Ask Questions

Ask Questions

What to Do If Your Email Account Is Hacked

Person beginning to recover a compromised email account

Your email account is more than an inbox. It can receive password-reset links, approve new accounts, store bills and identity documents, and reveal which services you use. If someone else gains access, they may be able to move quietly from your email into other parts of your digital life.

Act quickly, but do not rush through random changes. The safest order is to use a trusted device, regain control of the account, remove the attacker's access, inspect what they changed, and then protect accounts connected to that inbox.

If this is a work email account, contact your IT or security team immediately. Do not try to investigate or clean up a managed account on your own unless they tell you to.

Confirm the Warning Without Using It

An unexpected sign-in alert can be genuine, but it can also be a phishing message designed to frighten you into clicking. Do not use links, phone numbers, or buttons in the warning itself.

Open the email provider's known app or type its address yourself. Check recent activity, signed-in devices, security changes, sent mail, and deleted items. Common signs of unauthorized access include:

  1. A password or recovery detail changed without your approval.
  2. A successful sign-in from a device or location you do not recognize.
  3. Messages in Sent, Drafts, Trash, or Archive that you did not create.
  4. Contacts receiving strange messages from your address.
  5. Password-reset emails for other accounts that you did not request.
  6. Missing messages or replies that you never saw.

Location information is not perfect. Mobile networks, corporate connections, and VPNs can make a legitimate sign-in appear to come from somewhere unexpected. Look at the device, time, activity, and other evidence together.

If the warning began with a suspicious message and you interacted with it, follow the response steps in what to do after clicking a phishing link as well.

Start From a Device You Trust

Use a different, trusted device for recovery if you installed unknown software, opened a suspicious attachment, added a browser extension, or gave someone remote access. Changing a password on a compromised device may simply expose the new password too.

Update the trusted device and browser before signing in. If you suspect malware on the original device, disconnect it from the network when practical and run its supported security scan. A work device should be left to your IT team.

You do not need to wipe every device just because an email account was accessed. Treat the account and the device as separate questions: recover the account immediately, then investigate any device that may have caused the compromise.

Regain Control of the Account

If you can still sign in, change the email password to a new, unique password. Do not make a small variation of the old one. If that password was reused anywhere else, those accounts need new passwords too.

If you cannot sign in, use the provider's official account-recovery process from its app or help pages. Try the process from a familiar device and location, because providers may use that context when deciding whether a recovery attempt is legitimate. Supply accurate information and avoid paying a third party that promises to bypass the provider's process.

Once you are back in:

  1. Sign out all other sessions and devices.
  2. Remove devices, passkeys, or app passwords you do not recognize.
  3. Confirm that the recovery phone number and backup email belong to you.
  4. Replace any recovery codes that may have been viewed or downloaded.
  5. Turn on multi-factor authentication using a method you control.

A password manager can generate and save a genuinely unique password. If you do not already use one, this guide to choosing the right password manager explains what to look for. Also review why two-factor authentication matters before choosing your second factor.

Remove Hidden Access

Changing the password is important, but it may not remove every way back into the account. An attacker may have created a forwarding rule, granted access to another application, added a recovery method, or kept an active session.

Person reviewing account settings and connected access

Review these settings carefully:

  1. Forwarding and mail rules: Remove rules that forward, redirect, delete, archive, or mark messages as read without a clear reason.
  2. Delegates and shared access: Remove people or mailboxes you did not authorize.
  3. Connected applications: Revoke unfamiliar apps and any access you no longer need.
  4. App passwords: Delete old or unknown passwords created for mail clients and devices.
  5. Recovery options: Remove unknown phone numbers, email addresses, security questions, passkeys, and trusted devices.
  6. Signatures and automatic replies: Delete links, payment instructions, or messages you did not add.
  7. Aliases and sending addresses: Check for addresses that allow someone to send as you.

Look through Sent, Trash, Archive, Spam, and recently deleted folders. Attackers sometimes hide password-reset messages or replies from people they contacted. Search for terms related to password resets, verification codes, invoices, payments, and security changes, but do not click unfamiliar links while investigating.

Protect Accounts Connected to Your Email

Email access can be used to reset passwords elsewhere. Prioritize accounts that can lead to money, identity information, more accounts, or control of your phone number.

Start with banking and payments, your mobile carrier, cloud storage, government services, shopping accounts with saved cards, social media, and any other email account. Review recent activity and security settings on each one. Change a password when it was reused, when a reset was requested, or when you see evidence of access.

Do not automatically change hundreds of passwords without checking what happened. Begin with the highest-impact accounts and any service mentioned in suspicious mail. This keeps the response manageable and reduces the chance that you lock yourself out while rushing.

If recovery codes for important accounts were stored in the mailbox or cloud storage connected to it, replace them. The guide to storing account recovery codes safely can help you move them somewhere that does not depend on the same email account.

Contact your bank or payment provider through its trusted app or known phone number if you find an unauthorized transaction, altered payee, unfamiliar card, or payment request sent in your name. Do not reply to an email that claims it can reverse the fraud.

Warn People the Attacker May Have Contacted

Tell contacts if messages were sent from your account or if you cannot determine what the attacker did. Use another trusted channel when possible, especially if the attacker may still be reading replies.

Person warning contacts and checking linked accounts after recovery

Keep the warning simple. Say that your email was accessed, give the approximate time period, and tell people to ignore unexpected links, attachments, payment requests, password-reset messages, or requests for sensitive information. You do not need to speculate about who did it.

If the attacker used a business mailbox, customers and suppliers may receive convincing requests to change bank details or pay a fake invoice. Notify the people responsible for finance and vendor relationships immediately. They may need to pause transactions and verify recent requests by phone.

Work Out How Access Was Gained

Recovery is incomplete if the original route remains open. Common causes include a reused password exposed elsewhere, a phishing page, approval of an unexpected sign-in prompt, malware, an unsafe browser extension, a stolen active session, or weak recovery settings.

Review what happened before the first suspicious activity. Check whether you entered the password on an unusual page, approved a prompt you did not initiate, installed something, or reused the same credentials. Also check whether the provider recorded a new application, device, or recovery method at that time.

You may not find a definitive answer. That is frustrating, but it does not prevent you from improving the account. A unique password, stronger authentication, clean recovery details, fewer connected apps, updated devices, and secure recovery codes close the most common paths back in.

A Practical Email Recovery Checklist

  1. Open the provider directly instead of using a warning link.
  2. Use a trusted device for account recovery.
  3. Change the password or complete the official recovery process.
  4. Sign out other sessions and remove unfamiliar devices.
  5. Correct recovery details and replace exposed recovery codes.
  6. Enable multi-factor authentication.
  7. Delete malicious forwarding rules, delegates, apps, and app passwords.
  8. Inspect sent, deleted, archived, and hidden messages.
  9. Secure high-impact accounts connected to the inbox.
  10. Warn contacts and financial staff about fraudulent messages.
  11. Scan or investigate any device that may have caused the compromise.

The Bottom Line

A hacked email account can become a route into many other services, so recovery should go beyond changing one password. Regain control from a trusted device, end other sessions, remove hidden forwarding and connected access, and confirm every recovery method belongs to you.

Then inspect the accounts and people connected to the inbox. Protect the highest-impact services first, warn anyone who may have received a fraudulent message, and investigate the likely cause. A careful response can contain the damage and leave the account stronger than it was before.