Recover now
Something is broken right now.
Find the closest match below and go straight to the first fifteen minutes. If nothing fits exactly, pick the nearest one; the opening steps are similar across most incidents.
Before you do anything else
- Write down the time. Nearly every decision later depends on knowing when this started, and memory gets unreliable fast under stress.
- Stop changing things. Do not delete, tidy up, reinstall, or factory reset. Those actions frequently destroy the only evidence of what happened.
- Tell one other person. Working alone is how people make the expensive decision. You want someone who can ask whether you are sure.
- Do not pay, reply, or confront anyone. If a person caused this, your urgency is the thing they are counting on.
Most severe first
Find your situation
61 playbooks
App removed from an app storeA mobile app or developer account is rejected, removed, or suspended, blocking new installs, updates, billing, or discovery.Backups will not restoreBackups exist, but they are missing, corrupt, incomplete, encrypted, incompatible, or too slow to use.Business email compromisedAn attacker may read mail, reset other accounts, impersonate the business, or redirect payments.Cloud account compromisedAn attacker may control cloud identities, infrastructure, data, logs, or the account's billing and recovery settings.Cloud region outageA cloud region or availability zone hosting critical workloads becomes unavailable or severely degraded.Critical vendor shuts downA provider announces closure, ends your product, terminates service, or gives a short migration deadline.Customer accounts under credential-stuffing attackAutomated attackers are testing stolen username and password pairs against customer accounts.Customer receives another customer's dataAn export, report, attachment, or support response exposes one customer's information to another.Customers charged twiceA retry, webhook, race condition, import, or operator action creates duplicate customer charges.Database migration fails mid-releaseA schema or data migration partially applies, blocks traffic, corrupts records, or leaves old and new code incompatible.DDoS attack overwhelms the serviceMalicious traffic exhausts bandwidth, connections, compute, or expensive application operations.DNS change takes the business offlineIncorrect nameservers or DNS records make the website, API, email, or verification services unreachable.Domain expired or lostYour domain no longer resolves, has left your registrar account, or is registered to someone else.Encryption key lost or unusableEncrypted customer data, backups, or infrastructure cannot be decrypted because the required key is missing or inaccessible.Former team member still has accessSomeone who no longer works with the business can still reach accounts, code, data, devices, or customer systems.GitHub organization compromisedAn attacker may control an owner account, repositories, Actions, apps, or credentials connected to your GitHub organization.Package registry account compromisedAn attacker may be able to publish malicious versions of packages your customers or systems install.Password manager locked outThe vault containing business passwords, recovery codes, and secure notes is unavailable or cannot be unlocked.Payment webhooks stop processingPayment events are delayed, rejected, or ignored, leaving orders, subscriptions, and access out of sync.Personal email account hackedPersonalSomeone else is in your email, which means they can reset the password on almost everything else you own.Phone number stolen in a SIM swapPersonalYour phone suddenly loses service because someone moved your number to another SIM or mobile provider.Private data appears in a public repositoryCustomer information, credentials, internal documents, or private source code were pushed to a public repository.Private storage bucket becomes publicFiles intended for restricted access can be listed or downloaded without proper authorization.Production API key leakedA credential that can read data, spend money, send messages, or control production has been exposed.Production data deletedRecords, files, tables, or an entire production database were deleted or overwritten.Production database corruptedProduction records still exist but values, relationships, indexes, or internal storage are no longer trustworthy.Ransomware or destructive malwareSystems or data are encrypted, stolen, deleted, or held for payment by a malicious actor.Scammed or fraudulent bank chargePersonalMoney left your account that you did not authorise, or you were talked into sending it and have just realised.Sensitive data appears in logsPasswords, tokens, payment details, personal data, or private content are being recorded in application or vendor logs.Software dependency compromisedA library, container, plugin, action, SDK, or build dependency may contain malicious or unauthorized code.Stripe payouts frozenStripe is still collecting money, but payouts are delayed, paused, failed, or restricted.Sudden wave of chargebacksDisputes rise sharply because of fraud, customer confusion, service failure, or an organized abuse campaign.Unexpected cloud billCloud, AI, storage, bandwidth, or API spending rises far beyond the expected amount.Website hackedAn attacker may have altered your site, stolen data, installed persistence, or gained access to connected systems.Background jobs stop processingQueued emails, imports, billing actions, webhooks, or other asynchronous work is delayed or frozen.CI/CD provider outage blocks releasesBuilds, tests, package publishing, or deployments cannot run through the normal automation provider.Cloud quota exhaustedA provider limit prevents new requests, instances, storage, messages, builds, or other critical resources.Cloud sync deletes files everywherePersonalA deletion, bad edit, or damaged folder is copied across every device connected to your cloud storage.Contractor disappearsA contractor becomes unreachable while retaining access, knowledge, devices, code, data, or ownership of critical services.Critical SaaS provider outageA provider your product or operations depend on is unavailable, degraded, or losing data.Critical scheduled job silently stopsA cron task or scheduler no longer runs backups, renewals, reports, cleanup, billing, or synchronization.Database connections exhaustedThe application cannot obtain database connections, causing requests, jobs, and administrative access to stall.Founder unavailable for two weeksThe only person with critical authority, access, or knowledge cannot work or communicate.Home router or Wi-Fi hackedPersonalSomeone may control the router that connects every phone, computer, camera, and smart device in your home.Laptop lost or stolenA work laptop containing sessions, source code, customer data, or recovery credentials is missing.Launch produces 20× expected trafficA launch, mention, campaign, or attack sends far more legitimate traffic than the system was designed to handle.Locked out of your Google or Apple accountPersonalNobody attacked you. You simply cannot get back into the account that holds your photos, your email, and your two-factor codes.MFA device lost or brokenThe phone or security key used to approve critical logins is unavailable, damaged, or stolen.Monitoring and alerts go blindLogs, metrics, traces, uptime checks, or alerts stop reporting while production continues to run.Newsletter provider closes the accountYour newsletter account is suspended, disabled, terminated, or inaccessible before an important send.Phone lost or stolenPersonalYour phone is gone, and it is signed in to your email, your bank, your messages, and the codes that protect everything else.Photos and files lost with no backupPersonalThe drive died, the phone went in the water, or the folder is simply gone, and there was never a copy.Production deploy breaks the siteA release causes errors, missing pages, failed checkouts, corrupt writes, or unexpected customer behavior.Social media account hackedPersonalSomeone took over your Instagram, Facebook, X, or TikTok and is posting, messaging your friends, or holding it for ransom.Team member leaves without a handoverA key person departs before transferring ownership, context, credentials, work, or recurring responsibilities.Transactional email stops arrivingLogin links, receipts, alerts, invitations, and account messages are rejected, delayed, or sent to spam.Vendor API changes without warningA third-party API changes behavior, authentication, fields, limits, or versions and breaks a critical workflow.Wrong feature flag enabled in productionA hidden, unfinished, risky, or destructive code path is activated for the wrong customers or environment.Computer will not start after an updatePersonalA Windows or macOS update leaves the computer stuck, restarting, or unable to reach the desktop.Home internet stops workingPersonalYour home connection fails when you need it for work, school, payments, or communication.TLS certificate expiredBrowsers or API clients reject your site because its HTTPS certificate is expired, invalid, or issued for the wrong name.
Nothing matches that. Try a plainer word, like “password”, “money”, or “gone”.