Who still has access to your accounts?
Changing your password doesn't sign anyone out, and it does nothing to the apps you connected in 2019. Here are the exact pages to check, and the order to check them in.
I read the support mail here, so I see this one a lot. Someone has a scare, changes their password, and assumes that's that.
It isn't. A password change protects future logins. It usually does nothing to sessions that are already open, and nothing at all to the apps you gave access to years ago. Those keep working on their own tokens.
Here's a twenty-minute check. Do it once, properly, then put it in the calendar for every six months.
1. Third-party app access
This is the one almost nobody looks at, and it's where the old stuff lives. A recruiting tool you trialled. A PDF converter. A calendar thing from a job you left.
- Google — myaccount.google.com/connections
- Microsoft — account.microsoft.com, then Privacy, then Apps and services
- GitHub — Settings, Applications. Check both tabs: authorised OAuth apps and installed GitHub Apps
- Slack — your workspace admin page, Manage apps
- Apple — Settings, your name, Sign in with Apple
Revoke anything you don't recognise or don't use. Be aggressive. If you break something you still need, you'll find out immediately and you can just re-authorise it.
Read the permissions on whatever you keep. "Read, compose, send and permanently delete all your email" is a real scope that real apps ask for.
2. Active sessions
This is the one that actually kicks an intruder out.
- Google — myaccount.google.com, Security, Your devices
- Microsoft — account.microsoft.com, Devices
- GitHub — Settings, Sessions
- Facebook / Instagram — Settings, Accounts Centre, Password and security, Where you're logged in
Order matters here. Change the password first, then sign out everywhere. Do it the other way round and they just log back in with the password they still have.
3. Recovery options
Check these before anything else if you think someone is already in. Adding their own recovery email or phone is the first thing a competent attacker does, and recovery outranks your password by design.
- Google — Security, then How you sign in
- Microsoft — Security, Advanced security options
Anything there that isn't yours, remove it.
4. Email forwarding and filters
The quiet one. Nobody checks it, and it survives everything else you've just done.
In Gmail, Settings, then Forwarding and POP/IMAP, then Filters. Look for a rule that forwards mail somewhere, or one that auto-archives anything matching "invoice" or "password" so you never see it.
In Outlook, Settings, Mail, Forwarding, and then Rules.
This is a standard move in business email compromise. They don't need to stay logged in if your mail comes to them anyway.
5. App passwords
Older accounts may have these. They're long generated passwords for apps that can't do modern sign-in, and critically, they bypass two-factor authentication.
Google has them under Security. Delete any you don't actively use. If you turned on 2FA years ago and left an app password lying around, you have a 2FA bypass sitting in your account.
Why this order
Recovery options, then password, then sessions, then the quiet stuff. Each step undoes the one before it if you take them in the wrong sequence. There's a longer write-up of why here.
And if something is happening right now rather than in theory, the hacked account triage asks two questions and gives you the ordered list for your situation.