What to do if your email account was hacked
Maybe a login alert arrived from a city you have never been to, friends started asking about a strange message you never sent, or your password suddenly stopped working. Whatever tipped you off, finding out your email account was hacked is unsettling, because your inbox is where so much of the rest of your life is anchored. The good news is that the steps to take back control are clear, and moving through them calmly in the right order is what matters most.
It helps to understand why email is the account that criminals want most. Your inbox is the reset button for nearly everything else you own online. Banking, shopping, social media, even other email addresses all send their “forgot password” links to the same place. So the first goal is not to figure out who did it, but to lock the door and change the locks before anything else can be opened.
Get back in and change the password first
If you can still log in, change your password right away. Make it long and unlike anything you have used before, ideally twelve to fifteen characters or a short string of unrelated words, and do not reuse a password from any other account. Once it is changed, look for the option to sign out of all devices or end all active sessions. That single step kicks the intruder off any phone or computer where they were still logged in, so a new password actually sticks.
If you cannot log in because the password or recovery details were already changed, you are not locked out for good. Every major provider has an account recovery process for exactly this situation. Google, Microsoft and Outlook, Yahoo, and Apple each have a dedicated recovery flow that verifies your identity through backup information or a trusted device. Search for your provider’s name plus “account recovery” and use only the official support page, not a number or link someone sent you.
Turn on two-factor authentication
Once you are back in, add two-factor authentication if you did not already have it. This means that even if someone learns your password again, they still cannot get in without a second code from your phone or an authenticator app. An authenticator app is more secure than codes sent by text, partly because text messages can be intercepted through a SIM swap. If your phone recently lost service around the time of the breach, that may be how they got in, and our guide on a phone that suddenly has no service walks through what a SIM swap looks like and how to respond.
Check what the intruder set up while they were in
This is the step people skip, and it is the one that lets a hacker quietly keep reading your mail long after you change the password. Someone with access to your inbox often leaves a way back in before they leave. Go into your email settings and look carefully at a few things: any auto-forwarding rule that copies your incoming mail to an address you do not recognize, any filter that automatically deletes or archives certain messages so you never see the bank alerts, and any recovery email or phone number that has been swapped for one that is not yours. Remove anything you did not set up. While you are there, check your sent folder and trash for messages the intruder sent in your name, so you know who may have heard from “you.”
Protect the accounts your email unlocks
Because your inbox can reset other passwords, treat any account tied to it as potentially exposed, especially banking, shopping sites with a saved card, and your other email or social accounts. Change the passwords on the most sensitive ones, and turn on two-factor authentication there too. If a social profile was affected as well, our guide on recovering a hacked social media account covers that side. Keep an eye on your bank and card statements over the next few weeks, and if you see accounts or charges you did not make, our post on what to do when someone opens accounts in your name explains how to freeze your credit and clean things up.
Report it and warn your contacts
Let your contacts know the account was compromised, so nobody acts on a message the hacker sent asking for money or gift cards in your name. If you believe personal information was exposed, the U.S. Federal Trade Commission’s IdentityTheft.gov will walk you through a personalized recovery plan and generate the paperwork you may need. It is worth reporting even if nothing was stolen yet, because it puts the incident on record.
You handled it
An email breach feels like a violation of something private, and that reaction is fair. But an inbox is recoverable, and the person who got in was almost certainly casting a wide net rather than targeting you personally. Changing the password, signing out every device, turning on a second factor, and clearing out the rules they left behind closes the door firmly. If you would like a second set of eyes on what happened or help working out how they got in, that is the kind of thing we are here for.
— Gus