What I Learned Getting Hacked: Advice From Someone It Happened To
Earlier this year a neighbor of mine got hacked. Not a "someone guessed my Facebook password" hacked. The kind where her phone number got taken over, her accounts got hit one at a time, and months later she is still proving to companies that she is who she says she is. She expects to be dealing with it for at least another year.
She's been sending me what she learned, a bit at a time, and she gave me permission to put it all in one place as long as I only use her first name. So this is Cindy's guide. I've added a few notes where I can fill in the mechanics or point to the right place to go, but the advice is hers, and she earned it the hard way.
Her opening line is the whole reason this exists:
"People think it won't happen to them. They think they have a handle on it. Then it happens and they're surprised."
It's long. Read the first section now and bookmark the rest. If you only do the three things in the first section, you're ahead of almost everyone.
Part 1: Do these before anything happens
This is the part nobody does, because nothing's wrong yet. Everything in it takes minutes. Everything in it took Cindy weeks to undo after the fact.
1. Give your important accounts a second way to reach you
"Your phone number is attached to most accounts for verification. Mine was shut off abruptly by the hack, and I couldn't change it on those accounts first."
Most accounts let you add a backup phone number or a backup email for the security codes. Almost nobody turns it on. Do it now for your bank, your email, your Apple or Google account, and anything with money in it. If your phone number ever stops being yours, the backup is how you get back in.
Where to look:
iPhone: Settings > your name > Sign-In & Security > Two-Factor Authentication. Or at account.apple.com > Sign-In and Security.
Google: myaccount.google.com > Security. Look for the recovery phone and recovery email.
Microsoft: account.microsoft.com > Security.
Banks and everything else: usually under Profile or Security in the app.
While you're in there, look at what's already listed. Remove any phone number or email you don't recognize. And do it now, while everything still works:
"If you find a phone number listed on your Sign-In & Security, you will not be able to remove it unless you have the phone in your hands."
"Access it regularly to make sure you can."
Sign in to the important accounts every so often, on purpose, to prove you still can. Don't find out the day you need them.
My note: most accounts also offer one-time recovery codes, a list of ten or so you print or write down. Save them somewhere that isn't the phone they're meant to rescue.
2. Lock your phone number at the carrier
This is the one Cindy would put at the top if she were writing it. Her number was the master key, and once it was gone, every code every account sent went to someone else.
Here's what actually happened, in plain terms: a criminal convinced her carrier to move her number to a phone they controlled. It's called a SIM swap or a port-out, and it doesn't involve touching your phone at all. Your phone just stops working, and theirs starts getting your texts.
Every major carrier now has a free setting that blocks this. The names:
AT&T: Wireless Account Lock
Verizon: SIM Protection and Number Lock
T-Mobile: SIM Protection and Port Out Protection
Turn them on in the carrier's app under security or account settings, or call the carrier and ask for it by name. If the menu on your phone doesn't match what you expect, call. The names above are current as of this writing; the apps get rearranged constantly.
Set a PIN on the carrier account while you're at it, one that isn't your birthday or the last four of your Social.
3. Set every alert to $1
"Set alerts at $1 on every chargeable account. And LOOK when a notification wakes you up. Middle-of-the-night orders are timed so the transaction completes while you sleep."
Every card, every bank account, every app that can spend money. A dollar. You'll get some noise from your own coffee purchases. That's fine. The one that matters is the one at 3 a.m. you didn't make.
4. Close what you don't use
"Close accounts you've stopped using. Anything that might carry a cash balance or a credit card number is considered useful. Any personal information is useful."
An old shopping account with a saved card is a door you forgot about. Old email addresses count too, especially if they're still the recovery email for something.
5. Know about linked accounts
This is one of the two things in here that only a survivor would know.
"Linked membership accounts, like Sam's or Costco, that are attached to a card: change passwords on BOTH. If orders you didn't place show as out for delivery, call BOTH the store and the bank. They're separate companies. Stopping the card does NOT stop an order already placed."
6. Sign out, bookmark, screenshot
"Sign out of purchase and financial apps when you're done, including the linked membership account. An open app is an open door."
"Clear your browsing history after finishing. Bookmark instead. Screenshot every order with its full details."
Bookmark your bank's real website and use the bookmark, or the app. Don't search for it. Fake bank sites live in search results, and they look right.
7. One thing about ATMs
"Wiggle the card slot before inserting your card. If it moves at all, walk away."
Skimmers sit on top of the real slot. They're not attached well.
Part 2: The moment you notice something
Call the fraud department first, sort it out later
"Call the bank's fraud department the moment you notice something. Not after you sort it out."
You don't need to understand what happened before you call. They deal with this all day.
If someone calls YOU: hang up and call back
"If a bank, card company, creditor, or anyone claiming to be a government agency calls about charges, hang up and call back on the number on your card or the agency's public number. Never the number that called you."
"If a caller claims to be from a government agency, get their name, hang up, call the agency, and ask for that person by name. Ignore any extension they gave you. Staff can confirm in seconds. People working for the government in coordination with your bank do not call the customer."
Real fraud departments are fine with you hanging up and calling back. Scammers are not.
Change your recovery info BEFORE your password
This is the other one only a survivor knows, and it's the mistake that locks people out of their own accounts.
"If you have secondary authentication, change your recovery contact info, phone and email, BEFORE changing the password. Or you can literally lock yourself out with no way to get in without jumping through a dozen hoops."
Order matters. First make sure the account can reach you at a number and email you control. Then change the password. Then sign out every other device.
Turning the phone off does not stop it
"Most people think turning off the device that has been hacked will stop everything. It won't. They have your phone. They used over 1 terabyte of data on FaceTime in 3 days with my phone turned off. Get it locked and do what you can working with the carrier."
Here's why that's true: the person who took over her number wasn't using her handset. They were using her number and her account on their own device. Powering off the phone in your hand changes nothing for them. What stops it is the carrier locking the number, and signing out every device from your Apple or Google account (on iPhone: Settings > your name, scroll down to the device list, remove anything you don't recognize).
Change passwords from a different device
"Print your passwords if you have them saved on the phone. You won't realize how many you have until you print the list. This is the hard part. You need another device to get into accounts to change passwords. Do not try to change them on any device that is connected to your phone by a cloud. It will transfer all your changes automatically."
This one catches people. If the phone saves your passwords to the cloud (iCloud Keychain, Google Password Manager), then every new password you type on a connected device syncs right back to the account the attacker is sitting in. Change the cloud account itself first, sign everything else out of it, and do the rest of the password changes from a computer that isn't signed into that cloud.
Then change everything
"Make sure all accounts, affected or not, are secured with new passwords or new accounts."
"If passkeys were set up, remove them and create new ones."
My note on passwords: if you use a password manager with its own separate master password, you don't have to assume every password inside it is burned. If your passwords were saved in the browser or the keychain on the phone or computer that was compromised, assume they're all gone and change them.
Don't restore the new phone from the old backup
"Do not back up the phone. Any backup will include the hacked information."
"I had to trash my phone and start over."
"If you turn off backups when the trouble starts, they will turn them back on. It is their effort to catch anything new you may restore a backup to. That is why I had to start from scratch. I didn't have a clean backup I could use on any device connected to the cloud."
What she's warning about: a backup made after the trouble started carries the trouble with it, and the person in your account wants it that way. If you set up a replacement phone by restoring from that backup, you've moved the problem onto the new phone, which is exactly what they're waiting for. Turning backups off doesn't help either; they just turn them back on. So don't fight over the switch. Set the new phone up fresh, sign in to each account by hand with the new passwords, and copy photos over separately. Most phones keep only the last three backups, so by the time you're done, a backup from before the trouble is usually gone. That's the real reason to have your photos and important files somewhere other than the phone's own backup.
Tell every source of your money
"Tell every source of your money what happened. Banks, credit unions, brokerage, anything. So someone holding your details can't open the next door."
"Treat it as identity theft. New cards on EVERY open account, even with the same company. Close accounts you don't use. And be persistent when the company resists."
Part 3: Filing, and what happens after you file
One website does most of the paperwork
Cindy found this one herself and she's the reason I'm putting it front and center:
"It's a self-checking task list. It reminds you of the next step and hands you the credit bureau numbers."
IdentityTheft.gov. It's run by the Federal Trade Commission. You answer questions about what happened, and it builds you a recovery plan with the next step at each stage, pre-filled letters to send to the credit bureaus and the companies involved, and an official Identity Theft Report you'll need for the rest of this.
Fraud alert vs. credit freeze (this is the part people get mixed up)
"When you file for identity theft, your credit will be monitored closely for at least a year. When you apply for a loan or a credit card, you will have to prove you are who you say you are. It lengthens the process, but it is for your safety."
What Cindy is describing is a fraud alert. It tells any business checking your credit to confirm it's really you before opening a new account in your name. That's why every application takes longer. You place it with one credit bureau (Equifax, Experian, or TransUnion) and that bureau has to tell the other two. It lasts one year and you can renew it. With your Identity Theft Report you can place an extended alert that lasts seven years.
A credit freeze is the stronger tool. While it's on, nobody can open a new credit account in your name at all, including you, until you lift it. It's free. You have to place it at all three bureaus separately, and it doesn't happen automatically when you file. If you're going through this, do both.
The honest way to think about both, in Cindy's words:
"All agencies will be notified, but that doesn't mean they are watching for you. It is your information. You have to take responsibility."
Check your credit reports, free, every week
The one real site is AnnualCreditReport.com (or 1-877-322-8228). You can pull your report from each bureau once a week at no charge. Anything else claiming to give you free credit reports is trying to sell you something or worse. Nobody from the bureaus will email you asking for your Social Security number.
Where to report
IdentityTheft.gov for identity theft (that's the FTC).
ic3.gov if money was actually taken. That's the FBI's channel.
Forward any scam text to 7726 (it spells SPAM). Free, works on every major carrier, and it helps them block the number.
Part 4: Living with it
"First, remember ALL of your information is out there. Your address, phone information, banks, shopping information, birthdate, marital status, everything. Watch your accounts like a hawk and don't get lazy. I have had to replace my credit card four times since this all started. Yes, it got hacked more than once."
"Watch every account daily. You're a target until they see you watching. Then new attackers try."
"I am still working through purchases that were made. One big one was just closed in my favor. It will go on for a while, but we do what we have to do in this day and age."
That's the part nobody warns you about. It isn't one bad week. Cindy is months in, expects at least another year, and is still getting phone calls. The companies aren't uninterested. They're overwhelmed. The person who has to keep pushing is you.
If you do nothing else
Add a backup phone number and email to your bank, your email, and your Apple or Google account, and test that you can still get in.
Lock your phone number at the carrier.
Set every alert to $1 and look when your phone buzzes.
Thank you, Cindy.
David Martin
Information Security Kentucky LLC
Protect. Prevent. Prepare.
Hardin County, Kentucky
Sources for the parts that aren't Cindy's
FTC, Credit Freezes and Fraud Alerts: consumer.ftc.gov/articles/credit-freezes-and-fraud-alerts
FTC, What To Know About Identity Theft: consumer.ftc.gov/articles/what-know-about-identity-theft
FTC, Free Credit Reports: consumer.ftc.gov/articles/free-credit-reports
Apple, About trusted phone numbers and trusted devices: support.apple.com/en-us/122621
Carrier feature names checked September 2026; the AT&T, Verizon and T-Mobile apps move these settings around, so call the carrier if the menu doesn't match.