A computer hack is when someone gains unauthorized access to a device, network, or account by exploiting a weakness in security

A hack is an unauthorized entry into a computer, phone, email account, or network. The person doing it—called a hacker—finds a way past the security measures you have in place. They might steal passwords, install malicious software, trick you into revealing information, or exploit a flaw in the software itself. The goal varies: some hackers want your financial information, others want to steal your identity, and some straightforward want to disrupt your system or prove they can break in.

Hacking is not always a crime in the legal sense. Security researchers sometimes hack into systems with permission to find weaknesses before criminals do. But unauthorized hacking—breaking into a system you do not own or have permission to access—is illegal in most countries, including the United States under the Computer Fraud and Abuse Act.

Key Takeaways

  • A hack occurs when someone bypasses security to access a device, account, or network without permission, usually to steal data or cause disruption.
  • Common hacking methods include phishing emails, weak passwords, unpatched software, malware, and social engineering rather than complex technical wizardry.
  • You can reduce your risk by using strong unique passwords, enabling two-factor authentication, keeping software updated, and being cautious about what you click.
  • If you suspect your account has been hacked, change your password when ready, enable two-factor authentication, and monitor financial accounts for unauthorized activity.

The most common ways hackers gain access

Most hacks do not involve sophisticated code or deep technical knowledge. Hackers succeed because they exploit human behavior and outdated systems. Phishing is the most widespread method: a hacker sends an email that looks like it comes from your bank, email provider, or a service you use. The email asks you to click a link and log in, and when you do, the hacker captures your credentials. You have handed over the key yourself.

Weak or reused passwords are another major entry point. If your password is "password123" or the same one you use on five different sites, a hacker who cracks one account can access the others. Malware—malicious software installed on your device—can log your keystrokes, steal files, or give a hacker remote control of your computer. You might read it unknowingly from a compromised website or email attachment.

Unpatched software is a vulnerability hackers actively hunt for. When a software company discovers a security flaw, they release a patch or update to fix it. If you ignore those updates, you leave the door open. Hackers also use social engineering—manipulating you into revealing sensitive information by pretending to be someone trustworthy, like an IT support person or a coworker.

What happens after a successful hack

The consequences depend on what the hacker wanted. If they accessed your email, they can reset passwords on other accounts tied to that email address—your bank, social media, shopping sites. They can read your messages, find personal information, and impersonate you. If they stole financial information, they might open credit cards in your name or make unauthorized purchases.

Some hackers install ransomware, which encrypts your files and demands payment to unlock them. Others install spyware that watches your activity over time. Some breaches are silent: a hacker might steal your data and sell it on the dark web without you knowing for months. Large-scale hacks of companies can expose millions of people's information at once, and you may not learn about it until the company announces the breach publicly.

The difference between hacking and other security breaches

A data breach is when information is stolen or exposed, but it does not always involve hacking. A company employee might accidentally email sensitive data to the wrong person, or a server might be left unsecured without a password. A breach can result from hacking, but it can also result from negligence or misconfiguration.

Phishing and hacking are related but not identical. Phishing is a method hackers use to trick you into giving them access. Once you click the link and enter your password, the hacking begins. A brute-force attack is when a hacker uses software to try thousands of password combinations until one works. Man-in-the-middle attacks intercept your communication on an unsecured network—like public Wi-Fi—to steal data as it travels between your device and a website.

How to reduce your risk of being hacked

Use a strong, unique password for every important account. A strong password is at least 12 characters long and includes uppercase letters, lowercase letters, numbers, and symbols. A password manager like Bitwarden, 1Password, or KeePass can generate and store these for you so you do not have to remember them. Never reuse passwords across sites.

Enable two-factor authentication (2FA) on accounts that offer it, especially email and financial accounts. Two-factor authentication requires a second form of verification—usually a code from an app like Google Authenticator or a text message—even if someone has your password. This stops most hackers cold because they do not have access to your phone.

Keep your operating system, browser, and software updated. When you see an update notification, install it promptly rather than dismissing it. Be skeptical of emails asking you to log in or verify information, especially if they create urgency. Legitimate companies rarely ask you to click a link in an email to log in; instead, go directly to the website by typing the address yourself. Avoid public Wi-Fi for sensitive transactions like banking, or use a VPN (virtual private network) if you must.

What to do if you think you have been hacked

Act quickly. Change your password when ready—use a device that is not the one you suspect was compromised, or use a different network. Make the new password strong and unique. Enable two-factor authentication on that account if it is not already on.

Check your email recovery options and phone number associated with the account. If a hacker changed them, change them back. Review your account activity and connected apps or devices. Most email and social media platforms show you where and when your account was accessed; if you see logins from places you do not recognize, that is a sign of compromise.

Monitor your financial accounts and credit reports for unauthorized activity. You can check your credit report free once a year at AnnualCreditReport.com. If you see fraudulent charges, contact your bank or credit card company when ready. Consider placing a fraud alert or credit freeze with the credit bureaus (Equifax, Experian, and TransUnion) to prevent someone from opening accounts in your name.

When to involve law enforcement or a professional

If a hacker stole money from you or opened accounts in your name, file a report with the Federal Trade Commission at IdentityTheft.gov. This creates an official record and gives you a recovery plan. You can also file a police report, though local police may not investigate unless the amount is substantial.

If your computer is infected with malware and you cannot remove it yourself, take it to a local repair shop or use remote support from a reputable company. Be cautious about who you trust with your device; verify the business is legitimate before handing over your computer. If a business you use was hacked and your information was exposed, the company should notify you; follow their instructions for monitoring your accounts.

Frequently Asked Questions

Can hackers see me through my webcam?

Yes, if malware is installed on your device or if your webcam software has an unpatched vulnerability. This is rare but possible. Covering your webcam with tape or a physical shutter costs nothing and eliminates the risk. Keeping your software updated and avoiding suspicious downloads reduces the likelihood of malware infection.

Is it safe to use public Wi-Fi?

Public Wi-Fi is not encrypted, so hackers on the same network can intercept your data. Avoid logging into financial accounts or entering passwords on public Wi-Fi. If you must use it, connect through a VPN, which encrypts your traffic. Many VPN services cost a few dollars per month.

What is the dark web and why do hackers use it?

The dark web is a part of the internet that requires special software to access and offers anonymity. Hackers use it to sell stolen data, buy hacking tools, and communicate without being traced. You do not need to access it; understanding it exists is enough to know why your stolen information might end up there.

If I use a password manager, is that a security risk?

A reputable password manager is more find than reusing weak passwords. Password managers encrypt your passwords and require a master password to access them. The risk of a hacker breaking into the password manager itself is lower than the risk of a hacker cracking your weak password or accessing one of your accounts when you reuse passwords.

How do I know if a website is safe to enter my information on?

Look for "https://" at the start of the web address and a padlock icon in your browser's address bar. The "s" means the connection is encrypted. However, encryption alone does not may provide the website is legitimate; a phishing site can also use https. Type the address yourself rather than clicking a link in an email, and verify you are on the real website before entering sensitive information.