Email is the account that resets every other account, which is why it is the one criminals want most. If yours has been taken over, or you think it has, what you do in the next hour decides how much trouble follows. Work through these in order.
How you know
- Friends or customers receive messages from you that you did not send.
- You cannot sign in, and the password reset goes to an address or phone you do not recognize.
- Sent messages, or messages you did not read, that you never saw.
- A notice from the provider that the account was signed in from somewhere new, or that the recovery details were changed.
- Password reset emails for other accounts that you did not request. This one means the intruder is already moving on to the rest.
The first hour
1. Get back in, or lock them out. Sign in from a device you trust. If your password still works, change it now to something long that you have never used anywhere. If it does not work, use the provider's account recovery page; Google, Microsoft, Yahoo and Apple all have one.
2. Check the recovery details. In the account's security settings, look at the recovery phone number and recovery email. Intruders add their own so they can get back in after you change the password. Remove anything that is not yours.
3. Check forwarding and rules. This is the step people miss. Intruders set the account to forward a copy of every message to them, or create a rule that hides certain messages, and it survives a password change. In Gmail, look under Settings, Forwarding and under Filters. In Outlook, look under Rules and under Forwarding. Delete anything you did not create.
4. Sign out everywhere. The security settings have an option to sign out of all other sessions or devices. Use it, so that any device the intruder is holding open is disconnected.
5. Turn on two-step sign-in. With it on, a password alone no longer opens the account. Use an authenticator app rather than text messages if the provider offers it.
The first day
6. Change the passwords that matter, starting with money. Bank, credit cards, PayPal, Amazon, anything with a card stored. Then social media. If any of them used the same password as your email, they must be treated as compromised too. This is the point at which a password manager stops being optional; it is the only practical way to give every account its own password.
7. Look at what was in the mailbox. An intruder with an hour in your email has seen your bank's name, your accounts, your contacts and any document you ever sent yourself. Think about what they could do with it, and warn anyone who needs warning.
8. Warn your contacts. A short message to say your account was compromised and to ignore anything odd from you. It saves them from the scam that is usually the reason the account was taken in the first place.
9. Check the computer and phone. If the password was stolen by software on your computer, changing it only helps until the software steals the new one. Run a full scan, and if anything is found, or if you are not sure, have the machine checked before signing in to anything else from it.
The first week
10. Watch for the follow-up. Expect password reset emails, "confirm your identity" messages and calls claiming to be from your bank or from the email provider. These are the second act. Do not click, do not answer questions, and go to accounts directly as our guide to spotting a fake email describes.
11. Check your other accounts' recovery details. An intruder who had your email could have used it to reset other accounts and add their own recovery details there too.
12. If money was taken or your identity may have been used, contact the bank, report it to the FTC at reportfraud.ftc.gov, and consider a credit freeze with the three bureaus, which is free.
For a business
A hacked business mailbox is often the start of invoice fraud, where the intruder sends your customers a message changing your bank details. Warn customers straight away, check the sent folder and rules carefully, and if the business is on Microsoft 365 or Google Workspace, have the administrator review the sign-in log and reset the account from the admin side.
If you would like help
We handle exactly this: recovering the account, clearing out what the intruder left, checking the devices and putting protection in place so it does not happen again. The sooner we hear, the less there is to undo.