The first priority is regaining control of the account before the attacker locks you out permanently. Go directly to the service's account recovery page and use the official password reset process. Do this immediately, before taking any other action. If the attacker has already changed your password, use the account recovery options such as your backup email address, phone number, or recovery codes. If you can still log in, change your password immediately to a long, unique string generated by a password manager, and revoke all active sessions to sign out every other device.
Enable two-factor authentication on the account the moment you regain access if it is not already enabled. Two-factor authentication is what prevents this situation from recurring. Without it, a stolen password is sufficient to compromise your account. With it, a stolen password is insufficient because the attacker also needs physical access to your phone or authenticator app. This is the most important security improvement you can make in the immediate aftermath of a compromise and should have been in place before the incident.
Assess what the attacker had access to and for how long. If it was your email account, they had access to every password reset link that arrived, which means every account linked to that email address is potentially compromised. Change the passwords on your most critical accounts: banking, cloud storage, social media, your domain registrar, and your hosting provider. If it was a social media account, check whether any messages were sent, any posts were made, or any permissions were granted to third-party apps during the period of compromise.
Notify anyone who needs to know. If your business email was compromised, your contacts may have received phishing messages appearing to come from you. Send a note to your key contacts explaining the situation and warning them to disregard any unusual requests they received from your address. If your business social media account was compromised and posts were made, remove the malicious content and publish a clarification. Transparency about what happened is almost always better than hoping no one noticed.
Report the incident to the platform. Every major platform has an account compromise reporting mechanism. Using it creates a record of the incident and may assist in recovery, particularly if the attacker changed your recovery information before you regained access. For financial account compromises, contact your bank or payment processor directly by phone using the number on your card or statement, not a number found in any email related to the incident.
A compromised account is a forcing function for security improvements that should have happened before the incident. When you have regained control, audit your entire account portfolio: every account that uses the same password as the compromised one, every account without two-factor authentication, and every account that has not been accessed in years. Use the incident as the moment to implement the security hygiene that prevents the next one.