent sign-in may indicate access, but location data isn’t exact: mobile networks, corporate connections, VPNs, and shared internet providers can make a legitimate sign-in appear elsewhere.
Pay attention to combinations rather than one clue in isolation. A new browser at an unusual time, a device you don’t recognize, and a security-method change together are more concerning than a rough location match by itself. Check whether the listed activity corresponds to a phone, tablet, computer, streaming device, or browser you recently used.
Sign out unfamiliar sessions. If the service offers Sign out of all other sessions, using it can be sensible after you’ve recorded the evidence, although you may need to sign back in on your own devices. Some services take time to end sessions or let certain app connections remain active, so continue reviewing connected applications afterward.
If you’re locked out, don’t keep guessing passwords or repeatedly requesting codes. Use the provider’s official account-recovery process from a trusted device. The provider may ask for older account details, previous passwords, a recovery address, or other information. Follow the instructions carefully, and be suspicious of anyone offering paid “recovery” through an unofficial channel.
Change the password from a trusted route
Once you’ve documented the activity and reviewed sessions, change the account password. Use the account’s own security page or official app, not a link supplied by a questionable message. Choose a long, unique password that you haven’t used for any other service. A password manager can generate and store one without requiring you to memorize it.
Changing the password can block some existing access, but it doesn’t necessarily remove every session, app token, passkey, or recovery method. That’s why it should be one part of the sequence rather than the only response. After saving the new password, return to the security dashboard and confirm whether other sessions remain active.
If the old password was reused anywhere else, change it on those accounts too. Prioritize your email account, financial services, password manager, cloud storage, shopping accounts, and social-media accounts. An attacker who obtains one reused password may try it across many services.
Secure your primary email account early if it is separate from the affected service. Email often receives password-reset messages and security alerts, so access to it can allow someone to regain control even after you change another account’s password.
Add or confirm your own recovery methods
Before removing an unfamiliar method, make sure you have at least one recovery path that you control. Depending on the service, that might be a verified email address, phone number, authenticator app, passkey, security key, or set of one-time recovery codes.
Check every existing method, not just the one that looks suspicious. Confirm that your email address and phone number are correct, that an authenticator app is on a device you control, and that any security key or passkey belongs to you. If you use recovery codes, create a new set when the service allows it and store them somewhere private and accessible when your primary device is unavailable.
Be cautious about relying on text messages as your only protection. SMS codes may still be useful for recovery, but they can be exposed through phone-number takeover, message interception, or loss of the phone. A password manager, authenticator app, passkey, or hardware security key may offer a stronger additional option, depending on the account and your circumstances.
Don’t remove your only working method until you’ve successfully tested another one. Some services impose a waiting period after security changes, and an impulsive deletion can leave you unable to prove ownership or complete recovery.
Remove the unfamiliar sign-in method
After confirming your own recovery options, return to the sign-in and security-method settings. Remove the unknown method using the provider’s Remove, Revoke, Delete, or No longer have access control. If the service distinguishes between a device and a credential, remove both when appropriate: deleting a listed phone may not revoke a passkey stored on that phone, for example.
Read the confirmation screen before accepting it. Some services warn that removing a method will affect account recovery, signed-in devices, encrypted data, or access to particular features. Follow the provider’s official process if it requires an identity check or a waiting period rather than trying to work around it.
If you don’t recognize the method but it could belong to a shared family, work, or school account, check with the account administrator before removing it. An administrator may have added a security key, recovery address, or device as part of legitimate account management. For a personal account, however, an unfamiliar method combined with unexplained activity should be treated as a potential compromise until you establish otherwise.
Check forwarding, delegation, and connected apps
Changing the password and removing a sign-in method may not stop an intruder from receiving copies of new information. In an email account, inspect forwarding rules, filters, blocked addresses, automatic replies, mailbox delegation, and rules that mark messages as read or move them out of sight. Remove anything you didn’t create, and check whether legitimate messages—especially security alerts and password resets—are being redirected.
For cloud storage, calendars, social networks, and other services, review sharing settings, delegated access, linked devices, third-party applications, API tokens, browser extensions, and backup contacts. Revoke access you don’t recognize. Be careful with connected applications you do use; removing one may disconnect a useful service, but leaving an unknown application connected may let access continue.
Review recent account changes for altered profile details, recovery information, payment settings, sent messages, deleted files, purchases, or posts. If the account is used for work, school, or a business, tell the relevant administrator promptly. They may be able to check access logs, revoke organization-wide sessions, and preserve records that aren’t visible to you.
Preserve evidence without spreading the compromise
Keep screenshots, notification emails, timestamps, device details, support case numbers, and a brief timeline of what happened. Save original messages when possible rather than forwarding them repeatedly. If an email contains suspicious links or attachments, don’t open them just to investigate.
Evidence is useful when contacting the service, your employer or school, a payment provider, or law enforcement. It can also help you identify whether the same password or recovery address was used elsewhere. Store the records somewhere the suspected intruder can't access, such as an offline drive or a separate, well-secured account. Redact passwords, recovery codes, and other secrets before sharing screenshots.
If money, identity documents, private health information, or sensitive work data may have been exposed, contact the affected institution through a verified phone number or website. Account security steps can limit further access, but they can’t undo information that has already been copied.
Check the devices you used to sign in
An account change may be the result of stolen credentials, but it can also follow malware, a malicious browser extension, an untrusted app, or someone with physical access to an unlocked device. Update the operating system, browser, and security software. Remove unfamiliar extensions and applications, particularly those installed shortly before the account change.
Run the device’s built-in security scan or a reputable security tool. If you suspect the computer or phone is actively compromised, use a different trusted device to change important passwords and complete account recovery. Avoid entering new passwords on the questionable device until it has been examined or reset.
You may need professional help if the account controls valuable business data, the device shows signs of persistent compromise, or recovery information keeps changing after you reset it. Use support channels found on the provider’s official site, not contact details posted by strangers in comments or direct messages.
After recovery, reduce the chance of a repeat
Use a unique password and enable multi-factor authentication with a method you can protect and recover. Keep recovery codes in a secure location, review account activity occasionally, and remove old devices and applications you no longer use. Turn on security notifications where available, but remember that an alert is useful only if you can recognize genuine messages and reach the account through a trusted route.
If the suspicious method was a passkey or security key, check every device and password-manager vault where credentials may be synchronized. If it was a phone number or email address, confirm that your mobile and email accounts have their own strong passwords and multi-factor protection. The account you’re trying to protect may not be the only account involved.
The immediate goal isn't simply to delete one unfamiliar entry. It’s to regain exclusive control, prevent silent access through sessions or forwarding, and understand what changed. Preserve the facts first, secure a trusted route back in, replace compromised credentials, remove access you don’t recognize, and then inspect the devices and related accounts that could have enabled the change.