Give this login its own password
Choose a long password that you have not used for another service. Predictable substitutions in a familiar word are less useful than something a password manager can generate and remember for you.
Where an additional verification option exists, review how it works before enabling it. Put any recovery codes somewhere secure away from the device they protect, so losing the phone does not remove every way back in.
Check who can reach the recovery inbox
Confirm that the account email and phone number are still under your control. Replace obsolete contact information while you can still receive the confirmation needed to approve the change.
Then inspect the email account itself. Unfamiliar sessions or forwarding rules deserve attention, particularly after an unexpected reset notice. A separate email password prevents exposure of one service from immediately affecting the other.
Slow down an urgent message
Threats of immediate closure and surprise rewards often try to hurry a decision. Leave the message and enter XX6 through an address you already trust. Check whether the same notice appears inside the account.
Do not forward a reset link or login code to somebody claiming to help. If the conversation requires a secret credential, end it and contact support through the route you opened yourself.
Review changes that you did not make
Occasionally inspect device sessions, recent profile edits, and account activity. Browser names can be unfamiliar even when the session is yours, so compare the time and device before drawing a conclusion.
If you cannot account for an entry, preserve its details, secure the linked inbox, replace the XX6 password, and revoke unfamiliar sessions where possible. Report what you found through the established support channel.