Work from the official service
Open the service directly using its known address or app rather than following a link from the suspicious message. Change an exposed password and any other account that reused it. Use a unique password for each account.
Review access, not only the password
Check signed-in devices, recovery details and connected applications. Remove access you do not recognise using the service’s own controls. Enable multifactor authentication; CISA’s guidance explains why an additional factor helps protect accounts.
Preserve evidence without prolonging contact
Keep relevant message references and transaction records privately. Report impersonation or suspicious messages through the platform. If payment details were exposed, contact the payment provider through an independently verified channel.
Do not substitute a photo search for account recovery
A search result cannot tell you whether a session remains active or a recovery email was changed. Complete the provider’s recovery workflow first. Read catfish warning signs if you need help assessing the interaction itself.