Household Records, Digital Life and Communications · Chapter 6
Account recovery, identity theft and system audits
Know the recovery sequence before you need it. Audit the system before it drifts.
Recognize the signs
When an account is compromised
The FTC identifies warning signs that an account may have been taken over: the household member cannot log in with the usual credentials, the password or username was changed without their action, login notifications arrive from unfamiliar locations or devices, messages are sent that the user did not write, or recovery information has been changed.
Not every unusual notification means compromise. But any of these signs on an important account warrants immediate investigation using the recovery sequence.
The household recovery procedure
The hacked-account recovery sequence
The FTC recommends a specific sequence for recovering a compromised account. Changing the password alone is not sufficient.
Secure the device
Update the device and check for malicious software before using it to recover the account.
Use the provider's official recovery
Go directly to the service's recovery page. Do not use links from suspicious emails or messages.
Change the password
Use a strong, unique password. If the old password was reused elsewhere, change it on those accounts too.
Sign out all other sessions
Remove every device session so the attacker loses access even if they are still logged in.
Enable MFA
If MFA was not enabled, turn it on now. If it was enabled and bypassed, review the MFA method.
Review recovery information and settings
Check that recovery email, phone, and backup methods have not been changed. Inspect forwarding rules, linked accounts, and authorized apps for anything unfamiliar.
Notify contacts
If the account was used to send fraudulent messages, warn contacts through a different channel.
For the complete recovery guide with provider-specific recovery links, see When Accounts Are Compromised.
The chain reaction
Why email compromise requires a broader review
Because email receives password-reset links for many other services, an email compromise is not a single-account event. An attacker with access to the primary email can potentially request reset links for banking, shopping, cloud storage, cellular, social media, government, and tax accounts.
After recovering a compromised email account, review every high-priority account that uses that email for password resets or recovery. Check for unauthorized password changes, unfamiliar activity, altered recovery settings, and new forwarding rules. This review is the most time-consuming part of email recovery and the most important.
When personal information is misused
Identity theft and recovery
The FTC defines identity theft as the use of personal or financial information without permission. It can involve new credit opened in someone's name, unauthorized purchases, utility fraud, tax return filing, employment fraud, medical identity theft, or benefits fraud.
IdentityTheft.gov
The FTC directs identity theft victims to IdentityTheft.gov. The service creates an FTC Identity Theft Report, generates a personalized recovery plan, provides letters and forms for affected organizations, and tracks progress. It is free and does not require purchasing an identity protection subscription.
Credit freezes, credit report monitoring, and credit-related identity theft steps are covered in Credit Reports and Scores. Crisis-level identity theft response is covered in Fraud and Identity Theft in the Disruptions section.
Keep the system working
The annual household audit
A system built once and never reviewed drifts. Recovery phone numbers go stale. Devices fall out of update support. Subscriptions accumulate. The annual audit is what keeps the household information system functional as circumstances change.
Records
- Important originals accounted for
- Working copies current
- Expired or obsolete records removed
- Retention reviewed per governing rules
Backup
- Last backup date confirmed
- Restore test completed
- Backup separation verified
Accounts
- Recovery contact information current
- MFA status on important accounts
- Unknown devices removed from sessions
- Obsolete accounts identified
Devices and network
- Operating systems still receiving updates
- Router firmware current
- Admin and Wi-Fi credentials reviewed
- Connected devices recognized
Contacts
- Provider and emergency contacts current
- Communication channels still working
- Second person knows where directory is
Subscriptions
- Unwanted services canceled
- Account ownership documented
- Payment methods reviewed
This is a household operating practice, not a government-mandated audit. The goal is to catch drift before it causes a lockout, a missed bill, or a recovery problem that could have been prevented with a few minutes of review.
Unit complete
The continuity test
The household information system works when it passes one test: if the person who usually manages records and online accounts were unavailable for seven days, could another authorized adult determine what systems exist, how to contact providers, where records are located, what bills and services need attention, and how to use legitimate recovery or delegated-access procedures without guessing passwords?
If the answer is yes, the system works. If the answer reveals gaps, each gap points to a specific chapter in this unit.
Return to the hub
Household Records, Digital Life and Communications