Could securing the account protect a victim from further harm?¶
Yes. Credentials, sessions, recovery routes and provider controls may need changing to stop abuse, fraud, surveillance or exclusion from the account.
Protect the victim without losing the baseline¶
Where delay is safe, record account identifiers, sessions, linked devices, recovery details, sign-ins and present harm. Establish a safe alternative contact route before changes alert the offender or lock out the victim.
Use the narrowest effective measure: one hostile session may be revoked without resetting all access. Obtain provider, safeguarding, legal or technical advice where time permits.
Continue beyond the immediate reset¶
Record decision, operator, action and evidential cost. Check linked services, devices, delegated access and recovery routes rather than assuming one change restores control.
Provide clear support about credentials and reconnection, and preserve provider records after urgent protection.
Key takeaway
Stop continuing harm with the narrowest effective account control while preserving the original security state whenever the victim can safely wait.