Skip to content
Skip to main content
First Response & Preservation Technical Explainer

Could account-recovery action destroy useful evidence?

Yes. Recovery can replace credentials and recovery routes, end sessions, generate alerts and change provider records, even when it successfully restores legitimate access.

Preserve the pre-recovery state

Record the account identifier, current access, active sessions, linked devices, recovery addresses and phone numbers, authentication methods, recent sign-ins and security alerts. Note unfamiliar details and when they appeared. Do not start recovery merely to test whether access can be regained; attempts can trigger holds, notifications or waiting periods.

Where the victim is locked out or harm continues, recovery may be necessary. Use the official provider route from a safe device where possible and record why delay was unacceptable.

Make the recovery sequence auditable

Document every device, prompt, question, code, email, text, identity check, failed attempt and confirmation. Protect new credentials and recovery codes from personal notes and ordinary messaging. Preserve provider reference numbers and any lock or waiting period.

Afterwards, record which sessions ended or survived and what recovery, delegation, application-token and linked-device settings changed. Restored access does not prove the account is secure, because alternative tokens or compromised recovery paths may remain.

Key takeaway

Treat recovery as a potentially evidence-changing sequence: preserve the original access state, use the official route when protection requires it, and record every resulting credential and session change.

Reference: FRP-180First Response & Preservation