brand logo
How to manage an account compromise

How to manage an account compromise

09 Aug 2026 | By Danara Kulathilaka


  • Recovery ultimately depends on global tech platforms, not local authorities
  • Experts warn against paying self-proclaimed account recovery agents
  • Sri Lanka CERT, Police can help investigate, but cannot simply restore access
  • Prevention remains best defence against phishing, account hijacking


We have become increasingly more reliant on digital platforms for communication, banking, business, and personal connections. With that, the possibility of online account compromise has also increased. Cybercriminals often target email accounts, WhatsApp profiles, and social media accounts for financial gain, personal information, or access to a victim’s digital identity.

According to experts, the majority of account breaches are caused by phishing attempts, weak passwords, reused credentials from past data breaches, or a lack of additional security measures like two-factor authentication. 

Attackers often impersonate legitimate platforms by creating fake login pages or messages that deceive users into exposing their usernames or passwords.

However, recovering a compromised account isn’t always easy. The process depends largely on the platform involved, as companies such as Meta, Google, and WhatsApp have their own recovery procedures. In Sri Lanka, law enforcement and other related agencies can provide assistance in certain situations, while legal action may also be pursued under cybercrime-related laws.


What can be done?


Cybersecurity expert Asela Waidyalankara pointed out that most online platforms, including social media, messaging services, and email providers, had built-in account recovery protocols that users should follow if they lost access to their accounts.

“Each platform has a series of steps they want you to take if you have lost control of your account,” he said. “For example, platforms such as Facebook can detect suspicious login activity, such as someone suddenly logging in from another country, and automatically flag the account. Some platforms also allow users to report that an account has been hacked.”

Waidyalankara explained that recovery procedures varied across platforms. “Instagram, for instance, may ask users to submit a selfie so it can verify their identity by matching it with previously uploaded photos. Different platforms have different recovery processes, but the important thing is to follow the steps provided by the platform,” he noted.

He added that users with paid or verified accounts on platforms such as Meta may receive faster assistance during the account recovery process.

“If you have a verified or paid business profile on Meta, the company generally gives higher priority to your support request. However, regardless of whether the account is paid or not, users must still follow the platform’s official account recovery process,” he said.

Victims of compromised online accounts should first use the official recovery process offered by the platform, as it is usually the quickest and safest option to restore access, according to Sri Lanka Computer Emergency Readiness Team (Sri Lanka CERT) Lead Information Security Engineer Charuka Damunupola.

“The first thing you should do after an account has been compromised is to follow the recovery process provided by the platform. The recovery process differs from platform to platform, but it is the safest and quickest way to recover your account,” he said.

Damunupola explained that most email and social media platforms allowed users to recover accounts using the ‘forgot password’ feature and further elaborated on WhatsApp’s recovery process.

“If your WhatsApp account has been compromised, you should reinstall the application and attempt the recovery process using your phone number. However, attackers often enable additional security settings after taking over the account, preventing victims from receiving the verification SMS. In such cases, users should contact WhatsApp Support to reset the verification process,” he said.

He also advised users to initiate account recovery from a device they had previously used to access the account.

“Using a trusted device improves the chances of a successful recovery because the platform can recognise that device as one that has previously been used to access the account,” he explained.

Damunupola said that victims should immediately notify their contacts if their WhatsApp account had been compromised. “Criminals often use compromised WhatsApp accounts to request money from the victim’s contacts. Inform your family, friends, and colleagues through a phone call or SMS as soon as possible so they are not deceived,” he said.

He added that if users were unable to recover their accounts via the platform’s recovery process, they should contact the platform’s support channels instead.


Before it happens: Protect your account


Rather than focusing solely on recovering compromised accounts, Waidyalankara advised users to pursue preventive cybersecurity actions that could reduce the likelihood of compromise in the first place.

“As a baseline, you need to enable two-factor authentication. It cannot be just your password. That is the first level of security you need to have. Whether you choose SMS-based authentication or an authentication app, enabling two-factor authentication significantly reduces the likelihood of your account being compromised,” he said, emphasising that the best strategy was to safeguard accounts prior to an incident occurring.

Waidyalankara also encouraged users to practise ‘good cybersecurity hygiene’ by using strong passwords, regularly reviewing active login sessions, limiting access to trusted devices and browsers, maintaining updated recovery email addresses, and periodically conducting security reviews of their accounts.

“Nine times out of 10, the incidents we see involve users who have not enabled two-factor authentication, are using weak passwords, or are still using passwords that were exposed in previous data breaches and never changed,” he said. “Instead of asking what to do after an account is compromised, people should focus on preventing it from happening in the first place, because recovering the account could either be successful or unsuccessful.”

Damunupola also stressed that prevention remained the most effective defence against account compromise. “The most important thing is to prevent these incidents by enabling recovery options, activating two-step verification, and being cautious when clicking links or entering your credentials on unfamiliar websites,” he said.

He added that enabling two-step verification provided an additional layer of protection. “Even if someone manages to obtain your password, they still need to complete the second authentication step, such as a One-Time Password (OTP) or an authenticator app, before they can access your account,” he said.

Damunupola urged users to pay close attention to security notifications from email providers and other platforms. “Many users ignore notifications about suspicious login attempts or logins from unusual locations. These alerts are very important because they give users an opportunity to secure their accounts before attackers gain full control,” he said.

He also advised users to monitor their account activity for signs of unauthorised access. “If you notice messages in your inbox that you did not send or other suspicious activity carried out without your knowledge, change your password immediately. Doing so can log the attacker out of your account and help prevent further misuse,” he said.

Additionally, Damunupola recommended users to regularly review the list of devices logged into their accounts. “Most platforms allow users to view active login sessions. If you notice an unfamiliar device, immediately sign it out remotely and change your password,” he added.

Furthermore, Damunupola warned users against logging into sensitive accounts over unsecured public Wi-Fi networks. “It is not advisable to use public Wi-Fi for activities such as logging into email, social media, or online banking. Where possible, use your mobile data for sensitive transactions because you cannot always guarantee the security of public networks,” he added.


How does an account get compromised?


Damunupola identified phishing as the most common method used by cybercriminals to steal account credentials.

“Victims receive a message or email containing a link that directs them to a fake login page which looks almost identical to the genuine website. It will look very similar to or appear to be an identical clone of the website login page, but if you look carefully, there might be differences or misspelling in the domain name. We call that typosquatting. Through these, users unknowingly enter their usernames and passwords, exposing their credentials to attackers,” he said.

Waidyalankara also cautioned users to be vigilant of phishing attacks and never share OTPs or verification codes with anyone.

“People are often tricked into sharing an OTP that is actually being used to transfer control of their WhatsApp account to someone else. Once you approve that request yourself, it becomes much more difficult even for the platform to determine whether it was a legitimate action or whether you were deceived,” he explained.


How attackers misuse compromised accounts


Damunupola further explained how attackers exploited various types of compromised accounts.

“In WhatsApp cases, attackers commonly impersonate victims to request money from their contacts. With email accounts, they often remain unnoticed while monitoring communications before attempting financial fraud. On Facebook and Instagram, compromised accounts are frequently used to impersonate victims, send inappropriate messages, solicit intimate images, or conduct scams using the victim’s identity,” he said.

He also noted that in rare cases, compromised YouTube channels and other social media accounts had been misused to run unauthorised advertisements or promote scams. Such activity can result in the platform taking action against the account, including suspending or permanently banning it due to violations of its policies.


Who can help in SL?


According to Damunupola, victims of compromised Facebook and Instagram accounts that cannot be retrieved may request assistance from the cybercrime division of the Criminal Investigation Department (CID) to have the compromised account terminated.

“They cannot recover the account on your behalf, but they may assist in removing an account that you no longer have access to,” he noted.

Damunupola explained Sri Lanka CERT’s role, saying that the organisation provided technical assistance for specific platforms, but added that its ability to recover accounts was dependent on the service provider.

“If users have already followed the official recovery process and are still unable to recover their account, they can contact Sri Lanka CERT for assistance. We can technically assist with recovering compromised WhatsApp accounts and can request the removal of compromised TikTok accounts. 

“However, for Facebook and Instagram accounts, victims should contact the CID cybercrime division, while email providers require users to follow their own recovery procedures,” he told The Sunday Morning.

He said that users could reach Sri Lanka CERT via its 101 hotline or by sending a support ticket through its website.

“At present, there is no dedicated channel to recover compromised email accounts. The recommended approach is to follow the official recovery process provided by the email service provider, whether it is Gmail, Yahoo, or another platform,” he said, noting that Sri Lanka currently had no dedicated local authority that could directly assist with recovering compromised email accounts.

Victims whose email or social media accounts have been compromised should report the incident to the Police, as investigations are handled under the leadership of the Sri Lanka Police Information Technology Division, according to Police Spokesperson ASP F.U. Wootler.

“When a social media account is compromised, interfered with, or targeted through phishing or similar cyberattacks, the Police Information Technology Division, which is based at the Police Headquarters, will look into the matter,” he said.

He noted that since such incidents required technological competence, the division performed the necessary investigations and inquiries while supporting other Police units.

ASP Wootler also said that whenever a complaint was received, the necessary authorities, including Sri Lanka CERT, were alerted as part of the inquiry process. “If it is actually a hacking or phishing incident, the necessary complaint will be pursued and the required investigations will be carried out,” he added.

However, Waidyalankara cautioned against expecting that local organisations could simply recover hacked or compromised accounts.

“Many people think they can simply go to the Police, Sri Lanka CERT, or even a digital marketing agency and have the account recovered. The reality is that their ability to help is limited because the final decision rests with the platform itself,” he said.

According to Waidyalankara, organisations such as Sri Lanka CERT can only notify companies like Meta about a compromised account, but users must still complete the platform’s official recovery process.

He also warned against individuals who promise to recover hacked or compromised accounts in exchange for money. “Some people claim they can recover your account if you pay them a large sum of money, but many victims end up losing money without getting their account back,” he said.


Legal perspective


Sri Lanka’s legal framework provides many ways for victims of hacked and compromised online accounts to seek legal recourse, with the Computer Crime Act No.24 of 2007 serving as the primary legislation governing cyber offences, according to Attorney-at-Law Thineth Korasagalla.

“The Computer Crime Act makes it a criminal offence to gain access to another person’s computer system or online account without authority. It also covers the unauthorised modification of data, unlawful interception of data, and other forms of computer misuse,” he said, noting that offenders may face imprisonment, fines, or both upon conviction. 

Korasagalla explained that the act also gave law enforcement the authority to investigate cybercrimes, seek search warrants, seize computers and other digital devices, and preserve electronic evidence for prosecution.

He noted that other laws may also apply depending on the nature of the offence. “If the offender steals money or misuses debit or credit card information, the Payment Devices Frauds Act No.30 of 2006 may also apply. Where a hacked or compromised account is used to threaten, harass, or commit other criminal acts, relevant provisions of the Penal Code can also be invoked,” he said.

He further stated that victims whose personal information had been unlawfully accessed or disclosed may be protected under the Personal Data Protection Act No.9 of 2022.

Referring to the Online Safety Act No.9 of 2024, Korasagalla said that while it was not a hacking-related law, it became relevant when a compromised account was used to impersonate someone, spread false or harmful content, or encourage online harassment.

“The act provides for the establishment of the Online Safety Commission, which has powers relating to prohibited online communications and can work with online service providers in appropriate cases. However, the commission has not been established yet, so those provisions are not currently in force,” he explained.

Korasagalla encouraged victims to report such incidents to their local Police station or to the CID’s cybercrime division.

“It is also advisable to report the incident to Sri Lanka CERT, which assists victims in securing compromised accounts and coordinating with major online platforms such as Facebook, Instagram, WhatsApp, and Google,” he said.

He emphasised the need to act quickly, advising victims to immediately use the relevant platform’s account recovery tools, change passwords for any associated accounts, enable two-factor authentication, and sign out of unknown devices.

“Inform your family members, friends, and business contacts that your account has been compromised, as hackers frequently use hacked accounts to deceive others. Never pay money to the hacker,” he cautioned.

Korasagalla also emphasised the significance of preserving electronic evidence, pointing out that it often determined the success of a criminal investigation.

“Keep screenshots of suspicious messages, altered profile details, login alerts, recovery emails, and any communications from the hacker. Record the dates and times of each event. If financial loss has occurred, retain bank statements and transaction records. Properly preserved digital evidence is admissible before Sri Lankan courts,” he said.

He encouraged victims not to delay reporting occurrences out of fear or embarrassment.

“The earlier the complaint is made, the greater the chance of recovering the account, identifying the offender, and preventing further damage. Sri Lanka now has several legal mechanisms to combat cybercrime and harmful online conduct. The key is to act promptly, preserve the evidence, and seek legal assistance where necessary,” Korasagalla added.

 



More News..