If you believe another person may have accessed your Ackaia ID, treat the account as potentially compromised and secure it as soon as possible.
Examples include an unexpected sign-in, an authentication request you did not initiate, an unfamiliar connected application, an account change you did not make, or credentials that may have been exposed.
Whenever possible, perform account recovery and security changes from a device and browser you control.
If you believe the device itself is compromised, secure or replace that device before relying on it for sensitive account changes.
If you can still access your Ackaia ID and believe the password may be known to someone else, replace it with a new, unique password.
Do not reuse a password that is also used for your email account or another service.
If you cannot sign in because the credentials were changed, start the Ackaia ID recovery process instead.
Open the Ackaia ID Security page:
https://id.ackaia.com/account/security
Scroll to Two-step verification and confirm that MFA is enabled and controlled by you.
If MFA is not enabled, follow the setup flow to enable it.
If MFA was unexpectedly disabled or altered, mention this when reporting the compromise to Ackaia Support.
Open:
https://id.ackaia.com/account/apps
Review the applications connected to your Ackaia ID and revoke access for:
applications you do not recognize;
applications you no longer use;
connections that were created or changed unexpectedly.
Review any available account-security or session information for activity you do not recognize.
Ackaia can revoke sessions or apply additional account-security controls when reasonably necessary to protect an account. If you cannot terminate an unsafe session yourself, report the suspected compromise promptly.
If an attacker controls the email or recovery account associated with your Ackaia ID, changing only the Ackaia ID password may not be sufficient.
Secure the associated email account, including its password, MFA, active sessions, forwarding rules, recovery information, and connected applications as applicable.
Report the incident promptly and include:
the approximate time you first noticed the issue;
the most recent time you know the account was under your control;
unexpected security notices or account changes;
unrecognized applications or sessions;
the Ackaia products affected;
the exact error or restriction currently shown.
Never include passwords, MFA codes, recovery codes, private keys, or other authentication secrets.
After securing the Ackaia ID itself, review Ackaia products that were accessible through the account.
Depending on the product, check for unexpected changes to:
sharing or public links;
connected applications or integrations;
organization memberships or permissions;
billing or subscription settings;
security settings;
other product-specific activity.
For encrypted products, also protect any local cryptographic material and trusted devices independently of the Ackaia ID account.
Recovering Access to Your Ackaia ID
Managing Connected Apps on Your Ackaia ID
How to Enable or Disable MFA on Your Ackaia ID