Unexpected sign-in alert? Check this before you click.

An unexpected sign-in alert is a signal to verify—not a reason to panic or click the message.

First: do not use the alert’s link

Open the service from its app or by typing the address you already know. Sign in there and check recent activity or security alerts. This avoids turning a convincing phishing message into the doorway to your account.

If the sign-in was yours

  1. Confirm the device, location, and time match what you did.
  2. Dismiss the alert from inside the real account or app.
  3. If these alerts happen often, review old devices and active sessions.

If the sign-in was not yours

  1. Change the account password from the legitimate site or app. Make it unique.
  2. Sign out other sessions and remove devices you do not recognize.
  3. Turn on multifactor authentication, preferably using an authenticator app or security key when available.
  4. Check recovery email, phone, forwarding rules, and connected apps for changes you did not make.
  5. Protect reused credentials. If the old password was used anywhere else, change those accounts too—starting with email and financial services.
  6. Tell contacts if messages were sent from your account. Ask them not to open unexpected links or attachments.

If you already clicked

If you entered a password, change it immediately from the real service and follow the steps above. If you downloaded something, stop opening it, update your security software, and run a scan. Report the phishing message through the provider and at ReportFraud.ftc.gov.

Why this works

The goal is simple: verify through a trusted path, close any unauthorized access, and protect the accounts that could be used to reset everything else. You do not need perfect certainty before taking these reversible protective steps.


Primary sources

Reviewed September 27, 2026. SecureGadgetHub is a Security Risk Consultants LLC brand.