How to know if you’ve been hacked

How to know if you’ve been hacked

Natalie Moore
April 20, 2026· 7 min read

If you are wondering how to know if you’ve been hacked, do not focus on a single symptom like a slow computer. A better approach is to look at accounts, phones, computers, browsers, and payment alerts together. Many real compromises do not start with the device. They start with email, social accounts, cloud sync, or reused passwords.[1][2][3]

This guide is not only about computers or phones. It is about a practical question: when strange things appear in several places at once, which signals should no longer be dismissed as “the system being unstable”?

Use the digital privacy guide as the wider checklist: it connects this issue to accounts, devices, identifiers, and data-broker exposure.

Key Takeaways

  • The real warning sign is usually not one slow device, but several unusual events appearing together.[1][2]
  • Unknown sign-in alerts, changed passwords, altered security settings, and contacts receiving strange messages are more urgent than “my device feels slow.”[1][2][3]
  • Protect accounts first, then investigate devices. That is usually more useful than first trying to identify the exact attack method.
  • If email, payments, or cloud storage are involved, raise the priority immediately.
  • An “I hacked you” extortion email does not prove the account was hacked. It may be scareware or credential-stuffing language. That judgment follows official security guidance.[1][4]

How to know if you’ve been hacked: 8 cross-device signs

You do not need all eight signs at once. If several begin appearing together, take action.

1. You receive unfamiliar sign-in alerts

Google and Microsoft provide recent activity and security alert pages that can show time, location, device type, and whether an activity looks unusual.[1][2][3]

Treat it seriously if you see:

  1. a location you have not visited;
  2. a device you do not use;
  3. a security challenge you did not start.

That is harder to dismiss as a random glitch.

2. Your password or recovery information changed

Microsoft’s recent activity guidance says that if you see password changes, profile changes, or suspicious activity you do not recognize, you should secure the account immediately.[1]

Watch for:

  • password changes;
  • recovery email or phone changes;
  • replaced two-factor methods;
  • trusted devices removed from the account.

3. Contacts receive messages you did not send

This is a high-priority sign. Microsoft’s public guidance on hacked social accounts mentions random posts, suspicious direct messages, and abnormal account content as possible signs of takeover.[5]

It is clearer than ordinary slowness because the problem has become visible to other people.

4. Device settings changed without explanation

On phones, look for changes in location, accessibility, notification permissions, or device management. On computers, watch for changed search defaults, proxy settings, protection settings, startup items, or browser extensions.[1][3]

For device-specific checks:

5. Your browser redirects, shows pop-ups, or displays fake alerts

A changed homepage, constant redirects, and “fix now” security pop-ups should not be ignored. FTC guidance on malware and tech support scams warns that fake alerts and malicious redirects are often used to make you click, pay, or grant remote access.[4][6]

If the issue started from an email, text, or login page, compare it with how to recognize and prevent phishing attacks.

6. Battery, data use, or performance looks wrong

A hot phone, loud computer fan, or sudden data spike does not prove hacking by itself. But when it appears alongside unfamiliar logins, permission changes, pop-ups, or extension issues, treat it as more serious. This is a practical synthesis of Google, FTC, and Microsoft guidance.[1][3][6]

7. You are locked out of an account

If you suddenly cannot sign in, or your correct password no longer works, do not spend too long debating whether it was a mistake. Start the official recovery process and review recent activity.[1][2]

8. You recently did something high-risk

Examples include:

  • clicking an unknown email or text link;
  • downloading unknown software;
  • entering credentials into a pop-up;
  • giving a stranger remote access;
  • reusing the same password across sites.

That context can make “suspicious but uncertain” signs much more meaningful.

Do these 5 things before trying to prove exactly what happened

Many people get stuck trying to investigate first and lose time.

Step 1: Secure email and primary accounts first

Start with email, Apple ID, Google account, payment accounts, and cloud storage. If these fall, other accounts can follow.

Step 2: Change passwords and remove unknown devices

Use a trusted device. Do not handle everything from a suspicious environment. Google and Microsoft account security pages let you review activity and protect the account.[1][2][3]

Step 3: Check two-factor and recovery settings

Make sure backup emails, phone numbers, and verification methods still belong to you.

Step 4: Scan devices and inspect browsers

Check extensions, proxies, startup items, unknown apps, and device management permissions.

Step 5: Review payments and breach fallout

If the recovery chain may be affected, especially email and reset access, read how to secure your email account.


Which “you’ve been hacked” messages may be scams?

Not every warning is real.

Be especially careful with:

  • extortion emails claiming “I control your device”;
  • web pop-ups saying “37 viruses found”;
  • calls or pop-ups telling you to contact tech support immediately;
  • payment demands to unlock your device.

FTC guidance on tech support scams is clear: do not call support numbers shown in pop-ups, and do not give remote access because of a fake alert.[4][6]

Being hacked is a real risk. Being tricked by someone claiming you were hacked is also a real risk.

My practical test: one symptom matters less than several layers failing together

If only the computer is slow, observe. If only the phone is warm, it may be background updates.

But if you see:

  1. device problems;
  2. sign-in alerts;
  3. browser redirects;
  4. contacts receiving strange messages;

stop treating them as isolated events.

Summary

  • How to know if you’ve been hacked is not about finding one perfect clue. It is about seeing whether account, device, and browser anomalies appear together.
  • Unknown sign-ins, changed passwords, strange messages from your account, and security setting changes usually matter more than device slowness.
  • Protect accounts first, then investigate devices. That is the safer order for most users.
  • When you see a “you were hacked” warning, also check whether it is trying to scam you under the cover of security.

FAQ

Does a slow computer mean I was hacked?

Not necessarily. Slowness alone is not enough, but redirects, pop-ups, and account anomalies raise the risk.[6]

Does an unusual sign-in alert mean someone got in?

Not always. Some alerts are blocked attempts, but you should still investigate if you did not start the activity.[2][3]

What does it mean if contacts receive messages I did not send?

It often means the account is being used by someone else, so the priority is high.[5]

Is an extortion email saying “I hacked your device” always real?

No. Many are scare scams, but you should still review account activity and password safety.[4]

Should I change passwords or run antivirus first?

If email, payments, or primary accounts are involved, secure accounts and change passwords first.

Can a VPN tell me whether I was hacked?

No. A VPN protects the connection path. It does not detect account takeover or malware infection.


Disclaimer

This article is for general digital safety education only and does not constitute legal, forensic, or enterprise incident response advice. Security alert interfaces vary by platform and version.

The AethoVPN editorial team covers signs of being hacked here; a VPN is not a substitute for the relevant checks.

Sources

  1. Microsoft Support, What is the Recent activity page?: https://support.microsoft.com/en-us/account-billing/check-the-recent-sign-in-activity-for-your-microsoft-account-5b3cfb8e-70b3-2bd6-9a56-a50177863357?ns=MSFTTEAMS
  2. Google Account Help, Respond to security alerts: https://support.google.com/accounts/answer/2590353?hl=en
  3. Google Account Help, Investigate suspicious activity on your account: https://support.google.com/accounts/answer/140921?hl=en-WS
  4. FTC Consumer Advice, How To Spot, Avoid, and Report Tech Support Scams: https://consumer.ftc.gov/articles/how-spot-avoid-and-report-tech-support-scams?os=io__
  5. Microsoft 365, Eight signs your social media accounts were hacked: https://www.microsoft.com/en-us/microsoft-365-life-hacks/privacy-and-safety/eight-signs-your-social-media-accounts-were-hacked
  6. FTC Consumer Advice, Malware: How To Protect Against, Detect, and Remove It: https://consumer.ftc.gov/node/78347

Sources checked 8 May 2026.


Related Articles:

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

How to know if you’ve been hacked | AethoVPN