Account recovery

What to do if your email account is hacked

Regain control of your email, remove hidden access, protect connected accounts, and warn people who may receive scam messages from you.

In this guide 9 sections
A person reviewing email account access on a laptop at a calm evening workspace

An email account can reset passwords for many other services. If someone gets into it, the priority is to regain control, remove their access, and check what else they may have reached.

If money or work data is involved: contact your bank, employer, or account provider through a trusted phone number or official website. Do not use contact details from a suspicious message.

First, use a device you trust

If your computer or phone is behaving strangely, stop entering passwords on it. Update its operating system and security software, then run the built-in security scan. You can also start recovery from another device that you already trust.

Open the email provider through its official app or by typing the address yourself. Avoid recovery links in unexpected emails, texts, or search advertisements.

If you can still sign in

Work through these steps in order:

  1. Change the email password to a long, unique password.
  2. Sign out of other devices and sessions.
  3. Turn on two-step verification or add a passkey.
  4. Check that the recovery email and phone number are yours.
  5. Remove devices, passkeys, app passwords, or connected apps you do not recognize.

If you reused the old password anywhere else, change those accounts too. Start with banking, shopping, cloud storage, social media, and your mobile carrier.

If you cannot sign in

Use the provider’s official account recovery page. Complete the process from a familiar device and location when possible. Give accurate answers and use a contact address that you can access.

Support processes differ between providers. A person who claims they can bypass recovery for a fee is not a safe shortcut. Never send them a password, verification code, or recovery code.

Remove hidden ways back in

Changing the password is important, but it may not remove every form of access. Review:

  • Email forwarding rules
  • Inbox filters and blocked-address lists
  • Automatic replies and email signatures
  • Delegated mailbox access
  • Connected apps and app passwords
  • Signed-in devices and recent activity

Delete any rule or connection you did not create. An attacker may use forwarding to keep receiving password-reset messages after you change the password.

Check what happened while the account was exposed

Look in Sent, Deleted, Trash, and Archive folders. Search for password-reset messages, purchase receipts, security alerts, and changes to other accounts.

Then check your important accounts directly. Do not follow links from messages in the affected inbox. If you find an unfamiliar financial transaction, contact the bank or payment provider immediately using the number on your card, statement, or official app.

Warn your contacts

Tell family, friends, or colleagues that the account was compromised. Ask them to ignore unexpected links, attachments, requests for money, or requests for verification codes that appeared to come from you.

Use a different communication channel if you are not yet sure the email account is secure.

Make recovery easier next time

Once the account is stable, save recovery codes somewhere separate from your everyday phone. Confirm that your recovery information is current and review the guide to storing recovery codes safely.

You can also work through the household safety checklist to protect the accounts connected to your email.

Your sensible stopping point

You are done with the urgent part when the password is unique, other sessions are signed out, recovery details are correct, two-step verification is working, and no unknown forwarding rules remain.

Official sources