A notification reads: "There is a login attempt from a new device." Many people immediately press the That's not me button, change their password, or even ignore it because they feel they haven't done anything suspicious.
The problem is, not all security alerts should be treated the same way. Some come from official services and help stop intruders. Others may be fake emails or messages deliberately crafted to panic you into entering your password on a spoofed page.
The ability to calmly read security alarms is important because attackers do not always start their actions by breaching complex systems. Often, they simply wait for the victim to react hastily.
Differentiate between three commonly mixed-up items
Before taking action, distinguish between login alerts, login approval requests, and phishing messages.
- Login alerts typically inform you of new activity, such as a login from an unknown device, location, or browser.
- Login approval requests ask you to approve or deny an ongoing login process. If you are not logging in, do not approve it.
- Phishing messages are messages that mimic official services and attempt to direct you to fake login links or pages.
All three can look similar. Attackers can even copy the language style, colors, and logos of popular services. Therefore, do not make the appearance of the message your sole basis for trust.
Do not click buttons from panic-inducing messages
Statements like "your account will be closed in 10 minutes" or "verify now to prevent blocking" are designed to narrow your thinking time. This is a common phishing pattern: victims are pushed to make decisions before they have a chance to verify the message's authenticity.
If you receive an alert via email, SMS, or messaging app, access the service through the official app or a saved address. Do not use links in the message. After logging in independently, check menus like Security, Recent security activity, or Your devices.
The FTC also advises users to contact companies through known phone numbers or websites, not through information listed in suspicious messages. Unexpected links and attachments can lead to data theft or the installation of malicious software.
How to read login alerts practically
1. Check if you are indeed logged in
Recall your activities from the last few minutes. Did you just log in from a laptop, switch browsers, clear cookies, use a VPN, or access your account from a different network? Such activities can sometimes cause the service to consider the login as something new.
However, do not immediately conclude that all alerts are system errors. If the timing is off or the device is unfamiliar, continue your investigation.
2. Assess devices and locations reasonably
The displayed location is not always accurate. Location estimates can vary due to cellular networks, VPNs, or internet service providers. Focus on the combination of information: device type, operating system, browser, activity time, and whether you recognize all of it.
For example, a location that is a few kilometers different may not necessarily be dangerous. But a Windows laptop that you have never used, appearing at three in the morning, should be taken seriously.
3. Access the security page through official channels
Do not rely on buttons in emails to change your password. Manually type the website address, use a saved bookmark, or open the official app. Google, for instance, provides activity and device checks through account security settings. The same principle applies to email, social media, marketplaces, and banking services.
4. Revoke unknown access
If you find devices or sessions that are not yours, remove those devices. Also, check third-party applications that have access to your account. Applications you may have tried in the past might still hold permissions to read profiles, access files, or perform certain actions.
5. Change your password in the correct order
Use a new password that is long and not used on other services. If the same password has been used on multiple sites, change them all—starting with your primary email, as email often serves as a recovery gateway for other accounts.
Do not change the password only on the account that sent the alert. If the credentials have been reused, attackers may try the same combination on other services. This practice is known as credential stuffing, which involves trying leaked usernames and passwords across many sites.
MFA helps, but not all methods are equally strong
Multi-factor authentication or MFA is an additional verification layer after the password, such as a code from an authenticator app, confirmation on a device, biometrics, or a security key.
MFA makes it harder for attackers to gain access even if your password is known. However, SMS codes or one-time codes can still be stolen through social engineering or fake login pages. CISA encourages the use of phishing-resistant authentication, such as FIDO or WebAuthn, if available. For services that do not support it yet, authenticator apps are usually a better option than relying solely on SMS.
Never give verification codes to anyone, including those claiming to be service agents. Official agents do not need those codes to "cancel a hijacking." If someone asks you to read a code that just came in, consider it a warning sign.
If you accidentally clicked a link or approved a login
There is no need to panic, but act quickly. Access the service through official channels, change your password, remove unknown devices, and enable MFA. If the same password is used elsewhere, change those accounts as well.
Check for changes to recovery email, phone number, email forwarding rules, and applications that have gained access. Attackers sometimes do not immediately change passwords. They may add their own recovery methods or create email rules to forward security messages to them.
If you provided card data, banking information, or access to your computer, contact your bank and service provider through official channels. For devices that may have downloaded malicious files, perform security updates and scans according to the manufacturer's guidelines.
What you can do now
- Open the security settings of your primary email and check the devices that are logged in.
- Enable MFA on email, financial services, social media, and marketplaces.
- Remove devices, sessions, and third-party applications that you do not recognize.
- Ensure your primary email password is not used on other sites.
- Save the official website addresses of important services as bookmarks.
- Get into the habit of checking accounts through the official app, not via links from messages.
Security notifications are not a reason to panic, but they are also not a distraction that should always be dismissed. Treat them like a smoke alarm: it may be triggered by something trivial, but you still need to check the source before returning to your activities.
Official references
- FTC Guide on Recognizing and Avoiding Phishing
- CISA Guide on Multi-Factor Authentication
- Google Guide to Checking Suspicious Activity on Your Account
Sources & Further Reading
- How To Recognize and Avoid Phishing Scams
- More than a Password
- Investigate Suspicious Activity on Your Account
– Rio Yotto @rioyotto
