Authority lesson · 873 words
Accounts and recovery
Safety boundary: Educational guidance only. In immediate physical danger, contact emergency services. In the United States, call or text 988 for emotional crisis or self-harm risk. Do not redistribute intimate or exploitative material while seeking help.
Start with the account that unlocks the others
The primary email account often resets social, gaming, school, creator, shopping, and payment accounts. Protect it first. Use a unique password or passkey, turn on multifactor authentication, review recovery email and phone details, save backup codes somewhere secure, and sign out sessions you do not recognise. A password change on a secondary account will not help if someone still controls the email that resets it.
Do not share passwords, backup codes, or verification codes with friends, helpers, moderators, or someone claiming to be support. A real support process may ask you to sign in through the official app or website, but it should not need the one-time code sent for your login. Open the service yourself instead of following a link from an unexpected message.
Recovery is easier when ownership evidence exists
Before a crisis, record safe proof that an account is yours: original username, approximate creation date, purchase receipts, linked platform IDs, device history, recovery email, and official support case numbers. Do not post this information publicly. Keep it with a parent or trusted adult if the account controls money, a public channel, or important schoolwork. Screenshots of settings may reveal private details, so store them carefully.
If an account is stolen, use the platform’s official recovery page. Secure the primary email and device, revoke unknown sessions, change exposed passwords, and check payment methods. If the account was used to threaten, scam, or impersonate someone, save the exact profile link, messages, dates, and support numbers before content disappears. Avoid paying a stranger who promises recovery.
Treat device and phone-number access as part of the account
A lost phone, malicious app, SIM takeover, or shared browser can expose sessions even when the password remains secret. Use a screen lock, software updates, device-location tools, and remote lock or erase features. Review connected apps and browser extensions. Contact the mobile carrier through an official number if the phone number suddenly stops working or account recovery messages arrive unexpectedly.
After recovery, check more than the password. Review forwarding rules in email, authorised apps, recovery contacts, privacy settings, payment methods, public posts, and messages sent during the compromise. Tell contacts if the stolen account asked them for money or codes. Keep following up because an attacker may have created another recovery route.
Adults should support recovery without taking over everything
A useful adult response begins with safety and access, not blame. Ask what the person controlling the account can reach, whether money or location is involved, and whether threats are being made. Help document the timeline and use official recovery paths. Consequences for broken household rules can be discussed later and separately; fear of punishment should not keep a teen from reporting a stolen account.
For school, work, banking, or high-value creator accounts, involve the responsible organisation quickly. If there is stalking, sexual exploitation, credible violence, or immediate danger, recovery is only one part of the response. Bring in qualified help and preserve evidence without confronting the suspected person alone.
Scenario
A friend asks for the code sent to your phone
A friend says they are locked out and used your number for recovery. A code arrives. The safe response is not to forward it. The code may be authorising access to your account or creating an account tied to your identity. Stop the conversation, open the relevant service directly, review recent activity, and tell a trusted adult if pressure or threats continue.
- Do not share the code
- Verify through the official service
- Secure the primary email
- Save pressure or threat messages
Worked example
Create a recovery map
- List the primary email and every account it can reset.
- Turn on MFA and store backup codes safely.
- Record official recovery links and proof of ownership.
- Review sessions, connected apps, and payment methods.
- Choose a trusted adult who can help without demanding your password.
Checklist
Use this before acting
- Secure the primary email first
- Use unique passwords or passkeys
- Turn on MFA and protect backup codes
- Review recovery contacts and active sessions
- Store ownership evidence privately
- Use official recovery routes
- Check forwarding rules, apps, and payment methods after recovery
- Tell a trusted adult when safety, money, or identity is involved
Common mistakes
Failure patterns to avoid
- Sharing a verification code
- Following a recovery link from an unexpected message
- Changing only one secondary password
- Paying unofficial recovery services
- Posting proof of ownership publicly
- Treating the problem as finished before sessions and recovery settings are reviewed
Practical exercise
Build a private recovery card
Without writing passwords, create a card listing your primary email, official recovery pages, trusted adult, carrier, device-location service, payment contacts, and the first five actions after account loss.
Deliverable: A private recovery card stored somewhere accessible during a lockout.
Sources and further reading
Primary and official references
- CISA Secure Our World resources — Official practical resources on phishing, passwords, MFA, updates, reporting cybercrime, AI, and youth digital citizenship.
- FTC: Verification codes — Official guidance that verification codes should not be shared with someone who asks for them.
Topic-specific takeaway
Account recovery works best when the primary email, device, sessions, and proof of ownership are protected before a crisis.