Could securing the account protect a victim from further harm?¶
Yes. Securing an account may be necessary to stop ongoing abuse, fraud, surveillance or loss.
Why this matters¶
The dangerous assumption is that preservation should always delay protective action. Where harm is continuing, the victim’s safety and control of the account may take priority.
What to record and do¶
Potential actions include changing credentials, revoking sessions, removing malicious recovery details, enabling stronger authentication or contacting the provider.
Each action can alter evidence, terminate sessions or alert another user.
Before acting, preserve the visible account state where this can be done without unacceptable delay. Record identifiers, active sessions, recovery details, linked devices, recent sign-ins and current harm.
Use the least destructive effective measure. It may be possible to block one session rather than reset the whole account.
Where time allows, obtain specialist, provider, legal or safeguarding advice.
Record who made the decision, what risk was being managed, what action was taken and what evidential consequences followed.
Do not overstate the result. Securing one account may not remove access through linked services, devices or recovery routes.
Continue to consider victim support, monitoring and provider preservation after the immediate action.
Consider whether the victim has a safe alternative contact route before making changes that may alert the offender or lock the victim out. Preserve essential recovery information and provide clear instructions about what not to reconnect or reuse.
Record whether the victim can still access essential communications after the change.
Operational takeaway¶
Protect the victim where harm is continuing, but preserve the account state first where practicable and document every security action and evidential consequence.