Account takeover response, without giving GhostKit your secrets.
Choose what is happening. GhostKit turns it into a local checklist you can work through and print. Do not enter passwords, MFA codes, recovery codes, SINs, banking credentials or government ID numbers here.
Select a situation above
Immediate sequence
- Select an incident type.
Verification sweep
Evidence discipline
Record dates, times, URLs, usernames, notifications, reference numbers and actions taken. Keep originals separately. Do not publish sensitive evidence merely to prove what happened. When contacting a provider, use its official website or a trusted number you already have.
1 · Protect the primary email
Your email is often the recovery path for everything else. Secure it first when it is affected.
2 · Protect money & government access
Review banking, credit, CRA and other high-impact accounts for changes you did not authorize.
3 · Revoke access
Remove unknown sessions, devices, connected apps, forwarding rules and recovery methods.