"New sign-in from an unknown device"? Check whether it is real, then lock the account down in the right order.
Moderate⏱ 15–30 minAny
Security alerts about new sign-ins are a good thing: they mean the service noticed something unusual. Many are harmless — a new phone, a browser update, or travel can all trigger them — but they should never be ignored.
Be careful with the alert itself. Fake "suspicious sign-in" emails are a favourite phishing trick. Never click a link in the message; go to the service directly by typing its address or using its official app.
Try these first — 30 seconds each
[ ]Do not click links in the alert. Open the app or type the website address yourself.
[ ]Check the time and device in the alert — did you sign in on a new device, browser, or network around then?
[ ]Remember that location estimates are rough; a sign-in from your own provider can appear to be in a nearby city.
The full fix
6 steps in the order that solves it fastest, plus platform notes, prevention, and when to call
in a pro — unlocks with a short ad.
1
Review recent activity on the real site
Go to the account's security page: Google Account → Security → Your devices and Recent security activity; Microsoft → account.microsoft.com → Security → Sign-in activity; Apple → Settings → your name → Devices. Look for devices, locations, and times you do not recognise.
2
If anything is unfamiliar, change the password
Choose a new, unique password you have never used elsewhere — a password manager can generate one. If you reused the old password on other sites, change it there too, starting with email and banking.
3
Sign out every other session
Most services have a "Sign out of all other sessions" or "Remove device" option on the security page. Use it so any attacker is kicked out immediately, then sign back in on your own devices.
4
Turn on two-factor authentication
Add an authenticator app or security key. Even if someone has your password, they cannot get in without the second factor.
5
Check for changes an attacker may have made
Look for new email forwarding rules or filters, changed recovery phone numbers or emails, connected third-party apps, and unfamiliar payment methods or orders. Remove anything you did not set up.
6
Check whether your password was in a breach
Enter your email address at haveibeenpwned.com to see whether it appears in known data breaches. Many password managers also check saved passwords against breach lists and flag weak or reused ones.
Platform notes
Any
If you cannot sign in because the password has already been changed, use the service's official account recovery immediately — the sooner you start, the more likely it is to succeed.
Stop it happening again
Use a unique password for every account, stored in a password manager.
Turn on two-factor authentication for email, banking, and social accounts.
Treat unexpected sign-in emails with suspicion and always verify in the app.
When to get professional help
If money has been taken or a financial account is involved, call your bank using the number on its website or your card straight away. For identity theft, your national consumer or fraud reporting service can explain the next steps.
This is general troubleshooting information for home users. Menus and settings differ between
device models and software versions. Back up important data before making changes, and contact
the manufacturer or an authorised repair provider for hardware faults or anything under
warranty.
🔓
Keep reading
Watch a short ad to unlock the full step-by-step fix — free, no account needed.