Your preparation
0 of 0 safeguards readyWhat this means
Your email is not one account among many. It is the master key. Nearly every other service you use will happily send a password reset to it, no questions asked beyond access to the inbox.
So treat this as urgent even if nothing looks damaged yet. Someone reading your mail quietly is often more dangerous than someone who changes your password and locks you out, because you have no reason to look.
The part people miss is that changing your password does not, by itself, remove the intruder. They may have set up a forwarding rule, added their own recovery address, or authorised an app that keeps reading your mail with its own permissions. Any one of those survives a password change. You have to go and remove them.
Warning signs
- Sent messages you did not write, or replies to conversations you never had.
- Contacts tell you they received a strange message from you, often asking for money or a code.
- Password reset emails arrive for accounts you did not try to reset.
- Messages disappear from your inbox, which can mean a rule is deleting them so you miss the alerts.
- Your provider shows a sign-in from a country or device you do not recognise.
- You are suddenly signed out on every device and your password no longer works.
Recover now
First 15 minutes
- Change your email password from a device you trust. If you still have access, do this immediately. Pick something long and not reused anywhere.
- Sign out every other session. Every major provider has a button for this. It kicks the intruder out of any browser they left open.
- Turn on two-factor authentication if it was off, or check that the second factor still points at your own phone and not someone else’s.
- Check for forwarding rules and filters, and delete anything you did not create. This is the step people skip, and it is the one that lets someone keep reading your mail for months.
- Check your recovery email and phone number. If an attacker changed these, they can take the account back the moment you look away.
Clean out the hidden access
- Open myaccount.google.com/security-checkup. It walks through devices, recent activity, and saved passwords in one place.
- In Gmail, go to Settings → See all settings → Filters and Blocked Addresses, and delete any filter you did not create. Look for ones that forward, archive, or delete.
- Go to Settings → Forwarding and POP/IMAP and remove any forwarding address. Check that POP and IMAP are off unless you use them.
- Go to Settings → Accounts and Import and check Grant access to your account, which lets another person read your mail entirely separately from your password.
- At myaccount.google.com/permissions, remove any third-party app you do not recognise. These keep working after a password change.
- Open account.microsoft.com/security and review recent activity for sign-ins that were not you.
- In Outlook.com, go to Settings → Mail → Rules and delete any rule you did not create.
- Go to Settings → Mail → Forwarding and turn off forwarding if it is enabled.
- Check Settings → Mail → Sync email for connected accounts that could be pulling or sending your mail.
- Remove app passwords and unknown devices under the security page. App passwords bypass two-factor entirely, so any one you do not recognise should go.
- Sign in at appleid.apple.com and review the Devices list. Remove anything you do not recognise, which signs it out of your account.
- In iCloud Mail on the web, open Settings → Rules and delete rules you did not create.
- Check Settings → Forwarding and turn off any forwarding address.
- Under Sign-In and Security, check your trusted phone numbers. Remove any number that is not yours.
- Review Apps using Apple Account and revoke anything unfamiliar. Also check for app-specific passwords and revoke ones you cannot account for.
Today
- Change the password on anything that uses this email address to sign in, starting with your bank, your password manager, and any shopping account with a saved card.
- Look through your sent folder and your deleted folder to see what the intruder did. This tells you who to warn and what else to check.
- Warn your contacts, briefly and without drama. A short message saying your email was compromised and to ignore anything odd is enough.
- Check the accounts that could have been reset while the intruder had access. Password reset emails in your inbox or deleted folder are the clue.
- If money or identity documents were involved, tell your bank and consider a credit freeze.
Verify recovery
- Signing in requires your new password and your second factor.
- The recovery email address and phone number are yours, and nothing else is listed.
- No forwarding addresses, rules, or filters exist that you did not create.
- No unfamiliar apps have access to your mailbox.
- Recent activity shows only your own devices and locations.
Prepare now
The account itself
- Two-factor authentication is on, using an authenticator app or a passkey rather than SMS.
- The password is long, unique to this account, and stored in a password manager.
- Recovery codes are saved somewhere offline, such as printed and kept at home.
- Your recovery phone and address are current, so you can get back in without the provider’s slow appeals process.
Around the account
- A second email address exists for account recovery, and it is not reachable from this one.
- Important documents and photos are not stored only in your mailbox.
- You would notice a sign-in alert, meaning notifications are on and going somewhere you read.
- Your most important accounts use a passkey, which cannot be phished the way a password can.
Common mistakes
- Only changing the password. Forwarding rules, connected apps, and extra recovery addresses all survive it. The intruder walks straight back in.
- Ignoring it because nothing looks broken. Quiet access is the profitable kind. They are usually waiting for something worth taking.
- Using the compromised address to reset other accounts. Clean it up first, or you are handing over each new password as you create it.
- Setting up SMS two-factor and stopping there. It is better than nothing and much weaker than an app, because phone numbers can be taken over.
- Not checking the deleted folder. Attackers delete the alert emails. That folder is often the only record of what they touched.
Sources
- Google: Secure a hacked or compromised Google Account
- Microsoft: My Outlook.com account has been hacked
- Apple: If you think your Apple Account has been compromised
- UK NCSC: Recovering a hacked account