An old Apple account I no longer use was compromised. The attacker changed the birthday, security questions, password, and associated email address. I received Apple's notification emails before being completely locked out, but I don't know what information or payment methods may still be attached to the account. Is there any realistic way to recover or disable it, or should I focus on protecting my payment methods and other accounts?
4 Answers
The best protection going forward is to use unique passwords and enable two-factor authentication on every important account, especially your primary email and any current Apple account. A trusted phone number or device can make future recovery possible, but it usually cannot override an ownership check on a legacy account after the attacker changes its recovery details.
Contact Apple Support and start the official account-recovery process, but older accounts that were created before two-factor authentication may have very limited recovery options once the security questions and contact email are changed. If Apple cannot verify ownership, the account may not be recoverable.
This can happen with forgotten pre-two-factor accounts, and support representatives may not be able to recover or delete them without sufficient verification. Ask Apple to document the compromise and confirm whether any payment information or active services remain, but be prepared for them to say they cannot restore access.
Treat the account as potentially exposed. Check every card and payment method that might have been associated with it, contact the card issuer if anything looks suspicious, and change any password that was reused there. Also secure the email account that originally received Apple’s notifications.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures