An email or text message arrived saying someone just signed into your account. The alert might say it came from a city you have never been to, a device you do not own, or at a time when you were asleep. Or perhaps you got an alert about a login attempt that was blocked. Either way, it is worth taking it seriously — and taking a few specific steps in the right order.
First: is the alert real?
Login alerts are also a common type of scam. Before you do anything, make sure the alert itself is genuine.
Check who sent it. Look at the actual email address in the From field, not just the name. A genuine alert from Google will come from an @google.com or @accounts.google.com address. A genuine Apple alert comes from @apple.com. A genuine bank alert comes from the bank’s real domain. If the domain looks odd — extra words, misspellings, unusual extensions — it may be a fake.
Do not click links in the alert. Go directly to the account yourself. Open your browser and type the address (gmail.com, apple.com, your bank’s website) rather than clicking any link in the message. This protects you if the alert turns out to be a phishing attempt.
What is probably happening
If the alert is real, there are a few possibilities:
- It was you. Location data in login alerts can be unreliable. If you use a VPN, the alert may show the VPN server’s location, not yours. If you logged in on a work network or a mobile data connection, the location may show your internet provider’s data centre rather than your physical location. An unfamiliar city is often just your internet provider’s nearest server.
- It was someone with your password. If you reused a password from another site that was breached, that password may have leaked and someone is using it to try logging in.
- It was an automated attack. Programmes try common passwords against many accounts. An alert about a blocked login attempt does not mean the attacker has your password — it means one attempt was made and failed.
What to do if you think the login was not you
Step 1. Change your password immediately.
Do this for the account that triggered the alert. Go directly to the website, log in, and change the password to something new and unique — do not reuse a password from another account.
Step 2. Sign out of other devices.
Most accounts have an option to sign out all other sessions. In Google this is under Manage Your Google Account, then Security, then Your Devices. In Apple it is in your Apple ID settings. This removes any existing access the attacker had.
Step 3. Set up two-factor authentication if you have not already.
Two-factor authentication means a password alone is not enough to sign in — a code sent to your phone is also required. This stops most unauthorised access even if someone has your password. See the separate guide on setting up two-factor authentication.
Step 4. Check whether the same password is used elsewhere.
If you used the same password on other accounts, change those too. A password manager can help you keep unique passwords for each account. See the guide on setting up a password manager.
Step 5. Review recent account activity.
Most accounts have a section in settings showing recent logins and activity. Look for anything unfamiliar — emails sent that you did not write, orders placed you did not make, or settings that were changed.
If the alert was about your bank account
Call your bank directly using the number on their official website or on the back of your card — not any number in the alert. Explain what happened. Banks have fraud teams that can review your account and freeze it if necessary. Do not delay this step if your bank account was involved.
What NOT to do
- Do not click links in the alert email to “verify” or “secure” your account — this is exactly how phishing attacks work.
- Do not ignore the alert and hope it was an error. Even if it turns out to be nothing, five minutes of checking is worth it.
- Do not call a phone number in the alert message — look up the official number for the service yourself.
When to stop and seek help
If you find that your account has been accessed without your permission and there are transactions, messages, or data changes you did not make, contact the service’s support team and explain the situation. Most services have processes for account recovery and reversing fraudulent actions. If financial accounts were compromised, contact the relevant institutions as soon as possible.
If this did not work
If you cannot log in to your own account — the password no longer works — use the account recovery process to regain access. Most services offer recovery via email or phone number. If your recovery email was also compromised, contact the service’s support team for manual identity verification.
Frequently asked questions
I got an alert but I was the one who logged in. Should I still do anything?
If you triggered the alert yourself — new device, VPN, different network — no immediate action is needed. You may want to mark the device as trusted if the service offers that option.
Why does the alert show a city I have never been to?
IP addresses are mapped to physical locations, but the mapping is approximate and based on where your internet provider registers the address, not where you physically are. A location one or two cities away from your actual location is often just an inaccuracy in the data.
An alert about a blocked login attempt — should I be worried?
A blocked attempt means whatever password was tried did not work. It is worth changing your password as a precaution and enabling two-factor authentication, but a single blocked attempt is not unusual and does not mean your account was compromised.
How do I know if my email was part of a data breach?
The website haveibeenpwned.com lets you enter your email address and see whether it appears in publicly known data breaches. This is a legitimate and widely recommended service.
Can I prevent login alerts from being sent to my email?
You can usually adjust notification settings in your account, but it is not recommended. Login alerts are one of the fastest ways to notice unauthorised access.