Could account-recovery action destroy useful evidence?¶
Yes. Recovery can replace credentials and recovery routes, end sessions, generate alerts and change provider records, even when it successfully restores legitimate access.
Preserve the pre-recovery state¶
Record the account identifier, current access, active sessions, linked devices, recovery addresses and phone numbers, authentication methods, recent sign-ins and security alerts. Note unfamiliar details and when they appeared. Do not start recovery merely to test whether access can be regained; attempts can trigger holds, notifications or waiting periods.
Where the victim is locked out or harm continues, recovery may be necessary. Use the official provider route from a safe device where possible and record why delay was unacceptable.
Make the recovery sequence auditable¶
Document every device, prompt, question, code, email, text, identity check, failed attempt and confirmation. Protect new credentials and recovery codes from personal notes and ordinary messaging. Preserve provider reference numbers and any lock or waiting period.
Afterwards, record which sessions ended or survived and what recovery, delegation, application-token and linked-device settings changed. Restored access does not prove the account is secure, because alternative tokens or compromised recovery paths may remain.
Key takeaway
Treat recovery as a potentially evidence-changing sequence: preserve the original access state, use the official route when protection requires it, and record every resulting credential and session change.