Personal Incident Response Guide
This guide is for people who have already been hit. For hardening before something happens, read the DFP Guide. For understanding how adversaries operate, read the Threats catalog.
If something is happening to you right now, do not start at the top of this page. Find your scenario in the Emergency Triage below and jump straight there.
Emergency triage — pick the closest match
Section titled “Emergency triage — pick the closest match”How this guide is structured
Section titled “How this guide is structured”Three layers, increasing in generality:
- Threat-specific pages (
/cybersecurity/threats/...) — what the attack looks like, how it works, how to spot it. - Scenario IR pages (the links in the triage block above) — exactly what to do if you got hit by that thing.
- This page — the general “Identify → Secure → Restore → Report → Learn → Monitor” framework, with the right order of operations baked in.
If your scenario is on the triage list, go to that page — it has the specific protocol. This page is the fallback when nothing else matches.
Identify — which scenario are you in?
Section titled “Identify — which scenario are you in?”Pick the row that best describes what happened. Each links into the scenario-specific page or the matching section below.
Money or account-takeover
Section titled “Money or account-takeover”- Bank/card drained, payment app sent money I did not authorize → Money loss / account fraud + Remote-access scam if a “support” caller is involved.
- Locked out of an account / password no longer works → Account takeover.
- Phone shows “No Service” and I can’t log into anything → SIM swap.
- Unexpected “linked device” on Signal / WhatsApp / Telegram → Signal/CMA takeover.
Device compromise
Section titled “Device compromise”- I installed something (npm package, cracked app, “free” tool) and my passwords/wallet may be stolen → Infostealer.
- I gave someone remote control of my computer → Remote-access scam.
- Ransomware message on screen → Ransomware.
- Phone/laptop acting on its own — cursor moving, redirects, unknown apps installed → Generic device compromise.
- Lost or stolen device → Lost/stolen device.
Personal data / images / identity
Section titled “Personal data / images / identity”- Intimate photos of me are being shared without consent → Image-based abuse.
- Someone is impersonating me on social media → Impersonation.
- Data breach notification from a service I use → Account takeover (rotate passwords + check Have I Been Pwned) + freeze credit.
- Identity theft — new accounts opened in my name → Identity theft / fraud.
Scams (you were socially engineered)
Section titled “Scams (you were socially engineered)”- Phone call from “Amazon / Microsoft / IRS / your bank” asked me to install software → Remote-access scam.
- Emergency call from “family member” needing bail/medical money → AI voice clone scam.
- Phishing email/SMS/DM — I clicked / entered credentials → Account takeover.
- Romance scam / catfish — I sent money or images → General reporting + Image-based abuse if applicable.
Targeted / advanced
Section titled “Targeted / advanced”- I’m a journalist, dissident, USG/military/political figure and I think a state actor is targeting me → Signal/CMA RIS campaign + Clearance holder if applicable.
- Foreign-intelligence-entity (FIE) contact / approach → Clearance holder — SAEDA.
- OPSEC leak during a deployment → Military family + Servicemember.
Population-specific
Section titled “Population-specific”- I’m a servicemember (junior enlisted/NCO/officer) → Servicemember IR.
- I’m a military spouse/parent during a deployment → Military family IR.
- I’m a clearance holder and any personal incident may be reportable → Clearance holder IR.
- I’m over 60 or helping someone over 60 → DOJ Elder Justice Hotline 1-833-372-8311; AARP Fraud Watch 1-877-908-3360.
Secure — the right order matters
Section titled “Secure — the right order matters”The biggest single mistake in personal IR is doing the steps in the wrong order. The correct order depends on what was taken. Pick the path that matches:
Path A — Credential theft (infostealer, phishing, vault exposed, session cookie stolen)
Section titled “Path A — Credential theft (infostealer, phishing, vault exposed, session cookie stolen)”If your passwords / sessions / API tokens may be exposed, rotate from a clean device first. Malware removal can wait — the attacker is already inside. Speed of rotation matters more than scrubbing the infected box.
- From a clean device (your phone, a relative’s laptop, a freshly-imaged machine), sign in to your password manager and rotate email first — email controls password reset for everything else.
- Rotate financial accounts next — bank, brokerage, payment apps, crypto exchanges.
- Rotate identity infrastructure — mobile carrier (prevents SIM swap), GitHub, AWS/GCP/Azure, code-signing keys, cloud storage.
- Revoke active sessions on every service you just rotated. Changing the password does not kill stolen cookies. See Revoke sessions.
- Crypto-specific: if a hot-wallet seed phrase touched the compromised host, that seed is burned. Set up a new wallet on a hardware device and move funds immediately — see Infostealer page.
- Then isolate the compromised device (pull network, do not power off — memory artifacts may help forensics).
- Then wipe and reinstall the OS from clean media. Do not restore from a backup taken after compromise.
Path B — Remote control of your device (someone is/was in a remote session)
Section titled “Path B — Remote control of your device (someone is/was in a remote session)”- Unplug the network — yank ethernet, disable WiFi at the device or the router.
- From a different device — call your bank/card fraud line, then change passwords starting with email.
- Uninstall the remote-access tool (AnyDesk, TeamViewer, Quick Assist, ConnectWise/ScreenConnect, RustDesk, Splashtop) — these are legitimate software, not malware. Antivirus will not flag them.
- Take screenshots of the remote-access window, any messages, the calling phone number — evidence.
- Assume everything you typed was seen, including obscured passwords. Rotate every credential entered during the session.
- See Remote-access scam page for full protocol.
Path C — Ransomware (your files have been encrypted)
Section titled “Path C — Ransomware (your files have been encrypted)”The generic steps below are wrong for ransomware. See the Ransomware page for the correct protocol: photograph the screen, isolate but do not power off, identify the family, check NoMoreRansom.org, preserve the disk before any reinstall.
Path D — Generic device compromise (spyware, suspicious behavior, unknown apps)
Section titled “Path D — Generic device compromise (spyware, suspicious behavior, unknown apps)”Use this only if Paths A/B/C do not match.
- Disconnect the device from the network.
- Image the device if you may need evidence (forensic copy of disk via
ddor commercial imager). - Run a full malware scan with reputable AV (Defender, Malwarebytes, ESET, Sophos).
- Audit installed apps and browser extensions. Remove anything you do not recognize.
- Update OS and applications to current patch level.
- Change device-local passwords (login password, screen lock).
- Then rotate online account passwords from this device (now that it is clean) or, more safely, from a different clean device.
- Enable MFA on accounts that don’t have it — see MFA Guide.
- Consider professional help if you handle sensitive data.
Revoke sessions on every account
Section titled “Revoke sessions on every account”Changing your password does not sign out existing sessions. Stolen cookies stay valid until revoked. Go through every important service:
| Service | Where to revoke |
|---|---|
| myaccount.google.com/device-activity | |
| Microsoft | account.microsoft.com/devices → Sign out everywhere |
| Apple | iCloud.com → Account Settings → Sign out of unknown devices |
| GitHub | github.com/settings/sessions |
| Discord | User Settings → Devices → Log out all known devices |
| Slack | Workspace → Profile → Account settings → Sign out other sessions |
| AWS | IAM → Users → Security credentials → revoke sessions |
| Banking | Most US banks have a “sign out all sessions” or “trusted devices” page in security settings |
| Signal / WhatsApp / Telegram | Settings → Linked Devices → remove anything you did not link |
Account takeover
Section titled “Account takeover”If a specific account was taken over:
- Use the account-recovery flow (forgot password / recover account).
- If recovery fails: contact the provider directly via their official support channel — for Google/Microsoft/Apple, search “[provider] account recovery” from a clean browser, not from any link in an email.
- Once back in: change password, enable MFA (prefer app-based or hardware key over SMS), revoke active sessions, audit connected apps / authorized OAuth, audit recovery email and phone (the attacker may have added theirs).
- Check sent folder and recent activity to understand the blast radius.
- Notify contacts if the account was used to message them (see Communications protocols).
- Watch for related-account fallout: same password reused elsewhere, password-reset links sent to this account.
Money loss / account fraud
Section titled “Money loss / account fraud”Time matters. Reg E gives consumer protections for unauthorized electronic transfers if reported quickly:
- Within 2 business days: liability capped at $50.
- Within 60 days of statement: liability capped at $500.
- After 60 days: potentially unlimited loss.
Order of calls:
- Bank or card issuer fraud line — number on the back of your card. 24/7 at all major US banks. Freeze the account, dispute the charge, request new card/account numbers.
- The payment platform if the money moved through Zelle / Cash App / Venmo / PayPal — file in-app fraud report. Zelle and many bank P2P services have a “fraud” path distinct from “scam” — fraud (someone took my account) is reversible more often than scam (I willingly sent it). Push for fraud classification when applicable.
- Wire transfers — most US banks have a same-day reversal window for some wires. Call immediately.
- Crypto — almost never reversible. Notify the exchange in case the destination wallet is on their platform. Report to FBI IC3.
- Gift cards — call the card issuer (Apple, Google, Amazon, Steam) and ask for freeze/cancellation of unredeemed balance.
- IC3 + FTC + state AG — see Reporting.
- Freeze your credit at all three bureaus to prevent followup identity theft — see Freeze credit.
Identity theft
Section titled “Identity theft”Someone is opening accounts in your name:
- Freeze credit at Experian, Equifax, and TransUnion (all free). See Freeze credit.
- Place a fraud alert at one bureau — they notify the other two.
- Get reports from annualcreditreport.com (free, weekly).
- Report to FTC at identitytheft.gov — generates an Identity Theft Affidavit you’ll need for disputes.
- File local police report if needed for creditor disputes.
- Dispute fraudulent accounts with each creditor directly using the FTC affidavit.
Freeze credit
Section titled “Freeze credit”Free, easy, reversible. Lock down all three bureaus:
- Equifax — equifax.com/personal/credit-report-services/credit-freeze
- Experian — experian.com/freeze
- TransUnion — transunion.com/credit-freeze
- ChexSystems (bank account fraud) — chexsystems.com
- NCTUE (telecom/utility) — nctue.com
Full guide with all bureaus and brokers: IntelTechniques Credit Freeze Guide.
Impersonation
Section titled “Impersonation”Someone created a fake account pretending to be you:
- Report through the platform — Meta, X, Discord, LinkedIn, TikTok all have impersonation report forms. Provide ID proof.
- Tell your contacts — message your real audience via a verified channel: “Account X is not me, do not respond.”
- Reverse-image-search your profile photo to find other imposter accounts (often multiple).
- Document everything — screenshots with URLs and timestamps.
- Report to FBI IC3 if fraud was committed in your name.
- Servicemembers: also report to your service’s CID equivalent.
Lost or stolen device
Section titled “Lost or stolen device”- Use the manufacturer’s find-my-device service to locate and (if needed) remotely wipe.
- From a clean device, change passwords starting with email and bank.
- Revoke device-bound sessions — see Revoke sessions.
- Carrier — block SIM and disable the device IMEI (carriers can blacklist).
- File a police report with the device serial/IMEI — needed for insurance and for the carrier blacklist.
- Notify financial apps — Apple Pay, Google Pay, Venmo, banking apps can be remotely deauthorized.
- If the device contained sensitive work data, notify your employer’s IT/security team.
Device compromise (generic)
Section titled “Device compromise (generic)”See Path D in Secure.
Network compromise (router, home WiFi)
Section titled “Network compromise (router, home WiFi)”- Change router admin password (default credentials are public knowledge).
- Change WiFi password — forces all devices to re-authenticate.
- Update router firmware.
- Disable remote management / WPS / UPnP unless specifically needed.
- Audit connected devices — anything you don’t recognize, kick off and investigate.
- Replace if the router is end-of-life and no longer getting firmware updates.
- See Router Hardening.
Restore — assume what was lost, plan what’s next
Section titled “Restore — assume what was lost, plan what’s next”Recovery shape depends on whether you lost data (deletion, ransomware) or trust (compromise, exfiltration).
Lost data
Section titled “Lost data”- Backups — restore from the most recent clean backup. If you have versioned backups (Time Machine, restic, Borg, Backblaze), pick a version from before the incident.
- Cloud trash — Google Drive, iCloud, OneDrive keep deleted files for 30+ days.
- OS-level recovery — Windows File History, macOS Time Machine, Linux snapshots (Btrfs/ZFS).
- Last resort — forensic recovery (PhotoRec, Recuva) on a disk image.
Lost trust (assume-compromise thinking)
Section titled “Lost trust (assume-compromise thinking)”If data was read by an adversary rather than deleted, you don’t restore — you reason about what they now know and what they can do with it. Ask:
- What credentials were on the box? (Rotate them.)
- What documents were exposed? (Tax returns, ID scans, address book, medical records, source contacts.)
- What sessions were active? (Revoke them.)
- What was the attacker’s likely goal? (Money — watch financial accounts. Data — watch for use against you or your contacts. Espionage — see Clearance holder.)
- Who else’s data was on this device? (Family, sources, coworkers — notify them via a safe channel.)
Reinstall OS
Section titled “Reinstall OS”- Reinstall from official media (download fresh from the vendor, verify checksum).
- Do not restore from a backup taken after the compromise.
- Re-flash external drives that touched the compromised system.
- Set up password manager and MFA before logging into anything sensitive on the new install.
Report
Section titled “Report”The right reporting path depends on the scenario. Use this matrix:
| Scenario | First call (most urgent) | Secondary | Legal / regulatory |
|---|---|---|---|
| Money taken from bank/card | Bank fraud line (back of card) | FBI IC3 (ic3.gov) | FTC (ReportFraud.ftc.gov); state AG |
| Money sent via Zelle/Cash App/Venmo/PayPal | The platform + your bank | IC3 | FTC; demand Reg E fraud classification |
| Money wired (Western Union, MoneyGram, bank wire) | The wire service immediately | IC3 | FTC |
| Crypto stolen | Exchange compliance | IC3 (FBI Virtual Asset Unit) | IRS Form 4684 if loss > 10k |
| Identity theft (new accounts opened) | identitytheft.gov | Credit bureaus (freeze + fraud alert) | Local police if needed for disputes |
| Ransomware (business) | FBI IC3 + cyber-insurance carrier | CISA (stopransomware.gov) | State breach-notification laws; PCI |
| Non-consensual intimate imagery (adult) | CCRI Helpline 1-844-878-2274 | StopNCII.org; platform reports | Civil suit (state law); FBI if interstate threat |
| NCII (was a minor in image) | NCMEC CyberTipline 1-800-843-5678 | takeitdown.ncmec.org | Federal CSAM laws |
| Sextortion / extortion threats | FBI tipline 1-800-CALL-FBI | IC3 | Federal extortion statute |
| Phishing / scam (no loss) | FTC ReportFraud.ftc.gov | reportphishing@apwg.org | — |
| Older-adult target (60+) | DOJ Elder Justice 1-833-372-8311 | AARP Fraud Watch 1-877-908-3360 | State elder-abuse unit |
| Servicemember victim | Army CID 1-844-276-9243 (or branch CI) | IC3; FTC | CFPB Servicemembers’ Office |
| Military-family targeting during deployment | Unit Rear-D + FRG leader | Service Casualty Operations + Service CID | — |
| State actor / FIE / clearance angle | Local CI element / Army CI 1-800-CALL-SPY | DCSA; DOD IG 1-800-424-9098 | SAEDA / SEAD-4 |
| Nation-state targeting (journalist / activist) | FBI Field Office | Access Now Digital Security Helpline | Service provider trust & safety |
| Crime on military installation | Military Police → CID | — | — |
| NCII or scam crisis support | 988 (suicide & crisis) | CCRI 1-844-878-2274 | — |
When “call the local police” is the right answer (and when it isn’t)
Section titled “When “call the local police” is the right answer (and when it isn’t)”- Right answer: on-installation crimes (call Military Police), local property crimes (stolen device), and when you need a police report number for an insurance claim or creditor dispute.
- Wrong answer alone: nation-state targeting (call FBI), most financial fraud (call IC3 + your bank), NCII (call CCRI), or crimes that crossed state lines (call FBI). Local police can still take the report, but the federal/specialized channels move the case forward.
Communications & notification
Section titled “Communications & notification”How you tell people about the incident matters as much as whether you tell them.
Out-of-band — do not use the compromised channel
Section titled “Out-of-band — do not use the compromised channel”- If your email was compromised, do not warn contacts from that email. Call, text, or use a different account.
- If your Signal/WhatsApp/Telegram account is compromised (linked-device abuse), do not warn the contact list from the compromised account — the attacker sees it. Use a different platform or a known phone number.
- If your phone number is in active SIM-swap territory, do not use SMS or voice calls for sensitive verification — use a verified end-to-end channel.
Source / journalist protection
Section titled “Source / journalist protection”If your work involves people who could be at risk by association (sources, dissidents, abuse survivors):
- Assume the attacker has read all message history. Plan for that, do not deny it.
- Notify sources via a different channel than the compromised one — preferably the channel that source originally chose to contact you on.
- Coordinate any disclosures with the source on timing — sometimes “stay quiet for 48 hours” is right, sometimes “burn the channel and warn everyone now” is right. The source’s risk drives the choice.
- See also: Access Now Digital Security Helpline, free 24/7 for human-rights defenders, activists, and journalists.
Notify by relationship
Section titled “Notify by relationship”- Financial institutions — already covered in Money loss.
- Family — if you sent any “I’m in trouble, send money” message from a compromised account, family needs to know.
- Employer / IT-security team — required for any work-related device or account compromise. Check your employment contract.
- Customers (business) — required by state breach-notification laws if their data was exposed; varies state-by-state.
- Affected community / forum / Discord — coordinate with the moderation team; don’t accidentally amplify the attacker’s reach.
- Other targets — if you were hit by a campaign, similar people you know may be next. Warn them through your community’s normal info-sharing channel (Signal group, mailing list, work chat) — not from the compromised channel.
After the immediate crisis, before you forget:
- Write a short timeline. What happened, when, what you did. Even a few lines. Future-you (and anyone helping) will need this.
- Identify the entry point. Most incidents are: phishing click, reused password, MFA bypass, stolen device, supply-chain (malicious package / fake update), or social-engineering call. Knowing which informs prevention.
- Patch the gap that let it happen. A password manager, hardware key MFA, or a single device-isolation habit usually covers the most common gaps. See DFP Guide.
- Read about the threat. The Threats catalog describes how each common attack actually works. Spotting the second attempt is much easier than the first.
Monitor
Section titled “Monitor”Compromised once → likely targeted again. Adversaries often retry through a new vector within weeks.
- Check accounts weekly for the first 90 days post-incident — bank, email, social, cloud storage.
- Have I Been Pwned — haveibeenpwned.com — sign up for notifications on your email addresses.
- Credit monitoring — most US adults are entitled to free credit reports weekly at annualcreditreport.com.
- Linked devices — periodically audit Signal/WhatsApp/Telegram/iCloud/Google linked devices.
- OAuth-authorized apps — Google/Microsoft/GitHub all show third-party apps that have access; revoke anything stale.
- News on the threat actor — if it was a known group or campaign, follow vendor advisories (Mandiant, CrowdStrike, CISA alerts).
- Outbound traffic monitor — Little Snitch (macOS), GlassWire (Windows), OpenSnitch (Linux) flag unexpected network calls. See alternatives.
See also
Section titled “See also”- Threats catalog — how adversaries actually attack people
- DFP Guide — preventive hardening
- Secure After Compromise — post-incident hardening detail
- Password Managers
- MFA Guide
- Router Hardening
- How to Search Log Files