নিজে request না-করা password reset email এলে প্রথম reaction ভয় হতে পারে। কিন্তু message-এর button চাপলে আসল service-এর বদলে phishing page-এ পৌঁছতে পারেন। প্রতিটি reset mail account takeover প্রমাণ নয়—কেউ ভুল email লিখেছে বা legitimate notification এসেছে। Mail থেকে action না নিয়ে trusted path দিয়ে account state দেখুন। Sender, recent sign-in, recovery detail এবং other alerts মিলিয়ে evidence অনুযায়ী সিদ্ধান্ত নিন। Panic করে একই password বহু account-এ বদলানো বা unknown support number-এ call করা risk বাড়ায়।

Email-এর link, button ও phone number ব্যবহার করবেন না

নিজে reset request না করলে message-এর “Secure account”, “Cancel” বা “Reset now” button খুলবেন না। Displayed sender name trusted দেখালেও address spoof বা lookalike domain হতে পারে। Attachment download, QR scan এবং reply এড়ান। Saved mobile app, password manager bookmark বা browser-এ নিজে লেখা official domain দিয়ে service খুলুন। Google-এর official password assistance guidance বলে unrequested Google reset mail অনেক সময় অন্য user ভুল address দিলে আসে এবং শুধু ওই mail account compromise করে না। অন্য service-এর rule তার official help থেকে যাচাই করুন।

Message details evidence হিসেবে দেখুন, verdict নয়

Subject, sender domain, recipient address, time এবং wording note করুন। Spelling error, urgent deadline, mismatched brand, generic greeting বা unexpected attachment phishing signal হতে পারে, কিন্তু polished design legitimacy guarantee নয়। Mail app-এর security details available হলে authentication result দেখুন; technical header বুঝতে না পারলে organization IT team-কে original message report করুন। Forward করলে header হারাতে পারে, তাই approved reporting button ব্যবহার করুন। Unrequested reset mail password বদলের proof নয়, কিন্তু account interest-এর warning হতে পারে। একই সময়ে sign-in alert বা recovery change এসেছে কি না গুরুত্ব বেশি।

Official account activity ও active sessions review করুন

Trusted device থেকে account security page খুলে recent login, device list, session location এবং security events দেখুন। Location approximate হতে পারে এবং mobile network বা VPN ভুল city দেখাতে পারে; device, time ও activity মিলিয়ে সিদ্ধান্ত নিন। Unknown session থাকলে official sign-out control ব্যবহার করুন। Inbox rule, forwarding, recovery phone, recovery email এবং connected apps বদলেছে কি না দেখুন। Security page clean হলে screenshot বা date note করা useful, কিন্তু reset mail-এর link safe বলে ধরে নেবেন না। Account service unavailable হলে mail-এর alternative phone number নয়, manually found official support route নিন।

Password বদলানোর trigger evidence দিয়ে ঠিক করুন

শুধু genuine-looking reset email পেলে সবসময় password change দরকার নাও হতে পারে। কিন্তু unknown successful sign-in, changed recovery detail, reused password, credential breach notice বা আপনার করা নয় এমন account action থাকলে trusted device থেকে password বদলান। প্রত্যেক account-এর জন্য unique, long password password manager-এ রাখুন। Suspected malware থাকলে clean device ব্যবহার করে critical account আগে secure করুন। পুরোনো password-এর ছোট variation দেবেন না। Password change-এর পরে other sessions invalidate হয়েছে কি না দেখুন এবং saved devices পুনরায় authenticate করুন। Evidence না থাকলেও weak বা reused password উন্নত করা sensible maintenance।

MFA, passkey ও recovery methods শক্ত করুন

Available হলে phishing-resistant passkey বা security key বিবেচনা করুন; authenticator app SMS-এর চেয়ে অনেক ক্ষেত্রে stronger হতে পারে, তবে recovery plan দরকার। MFA on আছে শুধু দেখে থামবেন না—registered phones, backup codes, trusted devices এবং recovery email current কি না যাচাই করুন। Unknown method remove করার আগে নিজের access lockout হবে না তা নিশ্চিত করুন। Backup code screenshot normal photo gallery বা shared Drive-এ রাখবেন না। Recovery contact-কে social engineering target হতে পারে, তাই identity verification rule বোঝান। Service-এর supported options এবং organization policy অনুসরণ করুন; কোনো method absolute guarantee নয়।

Email account আগে secure করুন

Reset mail যে inbox-এ এসেছে সেটি অন্য account recovery-এর master key হতে পারে। তাই email account-এর password uniqueness, active sessions, forwarding filters, delegated access এবং recovery settings review করুন। Unknown mail rule reset notifications লুকাতে পারে। SIM-swap concern থাকলে mobile carrier-এর official channel ও account PIN controls দেখুন। Password manager account compromise হলে vault security ও emergency access review করুন। Multiple reset mails কোন services-এ এসেছে timeline বানান; একই credential reused হলে priority বোঝা যাবে। Message delete করার আগে phishing report বা incident evidence প্রয়োজন কি না organization policy অনুযায়ী ঠিক করুন।

Unrequested reset email checklist

  • Pause: Email link, QR, attachment ও phone number ব্যবহার হয়নি।
  • Path: Saved app বা manually typed official domain খোলা হয়েছে।
  • Activity: Recent logins, devices ও security events reviewed।
  • Recovery: Phone, email, MFA methods ও connected apps verified।
  • Password: Compromise evidence হলে clean device থেকে unique value set।
  • Inbox: Forwarding, filters ও delegated access checked।
  • Report: Suspicious mail official reporting flow-তে পাঠানো হয়েছে।

Outcome লিখে monitor করুন, ভয় ছড়াবেন না

Review শেষে তিনটি outcome-এর একটি record করুন: likely mistaken request with no other alert, suspicious phishing message, অথবা confirmed unauthorized activity। প্রথম ক্ষেত্রে mail ignore/report করে account monitoring চালিয়ে যান। দ্বিতীয় ক্ষেত্রে link না খুলে phishing report করুন। তৃতীয় ক্ষেত্রে password, sessions, recovery methods এবং affected transactions incident plan অনুযায়ী secure করুন; financial loss হলে provider ও relevant authority-এর official route ব্যবহার করুন। Family বা team-কে “কে reset করেছিল?” জিজ্ঞাসা করাও useful। Evidence ছাড়া “hacked” ঘোষণা করবেন না, আবার warning dismiss-ও করবেন না। Calm, trusted-path verification account এবং decision দুটোই নিরাপদ রাখে।