> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nexcloud.in/llms.txt
> Use this file to discover all available pages before exploring further.

# Account Breach

> If you believe your NexCloud account has been accessed by someone else, act immediately to secure your account and prevent further unauthorized access.

### Change Your Password

If you can still access your account

1. Go to your **Account Settings**.
2. Change your account password immediately.
3. Use a **new, unique password** that you have not used anywhere else.
4. Do not share your new password with anyone.

If you cannot log in, use the account recovery option or contact NexCloud Support.

### Enable Two-Factor Authentication

After changing your password, enable **Two-Factor Authentication (2FA)** on your account.

2FA provides an additional layer of protection even if your password is compromised.

### Check Your Account Activity

Review your account for anything you do not recognize, including

* Changes to server configurations
* Unknown users or subusers
* Unrecognized API credentials
* Unexpected billing or account activity
* Changed email address or account information

If you find anything suspicious, do not ignore it.

### Secure Your Servers

If the compromised account has access to active servers

* Change important server credentials.
* Review server users and permissions.
* Check for unfamiliar files or modifications.
* Review startup commands and environment variables.
* Rotate API keys or credentials that may have been exposed.
* Review recent server activity and console logs.

If you suspect a server itself has been compromised, consider taking it offline until it can be properly investigated.

### Contact NexCloud Support

If you believe someone has gained unauthorized access to your NexCloud account, contact **NexCloud Support** as soon as possible.

Include

* Your account email address
* When you first noticed the issue
* What unauthorized activity you observed
* Any suspicious servers, users, or changes
* Screenshots or other relevant information

**Never send your account password, 2FA codes, API tokens, or other private credentials to anyone, including support staff.**

### Important

NexCloud Support will never require you to provide your password or 2FA verification code.

If you still have access to your account, **change your password and enable 2FA before doing anything else.**
