GuideHQ

What should I do if my email has been hacked?

Regaining control, closing the attacker's routes back in, and limiting what they can reach next.

Difficulty
beginner
Time
1 hr 30 min
Read
2 min

Short answer

Change the password immediately from a device you trust, turn on two-factor authentication, and sign out all other sessions. Then check for forwarding rules and changed recovery details — those are how attackers keep access after a password change.

Email is the master key to almost every other account, so a compromised mailbox is more serious than it first appears. Changing the password is only the first step: attackers routinely add forwarding rules and alternative recovery addresses that survive it.

What you'll need

  • A device you trust
  • Your phone for two-factor codes (optional)

Step by step

  1. Change the password now, from a device you trust.Long and unique, used nowhere else. If you cannot log in, start the provider's account recovery process immediately.
  2. Turn on two-factor authentication.This is what stops them getting back in even if they know the new password. An authenticator app is stronger than SMS.
  3. Sign out of all other sessions.Most providers have a 'signed-in devices' or 'active sessions' page. Without this, an attacker with an open session keeps access despite the new password.
  4. Check for forwarding rules and filters.This is the step people miss. Attackers add a rule silently copying your mail to themselves, or deleting security alerts before you see them.
  5. Check recovery email addresses and phone numbers.If they added their own, they can reset your password again at any time. Remove anything you do not recognise.
  6. Check the sent folder and account activity log.It tells you what they did and who they contacted — which determines who you need to warn.
  7. Change passwords on important accounts linked to that email.Banking, cloud storage, shopping, social media. Anything whose password reset goes to that mailbox is exposed.
  8. Warn your contacts.Compromised accounts are used to send convincing scams to the people you know, because the message genuinely comes from you.

Tips

  • Check whether your address appears in known data breaches. If it does, any account where you reused that password needs changing.
  • A password manager makes unique passwords practical, and unique passwords are what contain a breach to one account.
  • Keep two-factor backup codes on paper. They are what gets you back in when the phone is unavailable.

Common mistakes

  • Only changing the password — Forwarding rules, added recovery addresses and open sessions all survive a password change and give continued access.
  • Reusing the same password elsewhere — Attackers try breached credentials across many sites automatically. One reused password turns one breach into several.
  • Not warning contacts — Compromised accounts are used to scam the people in them, and a message from a known address is far more convincing.

Questions people ask

How do I know if my email has been hacked?

Signs include password reset emails you did not request, messages in your sent folder you did not send, contacts reporting odd messages, missing emails, or unfamiliar devices in the account activity log.

What is the first thing to do if my account is compromised?

Change the password from a device you trust, then enable two-factor authentication and sign out all other sessions. Then check forwarding rules and recovery details.

Written and maintained by the GuideHQ editorial team. More in Technology.