Secure a suspected compromised account
Invalidate old access, protect the verified email, and contact Support when self-service recovery is unavailable.
IF YOU CAN ACCESS THE VERIFIED EMAIL
1. Open Forgot password.
2. Use the newest reset link.
3. Set a unique 12–72 character password.
4. Sign in again and review the account and workspace activity.
A successful reset invalidates every existing session, reset token, and magic-link token. Changing the password from Account security also expires previous tokens and signs the current user back in with a new session.
IMPORTANT LIMITS
Signing out removes only the current session and remember-me cookie. Changing the email alone does not revoke existing sessions. There is no customer device/session page for revoking one device selectively.
If the verified email is inaccessible, create a guest Support request under Account access with a reachable address. Recovery may require ownership evidence and is not automatic. Never send a password, magic link, reset token, private key, or full payment details.
Was this article helpful?