Email Account Hacked? How to Recover It and Secure Everything Else
What to do if your email account was hacked, for any provider: recover it through official routes, remove hidden forwarding and rules, then secure the accounts your inbox can reset.
If your email account was hacked, sign in and change the password right away, or start your provider’s official account recovery if you’re locked out. Then turn on two-step verification or a passkey, sign out of all other sessions, restore your recovery phone and email, and remove any forwarding, filters or rules you didn’t create. Finally, change the passwords of accounts that use this email for resets, starting with banking, and warn your contacts about messages you didn’t send.
Email is the master key to most of your online life, so it’s the first account to fix after any hack. The steps below work for Gmail, Outlook and Hotmail, Yahoo, iCloud and most other providers. For Yahoo’s own recovery steps, see our guide to a hacked Yahoo account. If you’d rather close an old address once it’s secure, see our guides to deleting a Yahoo account or an Outlook account.
Signs your email has been hacked
- Contacts receive messages you didn’t send, often asking for money, gift cards or a link click.
- Your Sent, Trash or Archive folders contain emails you don’t recognize.
- Security alerts about a new sign-in, a password change or a changed recovery phone.
- Password reset emails from other services that you didn’t request.
- Emails you expect never arrive, which can mean a filter is deleting or redirecting them.
- Your password no longer works.
One thing that isn’t a sign: an email from a stranger claiming they hacked your account or recorded you, and demanding payment. Those are almost always mass extortion scams using old breach data. Our guide to the “you’ve been hacked” email scam explains how to tell. The real password it quotes still needs changing, though.
If you can still sign in: the first 15 minutes
- Change the password to a long, unique one you’ve never used anywhere else. Do it on a device you trust.
- Sign out of all other sessions. Most providers show a list of devices and recent sign-ins in the account’s security settings, with an option to sign out everywhere. Use it.
- Check recovery details. Make sure the recovery phone and backup email are yours. Attackers change these so they can reset the password again later.
- Turn on two-step verification or passkeys. An authenticator app, passkey or security key is stronger than text-message codes, which can be stolen through a SIM swap.
- Run the provider’s security check, if it has one. Google, Microsoft and Apple all offer a guided security review.
If you’re locked out: use the official recovery route only
Every major provider has its own recovery process, started from the sign-in page with the “forgot password” or “can’t sign in” option. It asks questions or checks signals to confirm you’re the owner.
- Use a device and network you’ve used before, such as your usual laptop on home Wi-Fi. Providers use these as signals.
- Answer as fully as you can, including old passwords and when you created the account, if asked.
- Try again later if the first attempt fails. Some processes ask different questions or allow a waiting period.
For provider-specific detail, see our guides on a hacked Gmail account, Microsoft account recovery for Outlook and Hotmail, and an Apple ID that’s been hacked for iCloud Mail.
Remove the hidden settings attackers leave behind
Changing your password doesn’t undo changes the attacker made inside the account. These are the settings to check, whatever your provider calls them:
| Setting | Why attackers use it | What to do |
|---|---|---|
| Automatic forwarding | Keeps sending them copies of your mail after you change the password | Remove any forwarding address you didn’t add |
| Filters or rules | Hide security alerts, bank emails or replies from people they’ve scammed | Delete rules that move, delete, mark as read or forward mail |
| Delegated or shared access | Lets another account read your mail | Remove anyone you didn’t authorize |
| Aliases and “send as” addresses | Lets them send mail that appears to come from you | Delete unfamiliar addresses |
| App passwords and connected apps | Keeps access for mail apps or third-party services even after a password change | Revoke all you don’t recognize or use |
| Auto-reply and signature | Adds phishing links to every message you send | Remove text you didn’t write |
Also look through Sent and Trash from the period of the hack. They show who the attacker contacted and which services they tried to reset.
Secure the accounts your email controls
Anyone with your inbox can reset passwords on accounts that use it. Work through these in order:
- Banking and payment accounts. Change passwords, check for new payees or transfers, and call your bank using the number on your card about anything you didn’t do. If PayPal or Amazon was affected, see our guides on a hacked PayPal account and a hacked Amazon account.
- Your phone carrier account, so no one can move your number. Ask for an account PIN and SIM-swap protection.
- Social media accounts, which attackers use to scam your friends.
- Shopping, cloud storage and work accounts.
- Anywhere you reused the old password. Check whether your address appears in known breaches with our guide to Have I Been Pwned.
Warn your contacts
Attackers often use a hacked inbox to scam the people who trust you. A short message is enough:
Hi, my email account was hacked recently. If you got a message from me asking for money, gift cards or to open a link or attachment, please ignore and delete it. The account is secure now. Sorry for the trouble.
If it’s a work email, tell your IT or security team straight away. Business email compromise is a serious risk: attackers read threads about invoices and then send a convincing request to change bank details. Call suppliers and clients on a known number to confirm any recent payment instructions.
Not sure where to start?
Get a free audit of your search results and review profiles, with a prioritized fix list.
Get a free auditIf personal information was exposed
Inboxes hold tax forms, ID scans, bank statements and medical letters. If the attacker could have seen them, consider a free credit freeze with each of the three major credit bureaus. If your information has been misused, for example to open accounts in your name, report it at IdentityTheft.gov, the FTC’s official site, which gives you a recovery plan. Our guide on what to do if your identity is stolen covers the rest.
A worked example
This scenario is illustrative, not a real client. Marisol runs a small bookkeeping business from a Yahoo address. A client calls to ask why she sent new bank details for her invoice.
- She hadn’t. She signs in, changes her password and signs out of all sessions.
- In settings she finds a forwarding address she never added and a filter sending every reply containing “invoice” or “bank” to trash. She deletes both.
- She turns on two-step verification with an authenticator app, checks her recovery phone, and revokes an unfamiliar app password.
- She calls her clients on numbers she already has and tells them to ignore any payment changes from the last week. One had already paid. That client calls their bank at once to report the transfer.
- She changes her bank and cloud storage passwords, both of which used the same password as her email.
Without the filter check, she would have kept missing clients’ replies asking about the “new” bank details.
Common mistakes
- Changing the password and stopping. Forwarding, rules and app passwords can survive it.
- Clicking links in security alerts. Some are fake. Go to your account directly.
- Deleting the account. It usually makes things worse, because you lose the ability to reset every account tied to it.
- Relying on text codes only. Use an authenticator app or passkey where you can.
- Paying a recovery service. Recovery through your provider is free.
How to prevent it happening again
- Use a unique password for your email, saved in a password manager.
- Keep two-step verification or passkeys on, and store backup codes somewhere safe.
- Keep recovery details current.
- Review connected apps and forwarding a few times a year.
- Go to your account directly instead of clicking sign-in links in emails.
If a hacked inbox led to embarrassing messages or leaked emails showing up online, our personal reputation management service can help with removal requests and cleanup, and we’ll be honest about what can come down.
Frequently asked questions
What's the first thing to do if my email is hacked?
Change the password and sign out of all other sessions if you can still sign in. If you can’t, start your provider’s official recovery from its sign-in page. Then turn on two-step verification and check for forwarding and filters.
Can a hacker still read my email after I change the password?
Yes, if they set up forwarding, a rule, delegated access or an app password. Check and remove all of these after any hack.
Should I create a new email address after being hacked?
Usually not. Recovering and securing your existing address keeps access to the accounts tied to it. A new address can make sense if the old one is flooded with spam or used for harassment, but move your accounts over carefully.
How did my email get hacked?
Most often through a password reused from a breached site, a phishing page, or a stolen text code after a SIM swap. A unique password and two-step verification with an authenticator app or passkey block most of these.