Yes — you can turn on login alerts for your important accounts in under fifteen minutes: Google, Apple, and Microsoft notify you by default of new-device sign-ins (verify the setting is on, not assume it), banks and social platforms have equivalent toggles, and a few minutes of configuration buys you the earliest possible warning of an account takeover. The alerts arrive when someone signs in from a new device, browser, or unusual location — and since email is the master key that resets everything else, your email accounts come first.
Why alerts matter even with a strong password
Because passwords leak without your involvement — from vendor breaches, infostealer malware, and phishing — and two-factor authentication, while essential, has gaps: fatigue prompts get approved by accident, SMS codes get SIM-swapped, and some services quietly fall back to weaker methods. An alert is the tripwire layer: it cannot stop the login, but it tells you within seconds that a recovery race has started, and speed decides whether you lock the intruder out or they lock you out. The standard advice from CISA and incident responders alike: when an alert fires for a login that was not yours, act immediately — change the password, revoke sessions, check recovery settings.
Google accounts
- Go to myaccount.google.com > Security.
- Confirm 2-Step Verification is on — the critical layer.
- Under Recent security activity, review current events; Google emails and pushes notifications for new-device sign-ins by default — make sure notifications are enabled in the Google app if you want phone pushes.
- Under Your devices, remove anything you do not recognize.
Apple ID
- On iPhone: Settings > your name > Sign-In & Security.
- Verify two-factor authentication is on (it is forced on modern Apple IDs).
- Check Devices in the same menu — every device signed into your Apple ID appears here; sign out anything unfamiliar.
- Apple pushes notifications to trusted devices for new sign-ins and password changes by default — keep notifications for the Apple ID system alerts enabled in Settings > Notifications.
Microsoft accounts
- At account.microsoft.com > Security, review sign-in activity and turn on two-step verification.
- Microsoft emails unusual sign-in activity by default; in the Security settings, confirm notification contacts are current — a stale recovery email defeats the whole system.
- Sweep Sign-in activity for unfamiliar locations and sessions.
Banks, social, and everything else
Financial and social platforms scatter the setting, so search each app or site for "alerts," "notifications," or "login alerts": most banks offer email and push for new-device logins and transactions (enable both — transaction alerts are the higher-value pair); Facebook has Login Alerts under Settings > Security; X, Instagram, and LinkedIn have equivalent login-alert toggles; Amazon notifies on new-device sign-ins. Any service that offers login alerts and does not have them on is a small hole worth five minutes to close. And every service should be swept once for recovery settings — an attacker's email planted as your recovery contact is the classic persistence move after any partial takeover.
What to do when an alert fires
- Judge quickly: was it you — the new phone, the browser you just installed, the VPN exit city? Then no action needed.
- If it was not you: change that account's password immediately from a device you trust, then revoke all active sessions (Google: Security > Your devices; Apple: remove the device; Microsoft: Sign out everywhere).
- Check recovery details — email, phone, backup codes — for anything the intruder changed.
- Follow the blast radius: if the account was your email, assume every account it can reset is at risk; check those next, in order of value.
- Report significant takeovers to the FBI's IC3 and, for financial accounts, to the institution's fraud line immediately.
One habit to keep the system alive
Alerts only work if they reach you: keep recovery emails and phone numbers current (a stale number silently redirects warnings into nowhere), and once a year — alongside your other security maintenance — re-open each account's security page to confirm devices, sessions, and recovery settings look like yours. The fifteen minutes of setup plus the annual sweep is the difference between catching an intrusion at the first login and discovering it at the password-reset screen of your own account.
For more context, read The monthly personal security checklist: 20 minutes, first Saturday.
For more context, read authenticator app setup.
For more context, read online shopping safety.

