Respond to suspicious account activity
Secure your Estavo account after an unfamiliar sign-in, profile change, passkey, email update or unexpected property, document or financial activity.
Suspicious activity can include unfamiliar sessions, unexpected password-reset emails, a new passkey, an account email change or records being added, edited, downloaded or deleted without your knowledge. Treat unexplained access as a security incident until it has been reviewed.
Signs that your account may require immediate review
Potential account-security indicators
Review each sign together with recent account activity.
Take immediate action
Use a trusted device
Move to a device and network you control before changing security settings.
End unfamiliar sessions
Remove active access from devices or browsers you do not recognise.
Secure sign-in methods
Change the password and review passkeys and connected Google access.
Review recent account changes
Check profile, property, tenant, document, Marketplace and financial activity.
Revoke unexplained access first. You can review the cause and affected records after the account is secured.
Open Estavo directly
- Open the normal Estavo website or application directly.
- Do not rely on an unexpected email or message link.
- Check the page address before entering credentials.
- Use a trusted browser profile.
- Cancel any sign-in prompt you did not initiate.
- Do not approve unexpected passkey or Google prompts.
End unfamiliar or unnecessary sessions
- Open Account & Security.
- Select Active Sessions or Devices.
- Identify the current trusted session.
- End sessions you do not recognise.
- End sessions from old, shared or replaced devices.
- Use End All Other Sessions where available.
- Refresh the session list.
- Investigate sessions that return after being ended.
Change or reset the password
You still know the password
Change it from Account & Security using a new, unique password.
The password may have changed
Use the password-reset process from the Estavo sign-in page.
The password was reused elsewhere
Change it on those other services as well, particularly the connected email account.
Browser autofill still uses the old value
Update or remove the obsolete saved password from trusted browsers and password managers.
Review every registered passkey
- Open the Passkeys section.
- Review every label and associated device.
- Remove unfamiliar passkeys.
- Remove passkeys from lost or replaced devices.
- Keep only devices and providers you control.
- Add a new trusted passkey after securing the account where appropriate.
- Maintain another valid recovery method.
Changing the password may not automatically remove passkeys already registered to the account.
Review Google sign-in
- Confirm the connected Google email.
- Check whether it belongs to you.
- Review recent Google security activity.
- End unfamiliar Google sessions.
- Change the Google password if exposure is possible.
- Disconnect Google sign-in only after confirming another Estavo sign-in method.
- Contact support if Google opens the wrong Estavo account.
Review the Estavo account email
- Confirm the displayed email is correct.
- Review any pending email-change request.
- Cancel an unauthorised pending change where available.
- Check security messages sent to the previous address.
- Correct the account email after securing access.
- Contact support if the address changed and you can no longer access the account.
Secure the connected email account
- Change the email-account password.
- Use a unique password.
- Review active email sessions and devices.
- Check recovery email and telephone details.
- Review forwarding rules and filters.
- Check deleted and sent messages.
- Review whether Estavo security messages were removed.
- Do not share email authentication codes.
Someone who controls the account inbox may be able to receive password-reset and security messages.
Review profile and account-setting changes
- Check your name and telephone number.
- Review business or landlord details.
- Check the account email.
- Review sign-in methods.
- Check communication preferences where available.
- Correct only information you can confirm.
- Record unfamiliar changes before correcting them.
Review recent activity within Estavo
References, timestamps and screenshots can help support review the incident. Remove unnecessary personal information from screenshots.
Review Marketplace and payment activity
- Review recent Marketplace orders.
- Check tenant checks and property-service orders.
- Review SMS-pack purchases.
- Check storage upgrades.
- Review payment references and amounts.
- Check whether services were activated.
- Do not retry or cancel unfamiliar orders before reviewing their status.
- Contact support with order references where required.
Preserve useful details for review
- Record the date and time the issue was noticed.
- Record unfamiliar session details.
- Note the browser, device and approximate location.
- Record changed account fields.
- Keep relevant order, document or transaction references.
- Capture non-sensitive error or notification text.
- Record the actions taken to secure the account.
- Do not include passwords or authentication codes.
Contact Estavo support safely
- Your account email.
- Your name.
- The approximate time the activity occurred.
- The unfamiliar session or device details.
- The account fields or records affected.
- Relevant order, document or transaction references.
- Whether sessions were ended.
- Whether the password was changed.
- Whether the connected email account was secured.
Do not provide passwords, passkeys, authentication codes, password-reset links, Google credentials or full payment-card details.
Confirm the account is secure again
Review active sessions again
Confirm only recognised devices remain.
Test the intended sign-in methods
Confirm the new password, trusted passkey or connected Google account works.
Review corrected account details
Confirm the account email and profile information are accurate.
Continue monitoring recent activity
Review the account again if unfamiliar changes or sessions return.
Reduce the risk of another account incident
- Use unique passwords.
- Use passkeys only on trusted devices.
- Protect the connected Google and email accounts.
- Review active sessions regularly.
- Sign out of shared devices.
- Do not share account credentials.
- Use individual Estavo accounts for authorised users.
- Review unexpected security messages immediately.
- Keep profile and recovery information current.
Common suspicious-activity problems
You cannot sign in
Use password recovery, a trusted passkey or connected Google sign-in, then contact support.
The account email changed
Secure the connected inbox and contact support using the previous account email.
An unfamiliar session returns
Review passwords, passkeys and Google sign-in because the device may be signing in again.
An unknown passkey cannot be removed
Secure other sign-in methods and contact support with the passkey label and device details.
Records were deleted or changed
Record the affected references and contact support before recreating large amounts of data.
An unfamiliar payment appears
Review Marketplace orders and payment references and avoid duplicate actions.
No single event explains the issue
Secure every sign-in method and provide the complete timeline to support.
Suspicious activity continues
Stop normal account use, secure the connected email and Google accounts and contact support again.
The account-security incident has been reviewed
The next guide explains how to review your records, active services and data requirements before requesting closure of your Estavo account.
Continue to account closure