How to document a compromised account before requesting recovery
Immediate priorities after you suspect a compromise
The first priority is containment and documentation, not investigation. If you still have any access, avoid making changes that could erase evidence: do not delete alerts, messages, or logs that show unusual activity. Note the exact date and time you first noticed the issue and any immediate effects (locked out, unexpected changes, transactions).
If you no longer have access to the account, focus on preserving external evidence you control: copies of notification emails, SMS messages, billing statements, and any alerts from the service provider. Remember that any access to systems, accounts or devices that are not yours must be authorized by the account holder or by law enforcement; otherwise, hand over devices or evidence to an authorized representative or professional.
- Record the time and how you discovered the issue
- Do not delete notification emails, alerts, or transaction receipts
- Avoid making changes that could overwrite logs or other evidence
Preserve account-related evidence
Collect and secure all messages and notifications tied to the account, such as password reset emails, login alerts, and billing notices. Take clear screenshots or export copies of relevant emails and messages from your own device or mailbox, and keep originals where possible. Attach timestamps or note when each item was received.
Make a concise log of activity you believe is suspicious: dates, times, descriptions, device names if known, and any actions the intruder took (e.g., changed profile details, unauthorized purchases). If you have transaction IDs or reference numbers from billing records, include those. Keep this evidence organized for when you contact official support or authorities.
- Save notification emails/SMS and take screenshots with timestamps
- Export billing or transaction records related to suspicious activity
- Create a simple timeline listing suspicious events and their dates
Capture device and network context without altering systems
Document which devices or networks were used to access the account when you noticed the issue (work computer, personal phone, public Wi‑Fi). Note whether multiple devices show the same suspicious activity. If devices are under your control, keep them powered on and avoid reinstalling systems or clearing browser history until an authorized review is possible.
If you need technical details (IP addresses, session logs, browser headers), request them from the service provider rather than attempting to extract them yourself unless you are the account owner and authorized to do so. Service providers and law enforcement can often supply server-side logs that are more reliable and admissible than user-side copies.
- List devices and networks that accessed the account
- Avoid wiping devices or clearing histories unless advised by an authorized expert
- Request server-side logs from the service provider when preparing your case
Prepare clear documentation for official support
When you contact the platform’s support team, present a concise, factual packet: a timeline of events, copies of alerts and correspondence, transaction or reference numbers, and a statement of what access you have lost. Use plain language and include your preferred contact details. Explicitly state that you are the account owner or authorized representative.
Include proof of identity and account ownership as required by the service (for example, account creation details or billing information), but never share credentials or passwords in support requests. If the account owner cannot act, obtain written authorization that the provider accepts, and mention that any further actions should be authorized in writing.
- Prepare a timeline and copies of all notifications and receipts
- Provide proof of identity or ownership when requested—do not share passwords
- If acting for someone else, have written authorization ready for the provider
How to communicate with support and authorities
Start with the platform’s official recovery channels and follow their documented procedures. Keep all correspondence, ticket numbers, and SLA references. If the platform requests additional documentation, supply only what is necessary and avoid sending sensitive credentials via insecure channels.
If the compromise involves significant financial loss, identity theft, or criminal conduct, consider reporting to local law enforcement and inform the service provider. Law enforcement can request logs from providers and may advise on preserving evidence. Always ensure any investigative steps are authorized by the account owner or legally mandated before proceeding.
- Use official support channels and keep ticket numbers
- Provide only requested documents; never send passwords
- Report criminal activity to law enforcement when appropriate and authorized
When to seek professional or authorized help
If evidence collection or device preservation requires technical expertise, engage a qualified, authorized cybersecurity professional or a digital forensics specialist. They can create forensic copies and document chains of custody without altering data. Only work with providers who operate under proper legal and ethical standards and with written authorization from the account holder.
Authorized recovery services and legal counsel can help translate technical evidence into a format support teams or courts accept. They can also help determine whether to escalate to law enforcement. Avoid unvetted “shortcut” services that ask for account credentials or promise guaranteed recovery—these can further jeopardize your case.
- Hire authorized digital forensics or cybersecurity professionals when needed
- Ensure written authorization and chain-of-custody documentation
- Avoid services that require sharing account passwords or that make risky promises
Perguntas frequentes
How quickly should I start documenting a suspected compromise?
Begin immediately. The sooner you preserve notifications, emails, and receipts, the better the chance of retaining intact evidence. Do not alter or delete potential evidence and record the time you first noticed the issue.
Can I recover logs or IP addresses myself if I lost access?
If you are the account owner, you can provide server-side data to the provider or request logs through official support. If you cannot access the account, ask the service provider or law enforcement to obtain server-side logs; avoid attempting unauthorized access to systems you do not control.
What proof of ownership will support teams usually require?
Requirements vary by provider but commonly include account creation details, recent billing or transaction records, registered email or phone numbers, and government ID in some cases. Provide only what the provider requests and never share passwords in documentation.
Should I report the compromise to the police?
If there is financial loss, identity theft, or evidence of criminal activity, filing a police report is advisable. Law enforcement can assist in obtaining provider logs and may be required by some services before taking certain recovery actions. Ensure any involvement is authorized by the account holder.
What should I avoid when preparing evidence?
Do not reset passwords, delete alerts, or wipe devices if doing so would destroy evidence unless directed by an authorized expert. Avoid sharing credentials with third parties and do not use unverified recovery services that request passwords or sensitive access.
Read also
Documenting a compromised account carefully helps official support and authorities assess your recovery request
Documenting a compromised account carefully helps official support and authorities assess your recovery request. If you need help preserving or interpreting evidence, consider an authorized professional and always act with the account holder’s written permission. Contact the platform’s official support or a qualified specialist to take the next authorized step.
Fale com a equipa