Recover access without giving it away
A failed sign-in can be a forgotten password, an expired session, a second-factor problem, a locked account, a provider outage or a sign of compromise. The safest response is to identify the route, protect your recovery information and use the provider’s real support process.
Check the account name, the official provider status route and whether the problem is a password, verification, device or access-policy issue. Use recovery from the provider’s known website or app. Never share a password, recovery code or one-time verification code, and treat unfamiliar reset messages or support calls as suspicious.
Separate access problems by type
| Symptom | Safer first check | Do not do |
|---|---|---|
| Password is rejected | Confirm the official account name and use the provider’s genuine password-recovery route if needed. | Keep guessing until the account locks or reuse a password from another service. |
| Verification code does not arrive | Check the expected authenticator, device time, signal and provider guidance; use approved backup methods only. | Give a code to anyone who calls, messages or claims to be support. |
| Account is locked or restricted | Read the exact official message and follow the provider’s documented review or recovery route. | Create workarounds that breach an organisation’s policy or hide the original issue. |
| Unexpected security notice | Open the provider through a known app or typed address and review account activity there. | Use links or numbers in the unexpected notice. |
Use a secure recovery sequence
- Pause if you see unfamiliar activity, changed recovery details or a request you did not initiate. Preserve the message without clicking its links.
- Reach the account provider through its official website, app or previously verified support contact.
- Complete the documented recovery process on a device and connection you trust where practical.
- After recovery, review recovery details, active sessions, forwarding rules and unique passwords; enable multi-factor authentication where available.
- Tell relevant contacts or an internal security team if an account may have been used to send messages, access shared records or affect money.
Official recovery beats a plausible message
The NCSC advises using an account provider’s own support pages and independently verified contact details when access is lost. Its hacked accounts guidance also explains why checking recovery paths and reused passwords matters. CISA’s Secure Our World resources cover strong passwords, multi-factor authentication, phishing and updates.
Account access FAQs
Should I give a support agent my one-time code?
No. A genuine provider may ask you to enter a code on its own legitimate website or app, but you should not read or forward a code to a caller, chat contact or unexpected message.
What if the recovery email is no longer available?
Use the provider’s documented alternative recovery route from its known website. It may ask for verification that only you should provide through that official process.
Can a sign-in issue mean my account was hacked?
It can, especially with unfamiliar activity, changed settings or reset notices you did not request. Do not assume it is merely a forgotten password; use the official recovery route and review account security afterwards.
Choose the next safe step
Use the guide that matches the evidence you have, the impact of the problem and the reversibility of the next action. Do not rush from uncertainty to an irreversible change.
