What to Do if Your Email Is Hacked (Step by Step)

What to Do if Your Email Is Hacked (Step by Step)

Written by

in

Discovering that someone else may be inside your inbox is stressful, but take a breath: this is a problem you can fix, and acting quickly makes a real difference. Your email account is often the master key to your digital life, so the goal is simple: lock the attacker out and take back control. This guide walks you through exactly what to do, one step at a time.

How to Know Your Email Was Hacked

Sometimes the signs are obvious, and sometimes they are subtle. You may have been hacked if you notice one or more of these warning signs:

  • You can’t log in, even though you are sure the password is correct.
  • Your password suddenly changed and you never changed it.
  • There are sent messages you didn’t write, or emails you never opened have been marked as read.
  • Friends and contacts report spam or strange messages coming from your address.
  • You received a login alert from an unfamiliar device, location, or browser.
  • Emails are disappearing or your inbox looks emptier than it should.

Any one of these can be a false alarm on its own, but together they are a strong signal that someone has access to your account. Either way, the steps below will secure things.

Step-by-Step: How to Take Back Control

Work through these in order. If you get stuck on one step, move on and come back to it.

1. Try to Regain Access and Reset Your Password

Go to your email provider’s login page and attempt to sign in. If your password no longer works, use the “Forgot password” or “Can’t access your account” link to start account recovery. Your provider will try to verify your identity through a backup email, a phone number, or security questions.

If you still have access, don’t wait: reset your password right away before doing anything else. Locking the attacker out is the single most important move.

2. Set a Strong, Unique Password

Once you can get in, replace the old password with a brand-new one. Do not reuse a password from any other account, and avoid small tweaks to your old one. A long passphrase made of several random words is both strong and easy to remember. Our guide on how to create a strong password walks you through it.

While you’re at it, you can check if your password leaked in a known data breach. If it did, that may be how the attacker got in.

3. Turn On Two-Factor Authentication

Adding a second layer of protection means a password alone is no longer enough to break in. With two-factor authentication enabled, anyone trying to sign in also needs a code from your phone or an authenticator app. This one setting stops the vast majority of account takeovers, so turn it on before you move on.

4. Check Recovery Email, Phone Number, and Security Settings

Attackers often change your recovery details so they can lock you out again later, even after you reset the password. Open your account’s security settings and confirm that:

  • The recovery email address is yours and no unfamiliar addresses have been added.
  • The recovery phone number is your own.
  • Your security questions haven’t been altered.

Remove anything you don’t recognize.

5. Look for Hidden Forwarding Rules and Filters

This step is easy to skip, and it’s the one attackers count on you missing. A common trick is to quietly set up mail forwarding or inbox filters so that copies of your messages, or specific ones like password-reset emails, are secretly sent to the attacker or automatically deleted before you see them. That means even after you change your password, they can keep spying or lock you out again.

In your email settings, carefully review:

  • Forwarding: make sure your mail isn’t being forwarded to an address you don’t recognize.
  • Filters or rules: delete any rule that forwards, deletes, marks as read, or moves messages in ways you didn’t set up.
  • Auto-reply and signature: check that no strange links or messages were added.

If you find anything suspicious here, remove it immediately. These leftover rules are one of the biggest reasons people get “re-hacked” days later.

6. Sign Out of All Devices

Most email providers have an option to see where your account is currently logged in and to sign out of all sessions and devices at once. Use it. This instantly kicks out anyone still connected, even if they were reading your mail a moment ago. After signing everyone out, you’ll simply log back in on your own devices with your new password.

7. Scan Your Device for Malware

If a hacker got your password through a virus or keylogger on your computer or phone, changing the password won’t help for long, because they can just steal the new one. Run a full scan with trusted security software on any device you use for email. Keep your operating system, browser, and apps updated too, since updates often patch the very holes attackers use.

8. Warn Your Contacts

While the account was compromised, the attacker may have emailed your friends, family, or coworkers, often with spam or links designed to trick them. Let your contacts know your email was hacked and tell them to ignore and delete any strange messages from you. Remind them not to click links or open attachments they weren’t expecting. If they’re unsure what a scam message looks like, point them to our guide on how to spot a phishing email.

9. Check Other Accounts That Use That Email

Your email is the recovery address for many other services: banking, shopping, social media, and more. Anyone who controls your inbox can request password resets for those accounts. Make a list of the important ones and:

  • Change the passwords on any account tied to that email, especially if you reused the hacked password.
  • Turn on two-factor authentication wherever it’s offered.
  • Look for signs of unauthorized activity, like unfamiliar orders or messages.

10. Watch for Signs of Identity Theft

In the days and weeks that follow, stay alert. Keep an eye out for unexpected bills, new accounts you didn’t open, password-reset emails you didn’t request, or notices from your bank. If money or personal information may be at risk, consider stronger monitoring, and read our overview of identity theft protection to understand your options. Reporting fraud early makes it far easier to undo.

How to Keep It From Happening Again

Once things are calm, a few habits will keep your inbox safe going forward:

  • Use a unique password for your email that you use nowhere else.
  • Keep two-factor authentication switched on.
  • Be cautious with unexpected links and attachments, even from people you know.
  • Review your account’s security and forwarding settings every few months.

Conclusion

Finding out your email is hacked is unsettling, but you are far from powerless. Reset your password, turn on two-factor authentication, and, above all, check for the hidden forwarding rules and filters attackers leave behind. Then sign out all devices, scan for malware, warn your contacts, and secure the other accounts linked to that inbox. Work through the steps calmly, and you’ll have your account, and your peace of mind, back in your own hands.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *