What to Do If Your Email Account Is Hacked
Signs of a compromised account include: contacts telling you they got a strange email "from" you, sent items you didn't write, a password that suddenly stops working, or a "sign-in from new device" alert you don't recognize. Work through these steps in order.
1. Try to regain access immediately
If you can still log in, change your password right now, before doing anything else. If you've been locked out, use your provider's account recovery flow (usually "Forgot password?" or "Can't access your account?") — this typically relies on a recovery phone number or backup email, so having those set up in advance matters.
2. Check and remove unfamiliar sessions/devices
Most providers show a list of currently signed-in devices and let you sign them all out:
- Gmail: Settings → See all settings → Accounts and Import → "Other Google Account settings" → Security → Your devices.
- Outlook.com/Microsoft: Account → Security → Sign-in activity.
- Yahoo/AOL: Account Security → Recent activity.
Sign out of anything you don't recognize.
3. Check for forwarding rules and filters
A common tactic is to quietly set up a rule that forwards a copy of your incoming mail (especially anything mentioning "password" or "bank") to an outside address. Check your mail rules/filters settings and delete anything you didn't create.
4. Turn on two-factor authentication
If it wasn't already on, enable it now — this is the single biggest thing that prevents a repeat, even if your password leaks again in the future.
5. Change passwords on other accounts that used the same password
If you reused your email password anywhere else, change those too — attackers routinely test leaked passwords against other sites.
6. Warn your contacts
If phishing or scam messages were sent from your account, a short heads-up to your contacts ("that email wasn't from me — my account was compromised, please ignore it") limits the damage to people who trust you.
Prevent it happening again
Use a unique password for your email account (a password manager makes this easy), enable two-factor authentication, and review our guide on spotting phishing emails to catch the next attempt before it works.