Almost every lockout has a self-service fix. Here they are, from most to least common.
Forgotten password
Use the Forgot password? link on the sign-in page. We email a 6-digit code to your account address (it expires after 10 minutes) and you choose a new password. Every signed-in device is then signed out, including any you don’t recognise. Your two-factor authentication is untouched and still applies at the next sign-in.
“Account locked” message
Five wrong password attempts lock the account for 15 minutes as a protection against guessing. It unlocks itself. If you’re not sure of the password, use Forgot password? rather than more guesses.
Note: If you see this message without having tried to sign in, someone else may be guessing your password: reset it and let us know.
Lost or replaced phone (authenticator app)
On the 2FA screen at sign-in, choose Use a backup code and enter one of the one-time codes you saved when you set 2FA up. Once you’re in, go to Settings → Security to set up the authenticator on your new phone and generate fresh backup codes (each code only works once). A passkey on another device, such as your laptop’s fingerprint reader, also gets you in without any codes.
No phone, no backup codes, no other device
Contact support from the email address on your account. Removing two-factor authentication is exactly what an attacker impersonating you would ask for, so we follow a fixed verification procedure first. Expect us to check your request against your account’s sign-in history, and to confirm with you or your firm by phone on a number we already have on record. Please don’t ask us to skip those steps: they are what stops anyone else doing this to your account. Once verified, we clear the old 2FA setup and you set it up fresh at your next sign-in.
What we never ask for
Acquit staff will never ask you for a password, verification code or backup code. Codes and temporary passwords only ever go to the email address on your account. Anyone asking you to read one out is not us.