Securing your accounts after malware or phishing: the order that matters
After malware or a phishing attack, secure your main e-mail account first, from a clean device, because it can reset every other password; then sign out of all sessions, turn on two-step verification or passkeys, protect bank cards and crypto, and only then work through the rest. Changing passwords in the wrong order, or on a PC that is still infected, can hand the new passwords straight back to the attacker.
- Why the order matters
- Step 0: work from a clean device
- Step 1: your main e-mail account
- Step 2: sign out of all sessions
- Step 3: two-step verification and passkeys
- Step 4: banks, cards, payment apps and crypto
- Step 5: credit freeze and identity protection
- Step 6: the remaining accounts, then keep watching
- Common mistakes
Why the order matters
Attackers who get your data usually go after the accounts that unlock other accounts. Your main e-mail address is the master key: whoever controls it can request password resets for banking, shopping, social media and cloud storage, and read the confirmation messages. If you change your bank password first while the attacker still reads your e-mail, they can reset it again.
Speed matters too. Information stealers collect live session cookies, which let an attacker open an account without the password, and stolen logs are often used within hours or days. See information stealers for how that works. The steps below are ordered by how much each account can unlock and how quickly losses become permanent.
The order at a glance
- Use a clean device.
- Secure your main e-mail account, including forwarding rules and recovery options.
- Sign out of all sessions everywhere that matters.
- Turn on two-step verification, preferably passkeys or an authenticator app.
- Protect money: banks, cards, payment apps and crypto wallets.
- Freeze credit or place fraud alerts if identity details were exposed.
- Work through the remaining accounts, then keep watching for a few weeks.
Step 0: work from a clean device
Do not change important passwords on a PC that may still be infected. A keylogger or a remote access trojan would capture the new passwords as you type them. Use a phone, a tablet or another computer that was not involved, signed in over a network you trust.
If the infected PC is the only computer you have, use your phone for the urgent accounts (e-mail and banking), then clean the PC before doing the rest. Run a full scan and a Microsoft Defender offline scan first: Run a Microsoft Defender Offline scan. If a remote access trojan was involved, reset Windows before logging in to anything on it: clean up or reset Windows.
If you only typed details into a phishing page and did not run any file, the PC itself is probably fine. In that case the risk is limited to what you typed, and you can work from the same PC.
Step 1: your main e-mail account
Start with the e-mail address that your other accounts use for password resets. For most people this is a Gmail, Outlook.com, iCloud or internet provider address.
- Change the password to a new one you have never used anywhere. Use a password manager to generate it.
- Check the security activity or recent sign-ins page for logins you do not recognise, and note them.
- Check forwarding and filters or rules. A common trick is to add a rule that forwards all mail to the attacker, or one that moves security alerts and bank messages to an archive or the deleted items folder, so you never see them.
- Check recovery options: the recovery phone number and recovery e-mail must be yours. Attackers often add their own so they can take the account back later.
- Check connected apps and app passwords, and remove any you did not set up. A third-party app with mailbox access keeps working after a password change.
- Sign out of all other sessions (Step 2) before you move on.
If you cannot sign in at all because the attacker changed the password, use the provider's account recovery form from a clean device, and do it quickly: recovery is easier while your old phone number and recovery address are still attached. The UK National Cyber Security Centre's guide to recovering a hacked account, listed in the sources below, walks through the same checks.
If you use more than one important e-mail address, repeat these steps for each, starting with the one linked to banking.
Step 2: sign out of all sessions
A password change does not always end sessions that are already open. If a stealer copied your session cookies, the attacker may stay signed in even after you change the password, and two-step verification will not stop them, because that session already passed it.
Most large services have a way to end all other sessions. Look in the account's security settings for a list of signed-in devices or an option to sign out of all devices or everywhere. Use it for:
- your e-mail accounts;
- your Microsoft, Google and Apple accounts, which often hold saved passwords, files and payment methods;
- your password manager, if it has a session list;
- social media and messaging accounts (Facebook, Instagram, X, TikTok, Discord, Telegram, WhatsApp linked devices);
- gaming platforms (Steam, Epic Games, Battle.net, Xbox, PlayStation), which are frequent targets;
- cloud storage and work accounts. For work accounts, tell your IT department instead of acting alone.
Then remove any device you do not recognise from the trusted device list, so it is not allowed to skip two-step verification next time.
Step 3: two-step verification and passkeys
Two-step verification means a stolen password alone is not enough to sign in. Turn it on for e-mail first, then money, then everything else that supports it. The detailed steps per service are in Turn on two-step verification / secure a hacked account.
Not every second step is equally strong:
- Passkeys and hardware security keys are the strongest. They are tied to the real website, so a phishing page cannot use them, and there is no code to steal or type. CISA calls this kind of protection phishing-resistant.
- Authenticator apps that show a six-digit code, or approve a prompt, are a good choice. Pick an app that shows the number you must match, so a flood of prompts cannot trick you.
- Text-message codes are better than nothing, but they can be redirected through SIM swapping and typed into phishing pages.
When you set it up, save the backup codes somewhere offline, for example printed and kept at home. If the attacker already turned on two-step verification on your account with their own phone, remove their method and add yours.
Remember the limit: two-step verification protects the login, not a session that already exists. That is why Step 2 comes first.
Step 4: banks, cards, payment apps and crypto
Banks and cards
If card details were saved in a browser, typed into a phishing page, or visible to a remote attacker, call your bank or card issuer using the number on the back of the card, and ask for the card to be cancelled and replaced. Ask them to check recent transactions and to add extra monitoring. If you already lost money, speed matters: banks can sometimes stop or recall a transfer only within a short window. See What to do after paying a scammer.
Change online banking passwords and PINs from a clean device, and turn on transaction notifications in the bank's app so you see every payment.
Payment apps and shops
Change passwords and end sessions for PayPal, Amazon and other shops that store a card, and check for new delivery addresses, linked cards or gift card purchases you did not make.
Crypto wallets
A wallet is different from an account: you cannot reset it. If a stealer could have copied a wallet file, a browser wallet extension or a seed phrase, create a brand-new wallet on a clean device and move the funds there as soon as possible. Changing the wallet password does not help, because the attacker has the old wallet data or seed. On exchanges, change the password, end sessions, check withdrawal address allowlists and API keys, and turn on a withdrawal lock if the exchange offers one.
Crypto transfers cannot be reversed. Ignore anyone who contacts you offering to recover stolen crypto for a fee; this is a common follow-up scam.
Step 5: credit freeze and identity protection
If personal details such as your full name with date of birth, address, Social Security number, passport or ID scans were on the PC or entered into a phishing page, protect yourself against new accounts being opened in your name.
In the United States, a credit freeze stops lenders from seeing your credit report, so no one can open new credit in your name. According to the FTC, a freeze is free, does not affect your credit score, and lasts until you lift it. You have to contact each of the three bureaus, Equifax, Experian and TransUnion: Freeze your credit after a breach. A fraud alert is a lighter option: you contact one bureau, which tells the other two, and an initial alert lasts one year.
If someone has already used your identity, IdentityTheft.gov gives a recovery plan. Outside the US, ask your bank about fraud protection and contact your national fraud reporting service: where to report cybercrime.
Step 6: the remaining accounts, then keep watching
Now work through the rest of the accounts that were saved in the browser or password manager on the infected PC. Most browsers have a password checkup that lists saved passwords; use it as your to-do list. Change each password to a unique one, ending sessions where possible. Prioritise accounts that hold money or personal data, accounts that can post as you, and any account that used the same password as another.
For the next few weeks, watch for:
- sign-in alerts and password reset messages you did not request;
- new forwarding rules, recovery details or connected apps reappearing;
- friends receiving messages or links from your accounts;
- small test transactions on cards or bank accounts;
- letters or e-mails about accounts, loans or orders you did not open.
Breach notification services such as Have I Been Pwned can alert you when your e-mail address appears in a known leak. If something reappears, assume a device is still compromised or a session is still open, and repeat Steps 1 and 2.
Common mistakes
Changing passwords on the infected PC
A keylogger or remote access trojan sees the new password as you type it. Use another device, or clean the PC first.
Changing the password but not ending sessions
Stolen cookies can keep an attacker signed in. Always sign out of all devices after a stealer infection.
Starting with the account that was attacked instead of the e-mail
If the attacker still reads your mailbox, they can reset any password you change. E-mail comes first.
Only changing the wallet password
A wallet's seed phrase cannot be changed. Move the funds to a new wallet.
Assuming phishing and malware need the same response
A phishing page gets only what you typed into it, so you secure those accounts. Malware can take everything saved on the PC, so you secure every account that was saved or used there.
- Information stealers: what they take from a Windows PC and how fast
- Phishing e-mails and text messages: how they work and how to spot them
- Remote access trojans and backdoors: what an attacker can do and how to lock them out
- Where to report ransomware, scams and cybercrime: US, UK, Canada, Australia, EU
- Clean up or reset Windows after malware: how to decide
Frequently asked questions
Which password should I change first after a virus?
Your main e-mail account, from a clean device such as your phone. E-mail is the recovery route for almost every other account, so an attacker who controls it can reset any password you change afterwards. After the e-mail password, check forwarding rules and recovery options, then sign out of all sessions. Next come online banking and payment accounts, your Microsoft, Google or Apple account, and crypto wallets. Then work through social media, shopping, gaming and the rest. If the same password was used in several places, change it everywhere it was used, starting with the accounts that hold money or personal data.
Is changing my password enough after a hack?
Often not. Information stealers copy session cookies, which keep a browser signed in. With a valid cookie, an attacker stays logged in after the password change and is not asked for a two-step code. Use each service's option to sign out of all devices, remove devices you do not recognise, and check recovery phone numbers, recovery e-mail addresses, forwarding rules and connected apps, which attackers add to get back in later. Then turn on two-step verification. On services where changing the password ends all sessions automatically, the separate sign-out step does no harm.
Should I change my passwords before or after removing the malware?
The most urgent ones before, but only from a different, clean device. If you use the infected PC, a keylogger or remote access trojan can capture the new passwords as you type them. So change your e-mail and banking passwords from your phone right away, then clean the PC with a full scan and a Microsoft Defender offline scan, or reset Windows if a remote access trojan was involved. After the PC is clean, you can use it again for the remaining accounts. If you have no other device, clean the PC first, then change everything.
What should I do if my crypto wallet was on the infected PC?
Create a new wallet on a clean device and move the funds to it as soon as you can. A wallet's security rests on its seed phrase and wallet file, and if a stealer copied either, the attacker can empty it at any time. Changing the wallet password does not help. If you use a hardware wallet and never typed its seed phrase on the PC, the funds are much safer, but check the addresses you send to. On exchanges, change the password, end sessions, review API keys and withdrawal addresses. Crypto transfers cannot be reversed, and recovery services that contact you are usually scams.
Do I need to freeze my credit after malware?
Only if identity details were exposed, such as your Social Security number, date of birth with your address, ID or passport scans, or tax documents stored on the PC or typed into a phishing page. In that case a freeze is a cheap, strong protection in the United States: the FTC says it is free, does not affect your credit score and lasts until you lift it. You place it separately with Equifax, Experian and TransUnion. If only passwords and cookies were stolen, a freeze is not necessary; focus on the accounts instead.
How do I check if the attacker set up e-mail forwarding?
In your e-mail's web version, open the settings and look at three places: forwarding addresses, filters or rules, and connected apps. Attackers add a forwarding address so they receive copies of your mail, or a rule that moves messages containing words like bank, password or security to the archive or deleted items, so you do not see alerts. Delete anything you did not create. Also check the recovery phone and e-mail. The UK NCSC advises checking forwarding rules before changing passwords, because otherwise the reset messages may go straight to the attacker.
Are passkeys better than two-step verification codes?
Yes, for most people. A passkey is tied to the real website and stored on your device or in your password manager, so it cannot be typed into a phishing page and there is no code for anyone to intercept. CISA describes this kind of method as phishing-resistant. Authenticator app codes and prompts are a good second choice; text-message codes are the weakest form but still better than a password alone. Keep in mind that no login method protects a session that malware already stole, so after an infection you still need to sign out of all sessions.
Sources
- NCSC (UK): Recovering a hacked account (read 4 October 2026)
- FTC Consumer Advice: Credit Freezes and Fraud Alerts (read 4 October 2026)
- CISA: More than a Password (multifactor authentication) (read 4 October 2026)
- CISA: Implementing Phishing-Resistant MFA (fact sheet) (read 4 October 2026)
- FTC: IdentityTheft.gov (read 4 October 2026)
- Google Security Blog: Improving the security of Chrome cookies on Windows (read 4 October 2026)
Ugnius Kiguolis, Owner and editor of 2-spyware.com. Ugnius Kiguolis owns and edits 2-spyware.com and is responsible for its Windows security guides. Every page he signs is checked against current vendor, law-enforcement and Microsoft sources before it is published and again when the facts change.