Skip to content
Skip to main content
First Response & Preservation Technical Explainer

What should be preserved from a victim’s account-security alerts?

Preserve the alert in its original delivery channel, together with the account, device, timing and the victim's response. The wording alone is rarely enough to interpret it.

Retain the provider's technical context

Record the service, account identifier, date, time zone, receiving device and whether the alert arrived by email, text, application notification or security page. Capture the alert type and any displayed device, browser, location, network address, session, recovery change, password reset or authentication event. Keep provider references and link text without selecting controls unnecessarily.

Displayed locations and device names may be approximate, inferred or user-editable. They identify a technical event for corroboration, not automatically the offender.

Document response and state changes

Ask whether the victim recognised, approved, rejected or ignored the activity and whether the alert was delayed, repeated or mirrored to other devices. Preserve related authenticator prompts, emails, texts and linked-device notifications.

Buttons such as “secure account” can revoke sessions, change credentials and create audit records. If immediate protection requires their use, record the alert first where safe, then capture the exact time, device and all resulting notifications and session changes.

Key takeaway

Preserve account-security alerts with their original channel, identifiers, timing and response history before using controls that may change the very access evidence under investigation.

Reference: FRP-179First Response & Preservation