Table of Contents
The Family Digital Emergency Plan: Exactly What to Do When You're Hacked
When a family account is hacked, the first 30 minutes determine the outcome. This step-by-step digital emergency plan tells you exactly what to lock, check, and report.
At 10:47 p.m. on a Tuesday, a parent notices an email notification: “Your Apple ID was used to sign in on a new iPhone in Texas.” They’re in Ohio. Their hands are shaking. They’re not sure whether to call someone, change a password, or do nothing and hope it’s a mistake. In those 90 seconds of uncertainty, decisions that should take 5 seconds are consuming minutes. The Identity Theft Resource Center reported that in 2023, account takeovers affected 15.4 million Americans — and the most common thread in their follow-up surveys was that victims didn’t know what to do first. A digital emergency plan doesn’t require technical knowledge. It requires having thought through the steps before the moment arrives, so you’re executing a plan instead of improvising under stress.
Key Takeaways
- Account takeovers typically cascade: once one account is compromised, attackers use it to access email, which unlocks password resets on everything else
- The first priority is always email — whoever controls your email controls your digital life
- Checking what was accessed (message history, sent folders, data downloads) determines the scope of damage
- Credit freezes for children are free, permanent until lifted, and take 15 minutes per bureau — do them before any fraud occurs, not after
- Reporting to the FTC at identitytheft.gov generates a personalized recovery plan
- How you brief your kids on what happened affects whether they disclose future incidents to you
Understanding How Account Takeovers Cascade
The reason account takeovers feel so overwhelming is that they rarely stay isolated. The cascade works like this:
Step 1: Attacker obtains login credentials — via data breach, phishing, or credential stuffing (trying known username/password combinations from previous breaches).
Step 2: They access email. Email is the master key — password reset links from every other service go to email.
Step 3: From email, they reset passwords on accounts that have financial value: PayPal, Venmo, shopping accounts with saved payment methods, streaming services (which can be resold), gaming accounts (tradeable items).
Step 4: If they access cloud storage (Google Drive, iCloud, Dropbox), they harvest documents — tax returns, medical records, IDs, anything that enables identity theft.
Step 5: If the compromised account belongs to a child and contained their age (birthday on a school portal), address (shipping on a gaming account), and name, the attacker now has the building blocks of synthetic identity fraud using the child’s Social Security number.
Understanding this cascade determines the triage order.
The Triage Order: What to Lock First
Print this list and put it somewhere physical — it should be accessible even if your phone is the compromised device.
Priority 1 (within 5 minutes): Lock Email
- Gmail: Go to myaccount.google.com → Security → scroll to “Your devices” → review. Sign out all other sessions by going to Gmail → bottom right “Last account activity” → “Sign out of all other sessions.” Then immediately change your password to something new and enable 2FA.
- Outlook/Microsoft: account.microsoft.com → Security → “Sign in activity” → review. Change password, review sign-in activity.
- iCloud/Apple: appleid.apple.com → Sign-In and Security → “Sign in with Apple ID” review. Click your account → “Sign In and Security” → check trusted devices. Remove any unrecognized devices.
Priority 2 (within 15 minutes): Lock Financial Accounts
- Online banking: Log in directly (type the URL — don’t click links), change password, review recent transactions
- PayPal / Venmo / Cash App: Change password, review transaction history, disable any linked payment methods temporarily
- Amazon / shopping sites: Change passwords, review recent orders for unauthorized purchases, check saved payment methods
Priority 3 (within 30 minutes): Secure Secondary Accounts
- Social media (Facebook, Instagram, TikTok): Change passwords, review login history, check for unauthorized posts or messages sent
- Gaming accounts (PlayStation Network, Xbox, Steam, Epic Games): Change passwords, check transaction history for unauthorized purchases
- Child’s school portal: Contact the school’s IT department to flag the account and freeze any grade or record changes
Priority 4 (within 24 hours): Check What Was Accessed
This step is critical and most families skip it. Log into each account that was compromised and review:
- Sent folder (email): Did the attacker send emails from your account? Who to? What did they say? This matters for informing people who may have been phished.
- Download history (cloud storage): Check Google Drive/Dropbox/iCloud for recent download activity. If files were accessed, you need to know which ones.
- Purchase history: Review all accounts for the past 30 days for unauthorized charges.
- Data export requests: Some attackers request a full data export (Google Takeout, Facebook data download) to harvest information. Check if any such request is pending and cancel it.
Step-by-Step: Emergency Response Checklist
Within 5 minutes:
- Change the password on compromised email — make it unique, 16+ characters
- Enable 2FA on email if not already active
- Sign out all other email sessions
Within 15 minutes:
- Change passwords on all financial accounts (bank, PayPal, credit cards with online portals)
- Check financial accounts for unauthorized transactions
- Freeze all connected payment methods on shopping sites if any purchases were made
Within 30 minutes:
- Change passwords on social media accounts
- Review sent messages on social media for unauthorized messages to contacts
- Change passwords on child’s gaming accounts; check for unauthorized purchases
Within 2 hours:
- Run Have I Been Pwned (haveibeenpwned.com) on all family email addresses
- Report unauthorized charges to your bank (use the phone number on the back of your card, not one from an email)
- Report to the FTC at identitytheft.gov if any personal information was accessed — the site generates a customized recovery plan
Within 24 hours:
- File a report with the FBI at ic3.gov if financial theft occurred
- Contact your phone carrier and ask about SIM swap protection (adding a PIN requirement before number transfers)
- Review your credit report at annualcreditreport.com
Credit Freeze for Children: Do This Before Any Fraud Occurs
Children’s credit files are uniquely valuable to identity thieves. A child has a Social Security number and typically has no credit history — which means fraudulent accounts opened in their name can go undiscovered for years, until they apply for their first credit card or student loan. The Identity Theft Resource Center estimates that child identity theft goes undetected for an average of 7 years.
A credit freeze (also called a security freeze) prevents any new credit from being opened in your child’s name. It’s free, doesn’t affect any existing accounts, and is immediately reversible when you’re ready to apply for credit legitimately.
How to place a credit freeze for a child under 16:
The process requires mailing requests to all three bureaus (Equifax, Experian, TransUnion) — unlike adult freezes, child freezes cannot currently be done entirely online.
Each bureau requires:
- Child’s full name, address, SSN, date of birth
- Copies of the child’s birth certificate and Social Security card
- Parent or guardian’s government ID
- Proof of your address (utility bill or bank statement)
Equifax: equifax.com/personal/child-credit-freeze/ or mail to Equifax, PO Box 105139, Atlanta, GA 30348-5139
Experian: experian.com/help/child-identity-protection.html or call 1-888-397-3742
TransUnion: transunion.com/credit-freeze/child-identity-theft or mail to TransUnion, PO Box 380, Woodlyn, PA 19094
Each bureau sends confirmation within 2–3 weeks. Keep these confirmation letters — you’ll need the PIN to lift the freeze later.
How to Brief Your Kids on What Happened
The way you talk to children about a security incident directly affects whether they’ll come to you the next time something concerning happens — their own or a friend’s.
For kids under 10: Keep it simple and non-scary. “Someone tried to use our computer accounts to take some of our things. We caught it and fixed it. There’s nothing to worry about, but now we’re making everything extra secure. It’s like putting a better lock on the door.”
For kids 11–14: More detail is appropriate. “Somebody got our email password — probably from a website where we used the same password as something else. When that happens, they can get into other accounts too. That’s why we’re changing all our passwords and turning on extra verification. You should know this can happen to your accounts too — that’s why your Roblox account has the authenticator app.”
For teens 15+: They can handle the full picture. “Here’s what happened, here’s how we think it happened, here’s what it cost us to fix it, and here’s what we’re changing going forward.” Treating them as capable of understanding the full situation makes them more likely to disclose their own security problems.
The worst outcome is a child who experiences a social media hack, a sextortion attempt, or a gaming account compromise and doesn’t tell you because they assume you’ll be angry. Normalizing these conversations around an adult’s incident (not theirs) removes that barrier.
Internal Links
For the two-factor authentication setup that would prevent most account takeovers, see our complete guide to two-factor authentication for family accounts. For protecting gaming accounts specifically, read our guide to protecting kids’ gaming accounts from hackers. For strong password practices that prevent credential compromise, see our age-by-age guide to strong passwords for kids.
What to Watch For Over the Next 3 Months
Before any incident: Create a one-page “Family Digital Emergency Sheet” with: each family member’s email address, the username for each major account, the contact number for each financial institution, and the URLs for reporting to FTC and FBI. Store it physically. Update it when accounts change.
Month 1 (Prevention): Enable 2FA on all family email accounts. This single step prevents the most common cascade attack.
Month 2 (Credit protection): Submit credit freeze requests to all three bureaus for all minor children in your household.
Month 3 (Audit): Run all family email addresses through haveibeenpwned.com. If any appear in data breaches, change those passwords immediately and check whether the same password was used anywhere else.
Red flag: Login notifications you didn’t initiate are the clearest early warning. Set up login notifications on Gmail, Apple ID, and any financial accounts that support them. Treat any notification for a login you didn’t make as a confirmed compromise — not a possible one.
Frequently Asked Questions
What do I do if money was already taken from our bank account?
Contact your bank immediately using the phone number on the back of your card. Under Regulation E (federal law), you have up to 60 days from your statement date to report unauthorized electronic transactions and receive a refund. Report sooner for better protection — most banks resolve disputes within 10 business days and provide provisional credit while investigating. Also file at reportfraud.ftc.gov and ic3.gov for law enforcement purposes.
How do I know if any of our accounts were included in a data breach?
Visit haveibeenpwned.com and enter each family email address. The site cross-references against hundreds of known data breaches and tells you which breaches included that email, and what data was exposed (password, phone number, physical address). It’s free, legitimate, and maintained by security researcher Troy Hunt. For ongoing monitoring, the site offers email notifications when your address appears in new breaches.
Can I freeze my child’s credit before any theft has occurred?
Yes — and this is the strongly recommended approach. A proactive credit freeze on a child’s file costs nothing, takes 15–20 minutes per bureau to set up (plus mailing time), and prevents any credit-related identity fraud until the child needs to open accounts as an adult. You simply request a “lift” with your PIN when they’re ready. The FTC recommends placing a credit freeze on children’s credit files as a routine precaution, not a crisis response.
How do I stop the same hack from happening again?
Two changes prevent the vast majority of account takeovers: unique passwords for every account (use a password manager) and two-factor authentication on email and financial accounts. If you use the same password anywhere — or reuse any combination of email/password — you’re vulnerable to credential stuffing. A password manager (1Password, Bitwarden, Apple Passwords) generates and stores unique passwords for every site. Combined with 2FA, this closes the two most common attack paths.
About the author
Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.
Sources
- Identity Theft Resource Center. (2024). 2023 Annual Data Breach Report. https://www.idtheftcenter.org/publication/2023-annual-data-breach-report/
- Federal Trade Commission. (2024). IdentityTheft.gov Recovery Steps. https://www.identitytheft.gov
- Federal Trade Commission. (2024). Child Identity Theft. https://consumer.ftc.gov/articles/child-identity-theft
- Consumer Financial Protection Bureau. (2024). Regulation E: Electronic Fund Transfers. https://www.consumerfinance.gov/rules-policy/regulations/1005/
- Federal Bureau of Investigation. (2024). Internet Crime Report 2023. https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf
- Experian. (2024). How to Place a Security Freeze on Your Child’s Credit Report. https://www.experian.com/help/child-identity-protection.html