Most situations turn out fine when you act in the right order. Follow the steps. Need help? Call me
If something goes wrong

It just happened? Don't panic.

Here are the right moves, explained simply, in the order they should be done. In the vast majority of cases you can already limit the damage yourself. And if you'd rather not be alone with it, I'm here.

Click your situation to see the steps to follow.

Good news: in most cases, you can take it back within minutes.

Do this, in order

  1. Open WhatsApp and log back in with your phone number. The SMS code you receive automatically kicks out whoever took your account.
  2. Turn on two-step verification: Settings → Account → Two-step verification. It's the most effective protection, and it takes two minutes.
  3. Check Settings → Linked devices and log out anything you don't recognize.
  4. Warn your contacts by SMS or phone call. The attacker often impersonates you to ask for money: a quick message protects them.

Avoid

  • Don't click "recovery" links you receive by message: they're often a second scam attempt.
  • Never share a 6-digit SMS code, even with someone who claims to be a friend.
Account still locked? I'll help

Your mailbox gives access to many other accounts, so it's worth being methodical. But it's entirely fixable.

Do this, in order

  1. Change the password from a safe device, for example your phone, rather than the computer you're suspicious of.
  2. Turn on two-factor authentication, ideally with a dedicated app rather than SMS.
  3. Check the auto-forwarding rules in your settings: some attackers create them to quietly keep reading your mail.
  4. Review connected devices and apps and remove anything you don't recognize.
  5. Then change the passwords of important accounts tied to that address, starting with your bank.

Avoid

  • Avoid reusing a variation of the old password: a completely new one is far safer.
Review my accounts together

A clicking or scraping drive is wearing itself down. The good news: if you stop it right away, the data is very often recoverable.

Do this, in order

  1. Turn the computer off right away, without waiting to make "one last backup". This is the move that saves your data.
  2. Don't power the drive on again. Each restart can make the damage worse.
  3. Write down what you heard (clicks, scraping, beeps): it helps a lot with the diagnosis.
  4. Contact me or a properly equipped professional. Recovery from a damaged drive needs specific tools, but it succeeds very often.

Avoid

  • No recovery software on a drive that makes noise: it forces reads and can make the data permanently unrecoverable.
  • No freezer, despite what you may read online: moisture damages the inside of the drive.
  • Don't open the drive: a single speck of dust is enough to ruin everything.
How I work: I always start by making a complete, secure copy of the drive, then recover your files from that copy. Your original drive is never put at risk. And if something is unrecoverable, I tell you honestly.
Recover my data

It happens to everyone, even IT people. What matters is what you do now.

Do this, in order

  1. Entered a password? Change it right away on the real site, and everywhere you use the same one.
  2. Entered banking details? Call your bank: block the card and check the recent transactions.
  3. Downloaded or opened a file? Disconnect the computer from the internet until it can be checked.
  4. Keep the fraudulent email or SMS: it's useful as evidence, especially for the bank.
Have my computer checked

The faster you act, the less time the attacker has to impersonate you with your contacts.

Do this, in order

  1. Try "Forgot password" with your email or phone number: if the attacker hasn't changed the address yet, you're back in immediately.
  2. If the account email was changed, use the official recovery flow: instagram.com/hacked or facebook.com/hacked. It's the only real channel.
  3. Turn on two-factor authentication as soon as you're back in.
  4. Check active sessions and connected apps in the security settings, and remove anything you don't recognize.
  5. Warn your contacts through another channel: attackers often send scams in your name.

Avoid

  • Never pay an "account recovery service" found online or in your DMs: they're almost always scams.
  • Don't trust accounts offering help by DM right after the hack: it's often the attacker themselves.
Stuck in the process? I'll guide you

A page that screams, beeps and shows a phone number is never a real Microsoft or Apple message. It's theatre, and your computer is most likely fine.

Do this, in order

  1. Don't call the number on screen. Ever. That's the whole point of the scam.
  2. Close the browser, force-quitting if needed (Ctrl+Alt+Del on Windows, Cmd+Option+Esc on Mac), then restart if the screen stays stuck.
  3. If you did call and let someone take control of your computer: disconnect it from the internet, change your important passwords from another device, and call your bank if any payment was made.
  4. Have the machine checked if anyone had access to it, even briefly.

Avoid

  • Don't install any software dictated to you over the phone.
  • Never give a card number or make a "verification" transfer: no real tech support asks for that.
Have my computer checked

A site you use got breached and your email or password is circulating. It's common, and very manageable if you deal with it right away.

Do this, in order

  1. Change the password on the affected site.
  2. Change it everywhere else you used the same one: that's exactly what attackers try first.
  3. Turn on two-factor authentication on important accounts (email, bank, social media).
  4. Switch to a password manager so every site gets a unique password: the next breach will only ever touch one site.
  5. Watch out for targeted emails in the following weeks: scammers use breach data to look credible.

Avoid

  • Don't think "that site had nothing important": the real danger is the reused password.
Secure all my accounts in one session
Prevention

Three habits that prevent most problems

No expertise needed. These three things, set up once, protect you for good. I can help you put them in place in a single session.

1

A real backup

An automatic copy of your important files, including one outside your home. The day a drive dies, a virus encrypts your data or a phone falls in the water, you lose nothing that matters.

2

Updates done on time

An up-to-date system and apps means the vast majority of security holes are already closed. Turn on automatic updates: protection happens on its own, in the background, without a second thought.

3

One password per account, plus two-factor authentication

A password manager remembers a unique, strong password for every site so you don't have to. Two-factor authentication (2FA) blocks access even if one password leaks. It's the most effective pair for protecting your accounts.