“Look Who Died in an Accident” Message: What to Do

Got a “look who died in an accident” message? Learn what to do if you received it, clicked a link, entered a password, or lost account access.

A message saying “look who died in an accident” can make you tap before you have time to think. If it includes an unexpected link, pause. Do not use the link to find out whether the story is true, and do not enter a password or verification code on the page it opens. Check with the supposed sender through a contact method you already know.

What you should do next depends on what happened: did you only receive the message, open the link, enter information, or notice someone using your account? Those situations carry different risks. A suspicious message is a reason to check, not proof that your account has been hacked.

Why this message deserves caution

The frightening wording is a lure. It may appear to come from a friend, an unfamiliar account, or a forwarded conversation. A familiar name does not verify the message: the person may have forwarded a bad link, lost control of an account, or had their identity imitated. Equally, the wording alone cannot establish that any particular sender was hacked. Verify independently before trusting the link.

The destination may ask for a TikTok or Facebook login, a one-time code, contact information, or a download. Treat a login prompt reached from a surprising message as untrusted. TikTok's phishing guidance says it will not contact you to request your password or verification codes. A page that looks like a familiar social app can still be a copy. Open the real app yourself or type its known address instead of following the message back to a login screen.

This article describes a message pattern, not a verified current wave of attacks. The text, platform, sender, and destination can vary. Focus on what the message asks you to do and what you actually did, rather than on an assumed campaign name.

Leave the link alone. If you are concerned that the named person may really be in trouble, contact someone you trust through a separate channel. Start a new conversation from a saved contact or speak to the person directly; do not use a number or account suggested by the suspicious page. You can ask the sender whether they meant to send the message without repeating its link to other people.

Report the message in the app where it arrived. TikTok's reporting instructions describe opening the chat from Inbox, pressing and holding the message or opening chat options, and choosing Report. Facebook's Messaging Help says you can report or block messages that look like spam. Names and menu positions may differ across app versions, so use the reporting option visible in your own conversation.

You do not need to change every password merely because a message arrived. If you have other signs of compromise, such as a login alert you do not recognize or messages you did not send, use the account steps below. Avoid forwarding the suspicious URL as a warning; describe the lure without spreading its clickable link.

Close the page. Do not press its back-to-login, continue, or “verify” controls. Opening a link is different from giving it your password, and it does not by itself prove that someone entered your account. It also does not prove the device is safe; what the page did, and whether anything was downloaded or installed, matters.

Think through the interaction once, calmly. Did you type a username, password, one-time code, phone number, or payment detail? Did you approve a login prompt? Did the page ask you to install an app, browser extension, or file? If the answer is no, check your account's ordinary security alerts and recent activity through the real app, especially if the destination looked like a login page. If something downloaded or installed, follow current security instructions from your phone, computer, or browser vendor; that is a device issue as well as a possible account issue. The FTC recommends updating security software and scanning when a phishing link may have downloaded harmful software. Do not run an unfamiliar “cleanup” download offered by the suspicious page.

If the link opened a real-looking TikTok or Facebook page, still avoid returning through that message. Use your existing app icon or a known bookmark to reach account settings. A familiar logo, profile picture, or sender name is not enough to authenticate the site you visited.

If you entered a password, code, or other sensitive information

Act from the official app or a known address, not the suspicious page. Change the password for the account whose details you entered to a new, unique one. If you reused that password anywhere else, change it on those accounts too. If you entered a one-time verification code or approved a login request, review account activity and devices promptly; a code may let someone complete a login even when a password alone would not.

For TikTok, go to your profile, open Settings and privacy, then Security & permissions to find Security checkup, device management, and security alerts where available. TikTok's account-safety guide says to remove a device you do not recognize and change your password. Turn on two-step verification, and check that the email address and phone number linked to the account are still yours. TikTok says changing your password signs other logged-in devices out; still inspect the account for changes rather than assuming that one action resolves everything.

For Facebook, use its account settings or Security Checkup to update the password, review logged-in devices and login alerts, and enable two-factor authentication. Meta describes those controls in its current security and support update. If you entered payment-card information, contact the card issuer through the number on the card or its known app, and explain what you entered. Do not rely on a phone number supplied by the suspicious message.

No password change can undo information already disclosed to a third party. It can, however, replace a credential that may be known to someone else. Continue checking for unauthorized changes and use the platform's recovery flow if access has changed.

If the account changed or you cannot sign in

Unexpected messages sent from your account, unfamiliar devices, changed contact details, and posts you did not make are stronger signs that someone may have accessed it. Start recovery from the platform itself. TikTok's phishing guidance asks people who believe an account was compromised to report it. Its account-safety guide describes in-app recovery options when a password reset is not possible. Follow the options shown for your account; eligibility and screens may vary.

If the affected account is Facebook, go directly to facebook.com/hacked or find the recovery flow inside Facebook. Facebook's hacked-account Help recommends using a device you have previously used for Facebook. If the email account associated with a social account may also be compromised, secure that mailbox through its own provider; access to recovery email can affect later resets. Keep recovery messages and one-time codes private, including from anyone claiming to be a friend helping you.

Once you regain access, review the account's contact methods, active devices, recent messages, and posts. Remove access you do not recognize through the platform's controls and report messages sent without your permission. Tell affected contacts through a separate trusted channel that the earlier link was suspicious. You cannot assume that all recipients saw your warning or that a platform will remove every forwarded copy, so keep the warning plain and avoid promising an immediate cleanup.

A safer way to check future alarming messages

Pause at the point where a message moves you away from the conversation. Ask whether the sender would normally communicate this way and whether the link's destination is necessary to answer the question. Verify serious news with the person or a trusted contact independently. Never use an emotional message as the route to an account login or a code request.

Use unique passwords and two-step verification for important accounts. TikTok and Meta both provide account security controls, but no setting can guarantee that you will never receive a deceptive message. The useful habit is to recognize the difference between seeing a message, opening a page, handing over account information, and losing access-then respond to the action that actually occurred.