What this tool does
It asks two questions — what kind of account was taken, and what you can still reach — and returns an ordered first-hour checklist for that exact situation. The order is the product. Most advice for a compromised account is the same six actions in no particular sequence, and several of them quietly undo each other when done in the wrong one.
Why the sequence decides the outcome
Changing the password can be the wrong first move. If the attacker has already added their own recovery email or phone number, a password change just tells them to run a reset — and the recovery path outranks the password. Revert the recovery contacts first, then change the password. Get that backwards and you hand the account over.
A new password does not sign anyone out. On most providers an existing session stays valid after a reset. Revoking other sessions is a separate control, and it has to come after the password change or the attacker simply signs back in with the old one.
Fix your email before your bank. Your email is the reset path for every other account you own, so someone holding it does not need your banking password — they can request a new one. People triage the account with money in it first. It is the wrong one.
The step almost nobody does
After the password change, look at what was left behind: mail forwarding addresses, inbox rules,
connected third-party apps (OAuth grants) and app passwords. A rule that silently forwards or
deletes anything matching OTP or invoice survives a password change
untouched, and an OAuth grant carries its own access token that never sees your new password.
That is how a takeover persists quietly for months after everyone believes it was dealt with.
Every checklist here includes that sweep, in the position it belongs.
Nothing you type leaves your device
This tool asks two multiple-choice questions and has no text box anywhere, so there is nothing to upload even in principle. No account, no server, nothing saved — close the tab and it is gone. Our analytics records that a checklist was generated and which of the five account types it was for — nothing else, because there is nothing else to record.
Where this comes from
The sequencing, and the reasoning behind each position in it, is set out in how to check if your email was breached, and what to do in the next hour. Read that for the why; use this for the what, in order, right now. For what replaces the passwords you change, passkeys vs passwords vs 2FA covers what each option actually stops.
If money has already moved, that is a different clock and it runs faster than this checklist. In India, report at cybercrime.gov.in and call 1930, the national cyber-fraud helpline, before working through anything else. That is what gives a bank a window to freeze a transfer, and the window is short.