What to Secure First When Your Email Account Is Hacked

What to Secure First When Your Email Account Is Hacked

An email account is more than a mailbox. It is often the recovery route for banking, shopping, cloud storage, social media, work tools, and the password manager. Someone who controls it may reset other passwords, hide security alerts, impersonate you, or quietly forward future messages. That is why the first response must secure control and remove persistence, not merely delete a strange email.

Use this order when you believe an inbox was accessed without permission. The exact menu names differ by provider, but the recovery priorities are stable.

Priority order for securing a hacked email account

1. Move to a trusted device

If the incident began after you opened a suspicious attachment, installed software, allowed remote support, or noticed unexplained control of the device, do not change the email password there. An attacker or malicious program could capture the replacement.

Use an updated phone or computer you already trust. For a work or school mailbox, contact the organization’s security or support team from another channel. It may need to preserve logs or isolate the original device.

If there is no reason to suspect the device itself and the issue is only an unfamiliar account session, you can use the provider’s official security page. Reach it by opening the known app or typing the address yourself, not through a link in the warning.

2. Regain control through the official recovery route

If you can still sign in, open the account’s security settings immediately. If the password no longer works, use the provider’s account-recovery process. Supply only information requested on the genuine provider domain.

Recovery can be easier from a familiar device and network. Avoid repeated guesses that may create additional lockouts. Do not pay a person who claims they can hack the account back; third-party recovery offers can be another scam.

Once inside, verify that the account address is correct. People sometimes secure a secondary inbox while the compromised primary account remains exposed.

3. Replace the password and every reused copy

Create a long, unique password using a password manager. If the old email password was reused, replace it on every other account, beginning with the password manager, recovery inbox, mobile-carrier account, financial services, cloud identity, and work access.

Do not make small predictable changes such as adding the current year. A credential exposed through a data breach or phishing page should never return to use.

If the account supports passwordless sign-in or passkeys, review those options after control is stable. Do not rush into removing all fallback methods until recovery is prepared.

4. End sessions and remove unknown devices

A password change may not terminate every browser, app, mail client, or token. Use the account’s signed-in device, session, or recent-activity page. Remove or sign out anything you do not recognize and anything you no longer control.

Use a global sign-out option where appropriate, then sign back in only on trusted devices. Some providers warn that session removal can take time or may exclude specific products. Read the current instructions and check the list again later.

The device and session audit explains how device lists, sign-in records, and connected apps differ.

5. Repair recovery and authentication methods

Review every recovery phone number and email address. Remove unknown entries and correct your own information. Check passkeys, security keys, authenticator registrations, app passwords, backup codes, and push-approval devices.

Regenerate backup codes if the existing set might have been viewed. Revoke a lost security key or phone. Add a second safe authentication method so one damaged device does not force weak recovery later.

Use the strongest method the provider supports. The authentication-method comparison explains why SMS and one-time codes add protection but are not phishing-resistant, while properly implemented passkeys and security keys provide stronger defense against fake login pages.

6. Check forwarding before assuming the intruder is gone

Email forwarding can give an attacker copies of new messages after you change the password. Open the provider’s forwarding settings and remove any address you did not add. Check both account-level forwarding and rules that forward or redirect selected messages.

Attackers can create subtle rules instead of forwarding everything. Look for conditions involving words such as password, security, bank, invoice, payment, verification, or the names of important services. A rule may mark alerts read, move them to archive or trash, delete them, or forward them quietly.

Google’s hacked-account guidance specifically tells users to remove unfamiliar Gmail labels, filters, and forwarding rules. Microsoft’s recovery guidance also directs users to check connected accounts, forwarding, and automatic replies.

7. Inspect delegates, connected accounts, and app passwords

A mailbox can grant another person or service access without a normal device login. Review delegates, shared-mailbox permissions, connected inboxes, POP and IMAP access where relevant, and applications authorized to read or send mail.

Remove unknown OAuth or connected applications. Revoke app passwords created for older clients. If an outside application legitimately needs mail access, reconnect it only after verifying the developer and the permissions.

Do not assume uninstalling an app from a phone removed its online authorization. The account’s connected-app page is the authoritative place to revoke access.

8. Search for what the intruder did

Review Sent, Drafts, Trash, Archive, Spam, and recently deleted folders. Search for password resets, new-account messages, forwarding confirmations, bank alerts, purchase receipts, and verification codes. Check whether the attacker marked messages read or deleted warnings.

Inspect the address book and contacts for changes. Review automatic replies and the email signature for altered payment details, phone numbers, or links. For a business mailbox, search for messages requesting invoice or bank-detail changes.

The absence of obvious sent messages does not prove nothing happened. An attacker may have read information, used the inbox only for resets, or deleted traces. Provider activity logs and organizational audit records can supply more context.

9. Protect the accounts that depend on the mailbox

Make a list of important services registered to the compromised address. Start with password managers, banks, payment services, cloud storage, mobile carriers, government or health portals, domain registrars, shopping accounts, social media, and work systems.

For each service:

  • check recent logins, transactions, and security changes;
  • change a reused or reset password;
  • end unknown sessions;
  • verify the recovery email and phone;
  • remove unfamiliar authentication methods and connected apps;
  • contact the provider through an official route when changes or purchases are unauthorized.

If the compromised email is itself a recovery address for another inbox, secure both. An attacker can move back and forth through a recovery chain.

10. Tell contacts with a specific warning

If messages were sent in your name, warn recipients through another trusted channel. State the approximate time, the account involved, and what people should not do. For example: do not open the invoice attachment sent this morning, do not use the payment details in that message, and do not send a verification code.

A vague “I was hacked” notice may not help recipients identify the dangerous message. Do not resend the live link or attachment while warning them.

Report impersonation and fraudulent messages to the email provider. A business may need to contact customers, vendors, insurers, or regulators according to its incident plan and legal obligations.

11. Secure money and identity when they were exposed

If the inbox contained card details, tax documents, identity scans, financial statements, or reset access to a bank, contact the relevant institution using its official app or verified number. Review transactions and follow its fraud instructions.

Record exactly what information the attacker could access. Identity-theft steps depend on the data and country. Use the appropriate national reporting and recovery service rather than a commercial service advertised in an unsolicited message.

12. Preserve an incident timeline

Save the first alert, sign-in details, password-change time, recovery changes, forwarding addresses, suspicious rules, sent messages, affected services, and support case numbers. Take screenshots before deleting a malicious rule when safe, then remove it.

Do not store the only copy of evidence inside the compromised inbox. Export it to a secure location. Redact passwords, codes, document numbers, addresses, and other personal information before sharing it.

How to decide whether the compromise is still active

Separate evidence of past access from evidence that someone is active now. A security email from yesterday, an old forwarding rule, or a recently signed-out device proves that a problem existed, but the current controls may already have stopped it. A new message sent after your password change, a recovery method that changes again, or a session that returns with fresh activity suggests continuing access.

Use timestamps and time zones. Record the moment you changed the password, revoked sessions, removed apps, and deleted rules. Then compare every later event with that sequence. This makes it possible to identify which control failed instead of treating the entire mailbox as an unexplained state.

Why the password may never have been stolen

Account access can come through a stolen session cookie, a connected application, a delegated mailbox, an app password, a compromised recovery process, or a device that was already signed in. Do not conclude that a strong password is useless because an incident occurred. Determine which access path was involved.

This also explains why replacing the password is necessary but not sufficient. A successful recovery closes the credential, sessions, applications, delegates, rules, and recovery channels that an attacker could use. The order in this guide is designed to cover that full surface.

If you cannot remove the attacker

If unknown sessions return, recovery information changes again, or mail continues to be sent after cleanup, look for a remaining access route:

  • malware or remote control on a device;
  • an active session not revoked by the password change;
  • a connected application or app password;
  • a compromised recovery email;
  • a stolen or transferred phone number;
  • an organizational delegate or administrator setting;
  • a browser extension that can read sessions or pages.

Use another trusted device and contact the provider or organization. Do not repeat the same password change while the source remains active.

Special steps for work and school email

Report quickly even if you regained access. The account may contain other people’s data, and the organization can check audit logs, revoke tokens, search for malicious forwarding, and warn affected colleagues. Follow instructions about preserving the original device.

Do not send confidential logs to a personal inbox unless the organization authorizes it. Use its incident-reporting channel or contact a manager by phone when email cannot be trusted.

After the emergency

  • Update devices and remove unknown browser extensions or apps.
  • Use a password manager and keep the email password unique.
  • Enable phishing-resistant authentication where supported.
  • Keep offline or separately protected recovery codes.
  • Review devices, connected apps, forwarding, and recovery methods periodically.
  • Reduce sensitive information retained indefinitely in the mailbox.
  • Practice how to reach account recovery without relying on the same phone and inbox.

The priority order to remember

Use a trusted device, regain control, replace exposed credentials, revoke sessions, repair recovery methods, remove forwarding and delegated access, inspect activity, and secure dependent accounts. Deleting one suspicious message comes much later. The real task is to close every route that lets the intruder return or expand into the rest of your digital life.

Sources and further reading

Hasnain

Hasnain is the writer and editor behind NerveFilter, where he explains suspicious messages, account access, phone privacy, app permissions, and digital-safety recovery. His work is documentation-based: guidance is checked against current provider instructions and primary public sources, with limitations stated when devices, regions, or software versions differ. He is not presented as a certified cybersecurity professional. To report an error or ask an editorial question, email contact@nervefilter.info; never send passwords, codes, or banking details.