Unauthorized account access: what to document before you reset credentials

People rarely notice unauthorized account access directly. They notice a side effect: a message sent in their name, an order they never placed, a password reset nobody requested. The instinct is to clean everything up at once, which means new credentials, every device signed out, suspicious messages deleted. Those few minutes also erase the only thing that would have turned a police report into something more than a personal account of events.

The distinction matters because this offence is proven by the access, not by the damage. It is not enough that unwanted messages went out. What counts is being able to state when a stranger got in, from where, with which device, and how long they stayed. That information sits in the security section of the account, and it stays visible for a short window. One practical rule follows: capture first, restore afterwards. And the capture has to survive the scrutiny of whoever receives it, which a folder of saved images does not.

As covered in our guide on digital identity theft and cloned accounts, the problem affects individuals and organizations alike. This insight narrows the field to one specific case: the account you own, broken into from the inside.

This insight is part of our guide: Digital Identity Theft and Cloned Accounts: How to Certify Evidence for a Complaint

What disappears in the first minutes after an account is compromised

Resetting the credentials closes the gap and, at the same time, wipes the state that described the intrusion. Active sessions, connected devices and security alerts are live elements: the service updates them in real time and keeps no copy for the user. Once the account is clean, the consequences of the damage remain, but the circumstances of the access do not, and those circumstances are what a complaint rests on.

The traces a password reset erases

Signing out of every session is the first thing any provider recommends, and it is the right call for security. In evidentiary terms, though, the screen listing two active sessions from a country you have never visited is a photograph of the intrusion while it is happening. After the sign-out, the same screen shows one device, yours, and there is no way to reconstruct the earlier state. The same applies to settings the attacker changed, such as a replaced recovery address or an automatic forwarding rule: fix them before documenting them and you lose the proof of persistence, meaning the proof that the access was set up to last rather than being a one-off.

How long provider-side records stay available

The same data also exists on the provider's side, but on a different track and a different clock. Users cannot pull it themselves: it is obtained through judicial channels, which places it after the report rather than before, with no guarantee of success. Retention periods vary by provider, by data type and by jurisdiction, and they can expire before the request reaches the right desk. What the account holder does have immediately is the sign-in history shown in their own dashboard. It is thinner than the provider's records, and it has one decisive advantage: it is available now, and it lets the report be specific on the day it is filed.

What to capture before you restore access

The right sequence is capture, secure, report. The first step calls for five elements, all reachable from the account settings without technical skills. What orders them is not importance but volatility: first what vanishes with the earliest corrective action, then what survives it.

The elements to collect, ordered by volatility

Element Where it lives What it proves
Active sessions and connected devices Account security settings That control of the account was shared with a third party at the time of capture
Sign-in history with date, time, IP address and estimated location Recent activity or sign-in log When the intrusion started and where it came from
Altered settings: recovery address, forwarding rules, two-step verification Security and forwarding sections of the service That the access was made persistent rather than being a single episode
Security alerts received Recovery mailbox, SMS, in-app notifications The timing of the attempt and the moment the holder became aware of it
Actions taken from the account: messages sent, orders, payments Sent folder, order history, conversations The link between the intrusion and the harm suffered by the holder or by third parties

A phone snapshot of those screens, forwarded through a messaging app, does very little work. It reaches the other side as an image with no verifiable date, recompressed in transit, with no demonstrable link to the original screen. It runs into the objection familiar to anyone who has tried to rely on a screenshot as evidence in court. Under Federal Rule of Evidence 901 and its equivalents in other systems, the party producing an item must support a finding that the item is what it claims to be. A picture of a dashboard, on its own, rarely carries that burden.

TrueScreen

TrueScreen

TrueScreen, the forensic acquisition and certification platform

Acquire and certify digital content with legal value, right from the source.

Discover more →

From capture to report: what investigators actually check

Illegal access to a computer system is a criminal offence across most jurisdictions, and the wording is remarkably consistent: it covers both getting in without right and staying in against the will of whoever is entitled to exclude you. The Budapest Convention on Cybercrime sets that baseline in Article 2 for its signatory states, and national statutes follow the same logic. Time limits differ, which is the part worth checking early, because in several systems the clock starts when the holder discovers the intrusion, that is, exactly when the traces are still recoverable.

The pattern behind these cases is dull rather than dramatic. The Verizon Data Breach Investigations Report 2025 attributes a role to stolen credentials in 32 per cent of the breaches it analyzed, with 22 per cent starting from credential abuse outright. The ENISA Threat Landscape 2025 places phishing first among intrusion vectors, at roughly 60 per cent of observed cases. Valid credentials used by the wrong person, not a spectacular exploit, is how most accounts change hands.

Why date and origin matter more than content

Whoever receives the report seldom argues about what the screen says. They argue about when it was captured and where it came from. A sign-in log becomes useful once you can state that it was acquired at a precise moment, that it has not changed since, and that it genuinely came from that provider's dashboard. Strip those three elements away and what remains is the complainant describing a matter that concerns the complainant. The reasoning matches what applies to proving the original email in an invoice IBAN fraud, where the case turns on authenticity and timing rather than on wording.

How TrueScreen certifies the traces of unauthorized access

TrueScreen covers the step that usually goes missing, between the moment the holder sees the traces in the dashboard and the moment those traces have to be handed to a lawyer, an authority or an employer. Active session screens, sign-in history, altered settings and messages sent from the account are acquired through a forensic methodology directly at the source, inside an environment that prevents alteration, rather than being saved as pictures. The acquisition then carries a digital seal and a timestamp with internationally recognized legal value, fixing both content and moment and making any later change detectable.

What comes out is a package a third party can verify months later, when the account has long been cleaned and the original screen no longer exists. The practices behind it follow ISO/IEC 27037 for handling digital evidence, so the chain of custody is documented rather than asserted. Capture runs from the mobile app or from the platform, which keeps the whole collection inside the session that precedes the credential reset.

One recurring scenario shows the difference. A finance department mailbox is compromised and used to redirect a payment to a different account. Certify the foreign session, the forwarding rule the attacker created and the messages sent, all before the reset, and the company has a documentary basis for the criminal complaint, for the dispute with the customer who insists the invoice was paid, and for the notification to the bank. Reset first, and what remains is someone's recollection of a screen they once saw.

FAQ: unauthorized account access and evidence

What should be done first when a corporate account is compromised?
Capture before you fix. Active sessions, connected devices, sign-in history and altered settings need to be acquired while they are still visible in the account dashboard, because a credential reset and a forced sign-out clear them. Securing the account and filing the report come afterwards.
Is a screenshot of the sign-in history enough for a police report?
It can be attached, but it is easy to challenge. The party producing digital material has to support a finding that it is what it claims to be, and a phone picture of a dashboard carries no verifiable date or origin. A forensic capture sealed at the source, with a timestamp, answers that objection directly.
Can the provider still supply the access logs later?
Sometimes, but not on the holder's initiative. Provider-side records are obtained through judicial channels after a report is filed, and retention periods differ by provider, data type and jurisdiction. The sign-in history visible in the dashboard is thinner, yet it is available immediately and can be certified on the spot.

Capture the traces before you reset the account

Active sessions, sign-in history and altered settings stay visible for a short window. Capturing them through a forensic methodology means filing the report with a verifiable package instead of a description.

mockup app