What it is (in plain words):
Account hijacking is like someone slipping into your online life and wearing your name tag. They post as you, peek at your messages, even lock you out. It often starts small — a fake login page, a weak password — and suddenly a stranger is in your space.
How it happens:
Phishing pages that look real
Malware that steals saved logins
Weak or reused passwords
Stolen 2FA codes (SIM swap, fake prompts)
Signs to watch for:
New logins or devices you don’t recognize
Password or recovery info changed
Posts, messages, or purchases you didn’t make
If it happens, do this now:
Change the password from a clean device
Turn on 2-step verification (MFA)
Sign out of other sessions; remove unknown devices
Scan your device and update it
Tell contacts that recent messages might be fake
Prevent it:
Use strong, unique passwords (a manager helps)
Keep MFA on; prefer an app or security key over SMS
Double-check the web address before logging in
Keep your system and apps up to date

Secure the recovery path
Changing the password is only one step. Remove unfamiliar recovery email addresses and phone numbers, revoke active sessions and application tokens, regenerate backup codes, and inspect mailbox forwarding or social-account delegates. Save security alerts and login history before they expire.
Use a unique password and enable MFA, preferably a phishing-resistant method when the service supports it. If the account was taken through phishing or malware, secure the device and primary email account before resetting other services. Contact the provider through its official recovery page; people offering recovery through private messages are often running a second scam.