Señales de una cuenta hackeada

Amenazas

Qué delata un acceso ajeno, dónde buscar rastros y por qué el silencio en el correo también es una señal.

A compromised account rarely looks compromised. Whoever got in wants quiet: the longer you fail to notice, the more they achieve. So the signs have to be looked for deliberately rather than waited for.

Señales evidentes

  • Emails about a login from an unknown device. The most direct signal and the most often ignored — such messages look like newsletters.
  • Messages you did not send. Requests for money to friends in particular.
  • The password stopped working. It has already been changed; act immediately.
  • Unfamiliar transactions in order or payment history.

Las menos evidentes

Silence in your inbox is also a sign. If messages from your bank suddenly stopped arriving, check the forwarding and filter rules rather than the spam folder.

  • Mail from one sender disappeared. A classic trick: a rule that sends bank messages straight to the bin so you miss the transaction notice.
  • A forwarding rule appeared. A copy of all mail goes to someone else’s address and survives a password change.
  • The recovery address or phone changed. Those go first, so you cannot get back in.
  • An unfamiliar app in the list of connected services. Access granted once keeps working after a password change.
  • A verification code you did not request. The password is already guessed and only the second factor stands.

Dónde buscar rastros

Dónde mirarQué buscar
Login historyUnfamiliar cities, devices and browsers; logins at hours you never use
Active sessionsDevices you do not own or have not switched on for months
Filters and forwardingAny rule you did not create
Recovery settingsA phone number or backup address that is not yours
Connected appsAccess granted to services you do not recognise
The Sent folderMessages you did not write — and an empty folder is suspicious too

Qué hacer, por orden

Order matters more than speed, and it is the same as after a password leak.

  1. Start with email. While it is under someone else’s control, changing passwords elsewhere is pointless: the reset messages will not reach you.
  2. Change the password and end all sessions. One “sign out of all devices” cuts the intruder off at once.
  3. Restore the recovery contacts — phone number and backup address.
  4. Remove foreign forwarding rules and filters. This step is skipped most often, and without it your mail keeps flowing out.
  5. Revoke app passwords and third-party access.
  6. Turn on a second factor if there was none.
  7. Warn the people you may have “written” to.

Detectarlo antes la próxima vez

  • Turn on login notifications — they arrive at the moment of the event, not a month later.
  • Open the login history yourself every couple of months instead of waiting for a warning.
  • Keep a separate mailbox for banking: the less its address circulates, the rarer it appears in breaches.
  • Periodically check passwords against breach databases — that way you learn about the problem before the attacker does.
Copiado