Household Records, Digital Life and Communications · Chapter 6

Account recovery, identity theft and system audits

Know the recovery sequence before you need it. Audit the system before it drifts.

Recognize the signs

When an account is compromised

The FTC identifies warning signs that an account may have been taken over: the household member cannot log in with the usual credentials, the password or username was changed without their action, login notifications arrive from unfamiliar locations or devices, messages are sent that the user did not write, or recovery information has been changed.

Not every unusual notification means compromise. But any of these signs on an important account warrants immediate investigation using the recovery sequence.

The household recovery procedure

The hacked-account recovery sequence

The FTC recommends a specific sequence for recovering a compromised account. Changing the password alone is not sufficient.

1

Secure the device

Update the device and check for malicious software before using it to recover the account.

2

Use the provider's official recovery

Go directly to the service's recovery page. Do not use links from suspicious emails or messages.

3

Change the password

Use a strong, unique password. If the old password was reused elsewhere, change it on those accounts too.

4

Sign out all other sessions

Remove every device session so the attacker loses access even if they are still logged in.

5

Enable MFA

If MFA was not enabled, turn it on now. If it was enabled and bypassed, review the MFA method.

6

Review recovery information and settings

Check that recovery email, phone, and backup methods have not been changed. Inspect forwarding rules, linked accounts, and authorized apps for anything unfamiliar.

7

Notify contacts

If the account was used to send fraudulent messages, warn contacts through a different channel.

For the complete recovery guide with provider-specific recovery links, see When Accounts Are Compromised.

The chain reaction

Why email compromise requires a broader review

Because email receives password-reset links for many other services, an email compromise is not a single-account event. An attacker with access to the primary email can potentially request reset links for banking, shopping, cloud storage, cellular, social media, government, and tax accounts.

After recovering a compromised email account, review every high-priority account that uses that email for password resets or recovery. Check for unauthorized password changes, unfamiliar activity, altered recovery settings, and new forwarding rules. This review is the most time-consuming part of email recovery and the most important.

When personal information is misused

Identity theft and recovery

The FTC defines identity theft as the use of personal or financial information without permission. It can involve new credit opened in someone's name, unauthorized purchases, utility fraud, tax return filing, employment fraud, medical identity theft, or benefits fraud.

IdentityTheft.gov

The FTC directs identity theft victims to IdentityTheft.gov. The service creates an FTC Identity Theft Report, generates a personalized recovery plan, provides letters and forms for affected organizations, and tracks progress. It is free and does not require purchasing an identity protection subscription.

Credit freezes, credit report monitoring, and credit-related identity theft steps are covered in Credit Reports and Scores. Crisis-level identity theft response is covered in Fraud and Identity Theft in the Disruptions section.

Keep the system working

The annual household audit

A system built once and never reviewed drifts. Recovery phone numbers go stale. Devices fall out of update support. Subscriptions accumulate. The annual audit is what keeps the household information system functional as circumstances change.

Records

  • Important originals accounted for
  • Working copies current
  • Expired or obsolete records removed
  • Retention reviewed per governing rules

Backup

  • Last backup date confirmed
  • Restore test completed
  • Backup separation verified

Accounts

  • Recovery contact information current
  • MFA status on important accounts
  • Unknown devices removed from sessions
  • Obsolete accounts identified

Devices and network

  • Operating systems still receiving updates
  • Router firmware current
  • Admin and Wi-Fi credentials reviewed
  • Connected devices recognized

Contacts

  • Provider and emergency contacts current
  • Communication channels still working
  • Second person knows where directory is

Subscriptions

  • Unwanted services canceled
  • Account ownership documented
  • Payment methods reviewed

This is a household operating practice, not a government-mandated audit. The goal is to catch drift before it causes a lockout, a missed bill, or a recovery problem that could have been prevented with a few minutes of review.

Unit complete

The continuity test

The household information system works when it passes one test: if the person who usually manages records and online accounts were unavailable for seven days, could another authorized adult determine what systems exist, how to contact providers, where records are located, what bills and services need attention, and how to use legitimate recovery or delegated-access procedures without guessing passwords?

If the answer is yes, the system works. If the answer reveals gaps, each gap points to a specific chapter in this unit.