Unknown user signing in from a new device: what to do now
For customers who received a sign-in alert for a device or location they do not recognise. This runbook helps you quickly decide whether it is a harmless false alarm or a real account compromise, then lock the account down and verify access is safe again.
TL;DR — If you get an alert that a user you do not recognise is signing in from a new device, treat it as suspicious until proven otherwise. The fastest safe response is: change the account password, sign out all sessions, remove unknown devices or sessions, and turn on multi-factor authentication (MFA, an extra sign-in code) before reviewing recent sign-in history. Reading time: ~6 min
The scenario
It is a normal Tuesday afternoon and an email lands in your inbox: "New sign-in from Chrome on Windows". The location looks unfamiliar, the device name means nothing to you, and nobody on your team says they were logging in. You can still access the account, but you are not sure whether this is just a phone network, a VPN (a service that routes internet traffic through another location), or somebody else inside your account right now. You need to check quickly without making things worse.
Symptoms
- Email or app alert such as:
New sign-in from a new device
We noticed a login to your account from a device we haven't seen before.
- Security page shows a recent session you do not recognise, often with a browser, device type, IP address, city, or country.
- You may see sign-in history entries like:
Successful login
Device: Chrome on Windows
Location: Frankfurt, DE
IP: 203.0.113.24
- Password reset emails you did not request.
- MFA prompts you did not approve, for example:
Did you just try to sign in?
Approve or deny this request.
- Account changes you did not make, such as updated recovery email, phone number, or profile details.
- In more serious cases, teammates report strange messages, changed settings, or missing data after the sign-in.
Likely causes
| Cause | How common | Quick check |
|---|---|---|
| It was really you on a new browser, phone, laptop, or after clearing cookies | Very common | Security/Account Settings → Recent activity or Devices |
| The location looks wrong because of VPN, mobile carrier routing, office internet, or corporate security gateway | Common | Compare the alert IP with your current public IP at https://ifconfig.me |
| Your password was reused, guessed, or exposed in a breach | Common | Security/Account Settings → Recent activity; look for successful logins you cannot explain |
| MFA is not enabled, was bypassed, or you approved a prompt by mistake | Common | Security/Account Settings → Two-factor authentication / MFA |
| A shared mailbox, saved browser session, or shared device let someone else in | Occasional | Check whether the account is signed in on a shared computer or team-owned device |
| The alert is delayed or inaccurate, but the account is not compromised | Less common | Compare alert time with your own activity and current session list |
Step-by-step diagnosis
-
Open your account security page and recent sign-in history. In your provider's dashboard, go to
Account/Profile → Security → Recent activity,Login history, orDevices & sessions.- This is your problem if: you see a successful login from a device, browser, or location that nobody in your team can explain.
- Jump to:
### Your password was reused, guessed, or exposed in a breachand### MFA is not enabled, was bypassed, or you approved a prompt by mistake.
-
Check whether the "new device" is actually one of yours. Look at the browser, operating system, and approximate time in the alert. Then compare with your own devices.
- This is your problem if: the entry matches a real action, such as signing in from your phone browser instead of the mobile app, using a private/incognito window, reinstalling the app, or clearing cookies.
- Jump to:
### It was really you on a new browser, phone, laptop, or after clearing cookies.
-
Compare the alert IP or location with your current network. If the alert shows an IP address, open this in a browser on the device you used:
https://ifconfig.me
- This is your problem if: the IP is the same or close, but the city/country in the alert looks different. That usually means VPN, mobile routing, or ISP (internet service provider) geolocation drift.
- Jump to:
### The location looks wrong because of VPN, mobile carrier routing, office internet, or corporate security gateway.
-
Check whether MFA is enabled and whether there were approval prompts. In your provider's dashboard, go to
Account/Profile → Security → Two-factor authenticationorMFA.- This is your problem if: MFA is off, only SMS is enabled when stronger options are available, or you see push approvals you did not initiate.
- Jump to:
### MFA is not enabled, was bypassed, or you approved a prompt by mistake.
-
Review recovery methods and active sessions. Go to
Account/Profile → Security → Sessions,Devices,Recovery email, andRecovery phone.- This is your problem if: there is an unknown device, unknown session, changed recovery email/phone, or a session that stays active after you change your password.
- Jump to:
### A shared mailbox, saved browser session, or shared device let someone else inand also rotate the password immediately.
-
If anything still looks suspicious, contain first and investigate second. Change the password, sign out everywhere, remove unknown devices, and re-check activity.
- This is your problem if: new sign-ins continue after the password change, or settings keep changing.
- Jump to: all relevant fix sections below. If the account protects billing, customer data, or admin access, contact your provider's support after containment and ask them to review sign-in logs.
Fixes
It was really you on a new browser, phone, laptop, or after clearing cookies
A "new device" often just means the service no longer recognises the browser session. This happens after browser updates, cookie clearing, app reinstall, private browsing, or switching from app to browser.
What to do
- Confirm the time, browser, and operating system match your own use.
- In
Account/Profile → Security → Devices & sessions, rename or mark trusted devices if your provider offers that option. - If the alert was legitimate but you still do not have MFA enabled, turn it on now.
Verify it worked
- New activity matches your own devices only, and no unexplained sessions appear over the next 24 hours.
The location looks wrong because of VPN, mobile carrier routing, office internet, or corporate security gateway
IP geolocation is approximate. A login from your office or phone may show a nearby city, another region, or sometimes another country if traffic exits through a VPN or gateway.
What to do
- Compare the alert IP with your current public IP by opening:
https://ifconfig.me
- If you use a VPN, disconnect it and sign in again. If the new login now shows your expected area, the earlier alert was likely caused by the VPN.
- If you are on mobile data, switch to your normal Wi‑Fi and compare the next sign-in entry.
- If your company uses a secure web gateway or office VPN, ask your IT contact whether the alert IP belongs to that service.
Verify it worked
- The IP or device details line up with your known network path, and there are no other unknown sessions.
Your password was reused, guessed, or exposed in a breach
This is the most important case to treat seriously. If someone signed in successfully and you cannot explain it, assume the password is compromised.
What to do
- Change the password immediately in
Account/Profile → Security → Password. - Use a unique password generated by your password manager. If you need a temporary format, use at least 16 random characters.
- Then go to
Account/Profile → Security → SessionsorDevicesand chooseSign out all other sessions,Log out everywhere, or similar. - Review
Recovery email,Recovery phone, and any forwarding or notification rules. Remove anything you do not recognise. - If the same password was used anywhere else, change it there too.
⚠️ If this account has admin access, billing access, customer data, or email access, treat this as a security incident. Password changes and forced sign-out can interrupt active work, but delaying them is riskier.
Verify it worked
- The old password no longer works, all other sessions are gone, and no new unknown sign-ins appear after the reset.
MFA is not enabled, was bypassed, or you approved a prompt by mistake
MFA adds a second proof of identity. Without it, a stolen password is often enough. With push-based MFA, repeated prompts can trick people into approving one by accident.
What to do
- In
Account/Profile → Security → Two-factor authentication, enable MFA. - Prefer an authenticator app or hardware security key over SMS if your provider supports it.
- Save backup codes in your password manager or company vault.
- If you received MFA prompts you did not start, change the password first, then revoke all sessions.
- If your provider supports number matching or phishing-resistant MFA (for example, security keys), switch to that option.
Verify it worked
- The next login requires the second factor, and unexpected MFA prompts stop.
A shared mailbox, saved browser session, or shared device let someone else in
Sometimes the account was not "hacked" in the usual sense; someone had access because the device or browser session was already trusted.
What to do
- Check whether the account is signed in on a shared laptop, front-desk machine, contractor device, or family computer.
- In
Account/Profile → Security → Devices & sessions, remove every device you do not personally control. - On shared browsers, sign out and clear saved passwords/autofill for that account.
- If this is a team account, stop sharing one login. Create separate user accounts for each person if your service supports it.
Verify it worked
- Only your own devices remain in the session list, and the unknown sign-ins stop.
The alert is delayed or inaccurate, but the account is not compromised
Some providers send alerts late, group sessions oddly, or create a "new device" event after a browser update.
What to do
- Match the alert time against your own activity from the same hour.
- Check whether the session is still active in
Devices & sessions. - If everything lines up and there are no unknown changes, keep the alert for reference and still enable MFA if not already enabled.
Verify it worked
- No unexplained account changes exist, and later activity remains consistent with your own use.
Prevention
- Turn on MFA for every important account. In each service, go to
Account/Profile → Security → Two-factor authenticationand enable an authenticator app or security key. - Use a password manager and unique passwords. Do not reuse the same password across email, project tools, hosting, and billing. If one service is breached, reused passwords are the first thing attackers try.
- Review active sessions monthly. Put a recurring calendar reminder for
Security → Devices & sessionsand remove old laptops, old phones, and contractor devices. - Enable security alerts and send them to a monitored mailbox. In
Settings → NotificationsorSecurity alerts, turn on alerts for new sign-ins, password changes, recovery method changes, and MFA changes. - Separate admin accounts from day-to-day accounts. If your platform allows it, use one account for normal work and a different admin account for billing or production changes. That limits damage if one session is exposed.
- For team accounts, stop sharing one login. Create one user per person and remove access when someone leaves. Shared credentials make "unknown user" incidents much harder to investigate and contain.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI