What to Do If You Suspect Unauthorized Account Access
A login you don't recognize, a sign request you didn't send, an email about activity that wasn't you — act fast and in this order. Speed matters more than certainty; you can investigate after you've locked the door.
The First Five Minutes
1. Change your password — Settings → Security. This invalidates the attacker's session.
2. Enable 2FA if it wasn't already on. This blocks re-entry even if they still have the old password.
The Next Fifteen Minutes
3. Review your login history in Settings → Security — note unfamiliar devices, times, and locations.
4. Audit recent requests. Check your Sign Request list for anything you didn't create; open the audit trails of recent documents for actions that weren't yours.
5. Void anything suspicious. A fraudulent request that hasn't completed can be voided so it never becomes binding — do this before anything else spreads.
Then Tell Us
6. Contact support from your registered email with the subject "Suspected unauthorized access". Include what you found and when. We'll review server-side logs, and can take additional protective action on the account.
Note: If your email account itself may be compromised, secure it first — whoever controls your inbox can reset almost anything.