Account Login from Unknown Country – Quick Fix & Why

Your account showing a login from a country you've never visited. Here's how to kick them out, check for damage, and lock it down.

You saw a login alert from a country you've never been to. That's scary. Here's what to do right now.

Don't panic. Most of the time, you can lock the bad guys out in under 10 minutes. But you need to act fast, because whoever got in might still be poking around your email, bank, or social media. The steps below work for Google, Microsoft, Facebook, Apple, and most other major services.

Step 1: Change your password — but not at the same device

Open a browser on a phone or tablet you trust, not the computer where you saw the alert. Go to the account login page and reset your password. Make it long — 16 characters minimum with a mix of uppercase, lowercase, numbers, and symbols. Do not reuse this password on any other site.

What to expect: After you save the new password, you'll get an email or SMS confirming the change. If you don't see it within 2 minutes, check your spam folder.

Step 2: Force sign out of all sessions

Most platforms have a "sign out of all devices" or "sign out everywhere" button. Find it in your account security settings. Click it. This kills every active session, including the intruder's.

For example, on Google: go to myaccount.google.com → Security → Manage devices → Sign out of all devices. On Facebook: Settings & Privacy → Security and Login → Where you're logged in → Log Out Of All Sessions.

What to expect: You'll be signed out of everything yourself. So have your new password ready to log back in. You might need to re-enter your phone number or email for 2FA setup later.

Step 3: Turn on two-factor authentication (2FA) if it's not already on

This is the single most effective thing you can do. After you enable 2FA, even if someone steals your password, they can't get in without your phone. Use an authenticator app (like Google Authenticator or Microsoft Authenticator) instead of SMS when possible — SMS can be intercepted.

Go to your account's security settings, find "two-step verification" or "two-factor authentication," and follow the prompts. You'll scan a QR code with your phone, then enter a 6-digit code to confirm.

What to expect: The setup takes about 3 minutes. You'll get a set of backup codes. Save those somewhere safe (a printed paper in your wallet is fine). If you lose your phone, those backup codes are your only way back in.

Step 4: Check for changes the intruder made

Look at your account's recent activity log. It's usually under Security or Privacy settings. Scan for any new recovery email addresses, phone numbers, or forwarding rules (especially in email accounts). If you see something you didn't add, remove it immediately.

Also check your sent messages, deleted items, and any auto-forwarding rules. Hackers often set up forwarding to quietly read your mail while you ignore the breach.

Why these steps work

When you change the password, the intruder's cached credentials become worthless. Signing out everywhere forces their session to end — even if they had a cookie or token saved. 2FA adds a second lock that they can't pick without physical access to your phone. And checking recovery settings closes back doors they might have installed.

The real danger isn't the one login. It's that they might have set up persistent access. That's why step 4 matters more than most people realize. I've seen cases where someone changed their password but the hacker had already added a recovery email — so they just clicked "forgot password" and got back in the next day.

Less common variations of the same problem

VPN or proxy mismatches

Sometimes you get a login alert from a country you've never visited because your own VPN or proxy is routing through a server there. If you use a VPN, check its server location. Some free VPNs bounce connections through random countries. Solution: disable the VPN temporarily and check if the alert still shows.

Legitimate service geolocation errors

Occasionally, a service's IP geolocation database is wrong. An IP assigned to a US carrier might show as coming from Russia or Nigeria. This is rare but happens. Compare the IP address in the alert with your current IP (you can check at whatismyip.com). If they match, it's likely a false positive. Still, change your password as a precaution.

Family or shared device access

If you share a computer or phone with someone who travels, they might have logged into your account while abroad. Check with anyone who has your password. If that's the case, still change your password — shared passwords are never a good idea.

How to prevent this from happening again

  • Use a password manager. It generates and stores unique, strong passwords for each site. You only need to remember one master password. I recommend Bitwarden (free) or 1Password (paid).
  • Turn on 2FA on every account that supports it. That includes email, social media, banking, and work accounts. Use an authenticator app, not SMS, when possible.
  • Review your account permissions once a month. Remove apps and services you no longer use. They can be a weak point if they get compromised.
  • Don't click links in unsolicited emails or texts. That's how most passwords get stolen. If you get a message saying "unusual login detected" and it asks you to click a link, go directly to the website yourself instead.
  • Set up login alerts. Most services can email or text you when someone logs in from a new device or location. Enable that — it's your early warning system.

That's it. You're protected now. Go change that password.

Related Errors in Cybersecurity & Malware
0X0000361B Fix ERROR_IPSEC_IKE_NOTCBPRIV (0X0000361B) TCB Privilege Issue 0X800B0112 CERT_E_UNTRUSTEDCA (0x800B0112) Fix That Actually Works PC Slow After Free Software Install? Fix It Fast 0X0000070F Fix ERROR_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT (0X0000070F)

Was this solution helpful?

EP
Erropedia Team
Tech Support Editors
The Erropedia editorial team researches and documents real-world tech errors from across Windows, Linux, macOS, networking, databases, cloud platforms, and more. Every solution is reviewed for accuracy and updated as software and systems evolve.