GHOSTKIT/Safe Device & Recovery
SAFE DEVICE & RECOVERY · VICTIM-FIRST
Recover from a compromised account without making the situation worse.
Use this as a local checklist. Do not type passwords, MFA codes, recovery codes, SINs, banking credentials or full identification numbers into GhostKit.
If you think the device itself is monitored: do not change passwords or confront the suspected person from that device. If safe, use a trusted device and a trusted connection, and seek specialized support.
Before recovery
Recovery order
- Secure the primary email account first when appropriate.
- Change reused passwords from a trusted device.
- Terminate unknown sessions and devices.
- Replace unknown recovery email addresses and phone numbers.
- Revoke unknown connected apps and extensions.
- Check mailbox forwarding, filters and delegation.
- Enable MFA/passkeys and add a backup method.
- Then secure banking, CRA, government and social accounts.
Email red flags
Look for forwarding rules, delegated mailboxes, recovery changes, unknown devices, sign-in alerts and sent/deleted messages you did not create.
Phone/SIM red flags
Unexpected loss of service, SIM/eSIM changes, carrier notifications, unfamiliar recovery numbers or calls asking for verification codes.
Don't hand over the keys
Never give GhostKit or a helper your password, MFA code, recovery code, bank PIN or full SIN. A legitimate helper should guide you while you enter secrets yourself.
EmergencyHousing.CA principle: the person carries the choices; the system should carry only the workflow. GhostKit does not create a case file.