IDENTITY DEFENCE
Account Takeover Protection: Stop One Stolen Login Becoming a Digital Collapse

Account takeover becomes dangerous when one compromised login can reset or authorise everything else. The best defence is to break that chain before anyone gets your password, code or recovery channel.
This page focuses on protection, continuity and recovery. It does not provide instructions for carrying out cyber intrusion.
The immediate answer
Protect your primary email and financial accounts first, because they can unlock or reset many other services. Use passkeys where available, unique credentials elsewhere, review recovery details and active sessions, and independently verify any urgent request for a login code, password change or payment before acting.
Protect email as the root account
Your primary email is often the recovery route for shopping, social media, utilities and other services. Use a passkey where available, otherwise a unique password and two-step verification. Review recovery addresses, phone numbers and active sessions. Remove anything you no longer recognise. If you suspect compromise, secure email before lower-priority accounts because an attacker who still controls the inbox may simply reset the passwords you have just changed.
Stop reusing credentials across important services
Password reuse turns one breach into several. Use a credential manager to generate and store unique passwords for services that do not support passkeys. Avoid minor variations of the same password. If a provider notifies you of a breach, change any reused credentials immediately. The aim is containment: a stolen password from an old shopping account should not open your banking, email or cloud storage.
Prefer passkeys where the service supports them
The NCSC recommends passkeys over passwords where available because they are resistant to phishing and cannot be reused in the same way as a stolen password. Set them up on trusted devices and understand how your credential manager syncs or recovers them. Keep the device itself protected with a strong unlock method. Where passwords remain as a fallback, make sure those passwords are still strong and protected by additional verification.
Treat one-time codes as credentials, not proof of legitimacy
A caller who knows your name, bank or recent transaction is not automatically genuine. Never read authentication codes to someone who contacted you unexpectedly. If a message claims an account is under attack, open the official app yourself or call the provider using a known number. Criminals often create urgency because the victim is less likely to notice that they are authorising the attacker’s login or payment.
Know the signs of a takeover
Unexpected login alerts, password-reset messages, new forwarding rules, unfamiliar devices, changed recovery details and unexplained payments are all reasons to investigate. Check account security pages rather than relying solely on email notifications, which could themselves be hidden or manipulated. If money is involved, contact the bank promptly using trusted details. Record what you changed so recovery does not become a second source of confusion.
After recovery, close the route that let the attacker in
Changing the password is not always enough. Revoke active sessions, remove unknown app permissions, check email forwarding rules, replace compromised recovery details and review linked accounts. Scan affected devices and update software. If the same weakness exists elsewhere, fix it there too. A good post-incident review turns one frightening event into a smaller risk next time.
Continue from here
Build this topic into a wider plan, then see how the same dependency could fail in an AI-collapse scenario.
Evidence desk
The defensive guidance on this page uses current UK cyber-security advice. Where the page discusses AI-driven escalation or autonomous attack chains, that material is labelled as scenario analysis rather than presented as a guaranteed future event.
OFFLINE FALLBACK
Cyber resilience is part of household resilience.
The 72-hour field manual covers power, communications, money, food, water and the paper information you need when digital systems stop cooperating.
Continue
More Cyber & Digital Resilience guides → · Cyber and preparedness tools →