How to document a compromised account before requesting recovery

Guia informativo · Leitura aproximada: 6 minutos

If you suspect an account was compromised, act to preserve evidence and prepare a legitimate recovery request for official support. Any actions must be authorized by the account holder; authorities or authorized professionals may be needed.

Immediate priorities after you suspect a compromise

The first priority is containment and documentation, not investigation. If you still have any access, avoid making changes that could erase evidence: do not delete alerts, messages, or logs that show unusual activity. Note the exact date and time you first noticed the issue and any immediate effects (locked out, unexpected changes, transactions).

If you no longer have access to the account, focus on preserving external evidence you control: copies of notification emails, SMS messages, billing statements, and any alerts from the service provider. Remember that any access to systems, accounts or devices that are not yours must be authorized by the account holder or by law enforcement; otherwise, hand over devices or evidence to an authorized representative or professional.

Preserve account-related evidence

Collect and secure all messages and notifications tied to the account, such as password reset emails, login alerts, and billing notices. Take clear screenshots or export copies of relevant emails and messages from your own device or mailbox, and keep originals where possible. Attach timestamps or note when each item was received.

Make a concise log of activity you believe is suspicious: dates, times, descriptions, device names if known, and any actions the intruder took (e.g., changed profile details, unauthorized purchases). If you have transaction IDs or reference numbers from billing records, include those. Keep this evidence organized for when you contact official support or authorities.

Capture device and network context without altering systems

Document which devices or networks were used to access the account when you noticed the issue (work computer, personal phone, public Wi‑Fi). Note whether multiple devices show the same suspicious activity. If devices are under your control, keep them powered on and avoid reinstalling systems or clearing browser history until an authorized review is possible.

If you need technical details (IP addresses, session logs, browser headers), request them from the service provider rather than attempting to extract them yourself unless you are the account owner and authorized to do so. Service providers and law enforcement can often supply server-side logs that are more reliable and admissible than user-side copies.

Prepare clear documentation for official support

When you contact the platform’s support team, present a concise, factual packet: a timeline of events, copies of alerts and correspondence, transaction or reference numbers, and a statement of what access you have lost. Use plain language and include your preferred contact details. Explicitly state that you are the account owner or authorized representative.

Include proof of identity and account ownership as required by the service (for example, account creation details or billing information), but never share credentials or passwords in support requests. If the account owner cannot act, obtain written authorization that the provider accepts, and mention that any further actions should be authorized in writing.

How to communicate with support and authorities

Start with the platform’s official recovery channels and follow their documented procedures. Keep all correspondence, ticket numbers, and SLA references. If the platform requests additional documentation, supply only what is necessary and avoid sending sensitive credentials via insecure channels.

If the compromise involves significant financial loss, identity theft, or criminal conduct, consider reporting to local law enforcement and inform the service provider. Law enforcement can request logs from providers and may advise on preserving evidence. Always ensure any investigative steps are authorized by the account owner or legally mandated before proceeding.

When to seek professional or authorized help

If evidence collection or device preservation requires technical expertise, engage a qualified, authorized cybersecurity professional or a digital forensics specialist. They can create forensic copies and document chains of custody without altering data. Only work with providers who operate under proper legal and ethical standards and with written authorization from the account holder.

Authorized recovery services and legal counsel can help translate technical evidence into a format support teams or courts accept. They can also help determine whether to escalate to law enforcement. Avoid unvetted “shortcut” services that ask for account credentials or promise guaranteed recovery—these can further jeopardize your case.

Perguntas frequentes

How quickly should I start documenting a suspected compromise?

Begin immediately. The sooner you preserve notifications, emails, and receipts, the better the chance of retaining intact evidence. Do not alter or delete potential evidence and record the time you first noticed the issue.

Can I recover logs or IP addresses myself if I lost access?

If you are the account owner, you can provide server-side data to the provider or request logs through official support. If you cannot access the account, ask the service provider or law enforcement to obtain server-side logs; avoid attempting unauthorized access to systems you do not control.

What proof of ownership will support teams usually require?

Requirements vary by provider but commonly include account creation details, recent billing or transaction records, registered email or phone numbers, and government ID in some cases. Provide only what the provider requests and never share passwords in documentation.

Should I report the compromise to the police?

If there is financial loss, identity theft, or evidence of criminal activity, filing a police report is advisable. Law enforcement can assist in obtaining provider logs and may be required by some services before taking certain recovery actions. Ensure any involvement is authorized by the account holder.

What should I avoid when preparing evidence?

Do not reset passwords, delete alerts, or wipe devices if doing so would destroy evidence unless directed by an authorized expert. Avoid sharing credentials with third parties and do not use unverified recovery services that request passwords or sensitive access.

Read also

Documenting a compromised account carefully helps official support and authorities assess your recovery request

Documenting a compromised account carefully helps official support and authorities assess your recovery request. If you need help preserving or interpreting evidence, consider an authorized professional and always act with the account holder’s written permission. Contact the platform’s official support or a qualified specialist to take the next authorized step.

Fale com a equipa