Hacked email account: what to do first

Email is the master key to almost everything else you own online — password resets, invoices, cloud storage, social accounts. That is why an attacker who reaches your mailbox usually tries to stay there quietly rather than lock you out.

This page sets out a safe order of work for a personal or business mailbox, what evidence is worth keeping before you clean up, and where Cyber Crisis Desk turns those steps into a tracked plan.

Signs your mailbox is compromised

  • Password resets or sign-in alerts you did not request.
  • Sent or Deleted Items containing messages you never wrote.
  • A forwarding rule, alias or “redirect” you did not create — often named with a single character or left blank so it is easy to miss.
  • Contacts telling you they received odd payment requests or link-only emails from you.
  • Active sessions or devices in your account security page from unfamiliar locations.
  • Security settings changed: recovery address, phone number, or app passwords added.
  • Legitimate replies arriving in a folder you never use, hiding a conversation from you.

Safe immediate actions, in order

  1. Use a device you trust. If the same computer or phone may be infected, do the recovery from a different one. Changing a password from a compromised device can hand the new one straight back.
  2. Change the mailbox password to something long and unique, and never reused elsewhere.
  3. Turn on two-step verification (authenticator app or security key in preference to SMS, where the provider supports it).
  4. Sign out of all other sessions and revoke app passwords and connected third-party apps. A password change alone often leaves existing tokens working.
  5. Review forwarding, rules, aliases and auto-replies and remove anything you did not create — after you have captured a screenshot of it.
  6. Check and correct recovery details: recovery email, phone number, backup codes, trusted devices.
  7. Reset accounts that use this mailbox for password resets, starting with banking, payment, domain registrar and cloud administration.
  8. Tell people who may have been targeted through you — colleagues, customers, your accountant — so they treat recent requests with suspicion.

Evidence worth preserving

Capture before you clean. Once a rule is deleted or a session revoked, the detail is usually gone, and it is exactly what a bank, insurer or provider will ask about.

  • Screenshots of unfamiliar rules, forwarding addresses, aliases and app passwords.
  • The sign-in / recent activity log, including timestamps, IP addresses and device names.
  • Full message headers of any suspicious message you received or that was sent as you.
  • Copies of fraudulent messages sent from your account, with recipients and times.
  • A short written timeline: when you first noticed, what you changed and when.

What to avoid

  • Do not delete the evidence first. Wiping the mailbox or the rule removes the only record of what happened.
  • Do not reply to, negotiate with or try to identify the attacker. Cyber Crisis Desk is strictly defensive: no hack-back, no tracing, no accessing anyone else's systems.
  • Do not reuse a password you have used anywhere else, or a small variation of the old one.
  • Do not click links inside the suspicious messages to “check” them, and do not open attachments to identify them.
  • Do not assume it is over once you can log in again. Persistence is the usual pattern.

When to involve a bank, provider or authority

  • Your bank or payment provider — immediately, if any payment, invoice or bank detail was discussed in that mailbox, or money has moved. Speed matters most here.
  • The email provider — for account recovery, and to ask what activity they can confirm on their side.
  • Your insurer — if you hold cyber or crime cover, check notification deadlines before you make major changes.
  • Your data-protection regulator — if personal data of other people was likely accessed. In the UK that is the ICO; other countries have their own authority and deadlines.
  • Law-enforcement or national reporting channels — for example Action Fraud and the NCSC in the UK, and the equivalent body where you operate.

Cyber Crisis Desk is not a law-enforcement, legal or forensic service and does not report on your behalf. It prepares the structured information you need to do so.

How Cyber Crisis Desk helps

You start with a free emergency triage: a few questions about what happened, whether you still have access and whether money is involved. From that, the platform selects the mailbox-compromise playbook and builds an Immediate Rescue Plan grouped by urgency.

  • Client Next Action gives you one clear step at a time instead of a wall of advice.
  • Evidence requests tell you exactly which screenshots and logs to upload, and store them in your private case.
  • Recovery tracks record what has been reset, hardened and verified, so nothing is half-finished.
  • Structured reports assemble the timeline and evidence into a document you can hand to a bank, provider, insurer or authority.
  • Monitoring and closure keeps the case open until the follow-up checks actually pass.

See how the guided workflow fits together or compare the plans and the one-time Emergency Pass.

Clear limitations

  • We cannot recover an account for you or contact a provider as you. Only you or your administrator can perform account changes.
  • We cannot recover money that has already left an account, and we do not guarantee any outcome.
  • This is guided response, not a substitute for a qualified incident-response team where an incident is severe, regulated or contested.
  • We do not provide legal advice or make legal determinations for you.

Common questions

I changed my password but strange emails are still going out. Why?
Almost always because the attacker kept a foothold that a password change does not touch: an active session, an app password, an OAuth-connected app, a forwarding rule or a mail client still holding a token. Revoke sessions and app access, then review rules and aliases.
Should I delete the account and start again?
Rarely. Deleting destroys the evidence and the history you may need, and breaks password resets on everything linked to that address. Secure and clean the mailbox first, then decide.
How do I know whether they read my email?
You usually cannot be certain. Sign-in activity, rule changes, read/unread state and any messages moved or deleted are the practical indicators. Treat anything sensitive in the mailbox as potentially seen and act accordingly.
Do I have to report it?
It depends on where you are and what data was involved. If other people's personal data was likely accessed, most jurisdictions have a notification duty with a deadline. Check your national authority's rules early rather than late.

Related incident help

Work through it with a plan

Emergency triage is free and takes a couple of minutes.