Transcript-only lesson. No video or audio is presented on this page.

00:00 — Why email comes first

Your primary email is often the key to your other accounts. Social platforms, shopping services, cloud storage, and sometimes financial services use it for password resets and security alerts.

During an account takeover, securing a less important profile while the attacker still controls your inbox can let them reset the profile again.

00:35 — Use a trusted route

Open the email provider's official app or type its known website address. Avoid links from unexpected messages and search advertisements.

If you can sign in, create a unique password and review active sessions. If you cannot sign in, begin the provider's official recovery process.

01:10 — Check hidden persistence

Changing the password is only one step. Review:

  • recovery addresses and phone numbers;
  • authenticator methods and security keys;
  • trusted devices and active sessions;
  • forwarding addresses, inbox rules, filters, and delegates;
  • connected applications and application passwords.

An unfamiliar forwarding rule can silently copy future security messages even after a password change.

02:00 — Protect connected accounts

Once the inbox and its recovery routes are controlled, move to important connected accounts. Replace reused passwords, revoke unfamiliar sessions, and check whether account details changed.

02:30 — Keep evidence safe

Record times, provider alerts, unfamiliar devices, and the actions you completed. Never place a password, one-time code, backup code, or live recovery link in the evidence.

02:50 — Know when to escalate

Contact your bank or payment provider immediately if financial activity may be affected. Contact the appropriate local authority or emergency service for credible threats or immediate danger. Use official provider support for account restoration.