What to Do If Your Email Is Hacked

Affiliate disclosure: Some links on this page are affiliate links. We may earn a commission if you sign up for a service through one of these links. Read our full affiliate disclosure.

If you think somebody has gained access to your email account, act as soon as possible. The main priorities are to regain control of the account, make sure the device you are using is safe, remove anyone else’s access and check whether important settings were changed.

An email account can be compromised because somebody obtained the password through phishing, password reuse, malware or another form of account theft. If the device itself may be infected, changing the password on that same device can leave the new password at risk as well.

Was your email account actually hacked?

Some warning signs strongly suggest that somebody else has accessed your account. These include a password or recovery address being changed without you, unfamiliar sign-ins, messages in your Sent folder that you did not write, missing emails or security notifications about devices you do not recognise.

Your contacts receiving strange messages that appear to come from you can also be a warning sign, but it does not prove that the account itself was accessed. An attacker can sometimes use email spoofing to make a message look as though it came from your address without signing in to your mailbox.

If there are signs of activity inside the account itself, treat the account as compromised and secure it.

What should you do if your email is hacked?

The exact settings differ between email providers, but the main recovery steps are broadly the same.

  1. Check whether the device itself may be compromised.
  2. Recover the account if you cannot sign in.
  3. Change the email password.
  4. Sign out unfamiliar devices and sessions.
  5. Check your recovery information and sign-in methods.
  6. Remove unfamiliar forwarding rules, filters and connected apps.
  7. Check what the attacker may have done inside the mailbox.
  8. Warn contacts if messages were sent from your account.
  9. Secure other accounts that may now be at risk.
  10. Turn on stronger sign-in protection.

Check whether your device may be compromised

Your email password may not have been stolen from the email service itself. Malware, a malicious browser extension, unsafe software or something you downloaded can sometimes capture passwords or other sign-in information from your computer.

If the problem started after downloading unfamiliar software, opening an unexpected attachment, installing a browser extension or following suspicious instructions on a website, treat the device itself as potentially compromised. Do not immediately enter a new email password on that device, because harmful software may be able to capture the replacement as well.

If possible, use another trusted device to secure the email account first. On the affected computer, update your operating system and security software, run a full malware scan and remove anything suspicious that is found before using it again for important account changes.

Recover the account if you cannot sign in

If the attacker has changed your password or recovery information, use the email provider’s official account-recovery process. Do not use recovery links sent to you by strangers or pay somebody who claims they can bypass the provider’s security checks.

For Gmail, recovering the mailbox means recovering the Google Account connected to it. The process, including what to do if your password or recovery information has been changed, is covered in How to Recover Your Gmail Account.

Outlook and Hotmail users can use Microsoft’s account sign-in and compromised-account tools. Apple provides password reset and account recovery for Apple Accounts used with iCloud Mail, while Yahoo uses its account-recovery tools for Yahoo Mail.

Recovery is not always guaranteed. The provider needs enough evidence to establish that the account actually belongs to you.

Change your email password

If you can access the account, change its password as soon as you are confident that the device you are using is safe. Use a new password that you have not used for another account.

If the old email password was also used elsewhere, those accounts may now be at risk even if they have not shown any suspicious activity. Change the reused password on those accounts as well, starting with important services such as your recovery email, banking, shopping and social-media accounts.

Do not simply make a small change to the old password. The replacement should be genuinely different.

Sign out other devices and sessions

Changing a password may remove some existing access, but do not rely on that alone. Check the devices, sessions or recent sign-in activity shown by your email provider and remove anything you do not recognise.

Some providers also offer a way to sign the account out from other devices. Microsoft, for example, provides a sign-out-everywhere option for Microsoft accounts, while Google lets you review and remove unfamiliar devices from the account.

Look at the date, location and device information where it is available. Bear in mind that locations can sometimes be approximate, so an unfamiliar location alone is not always proof of an attack.

Check your recovery information and sign-in methods

An attacker who expects you to change the password may try to leave another way of getting back into the account. Check the recovery phone number, recovery email address and other security information connected to the account.

You should also review any two-step verification methods, authenticator apps, security keys, passkeys or app passwords shown by the provider. Remove anything you did not add yourself.

If an unfamiliar recovery phone number or email address has been added, correct it immediately where the provider allows you to do so. Also make sure you still control the recovery email account itself, because access to that account can sometimes be used to reset the password again.

Check forwarding rules, filters and other email settings

This is one of the most important steps after an email account has been compromised. An attacker can sometimes keep receiving copies of your messages even after you change the password by adding an automatic forwarding rule.

Check for forwarding addresses, inbox rules, filters, delegates and other settings that you did not create. Depending on the provider, also look for unfamiliar reply-to addresses, automatic replies, connected accounts, app passwords and third-party apps with access to the mailbox.

Google specifically tells compromised Gmail users to review settings such as mail delegation, automatic forwarding, filters and remote IMAP or POP access. Microsoft and Yahoo also tell users to inspect forwarding and other mail settings after an account compromise.

Remove unfamiliar settings rather than simply turning them off temporarily.

Check what happened inside your mailbox

Look through your Sent folder for messages you did not send. Also check Trash, Deleted Items and other folders for messages an attacker may have deleted after reading them.

Pay particular attention to password-reset emails, security alerts, banking messages and messages containing personal information. An attacker with access to your email may have used the mailbox to reset passwords for other services and then deleted the evidence.

If important messages appear to have been deleted, do not assume they are permanently gone. Some email providers keep deleted messages for a limited period or offer additional recovery options.

Warn your contacts if messages were sent from your account

If the attacker sent email from your mailbox, let the affected people know that the messages were not from you. This is particularly important if the messages asked for money, passwords, personal information or contained unexpected links or attachments.

Tell recipients not to follow instructions in the suspicious messages and to be cautious about any further messages from the compromised period.

Many email-account attacks begin with deceptive messages that steal a password. If you entered your email password into a page reached through a suspicious message, phishing may have been how the attacker gained access.

Check your other accounts

Email accounts are particularly valuable to attackers because email is often used to reset passwords for other services. Once somebody controls your inbox, they may try to take over shopping accounts, social-media profiles, cloud storage or financial services connected to the same address.

Look for unexpected password-reset messages, login alerts or security changes from other services. If another account appears to have been accessed, secure that account directly rather than assuming that fixing the email account will automatically fix everything else.

If banking information, payment details or sensitive identity documents may have been exposed, contact the relevant bank or organisation directly. Use contact information you already trust rather than phone numbers or links found in suspicious messages.

Turn on two-factor authentication or a passkey

Once you have regained control, strengthen the way the account is protected. Two-factor authentication, sometimes called two-step verification, requires another form of verification in addition to the password.

This means that stealing the password alone may not be enough for somebody to sign in again. Providers increasingly also support passkeys, security keys and authenticator apps as alternatives to relying only on a password or text-message code.

The different options and what they actually protect against are covered in Two-Factor Authentication and Passkeys for Email Explained.

What if your email was hacked but you are still receiving messages?

An account does not have to be completely locked to be compromised. An attacker may deliberately leave the password unchanged so that you do not realise somebody else has access.

If you notice an unfamiliar login, forwarding rule, sent message or security change, secure the account even if email appears to be working normally. Do not wait until you are locked out before taking action.

What if the attacker changed your recovery email or phone number?

Use the provider’s official recovery and security process as soon as possible. Some providers send warnings when recovery information or other important security settings are changed, and those warnings may include a way to report that the change was not yours.

Do not repeatedly change settings back and forth if somebody else is actively controlling the account. Regain control through the provider’s recovery process, change the password, remove unfamiliar sessions and then review the security information again.

What if your work or school email is hacked?

If the account belongs to an employer, school or another organisation, contact its IT administrator or security team as soon as possible. Managed email accounts can have security controls that ordinary users cannot access themselves.

The organisation may be able to reset the account, revoke active sessions, inspect suspicious activity and check whether other accounts were affected. Follow its security procedures rather than treating the account exactly like a personal Gmail, Outlook, Yahoo or iCloud account.

EmailExplained.com
Logo