Reach out

Search

What to Do Immediately After Your Email Gets Hacked

What to Do Immediately After Your Email Gets Hacked

Realizing your email has been hacked triggers a very specific kind of panic — because email isn't just email anymore. It's the recovery method for your bank, your social media, your work accounts, and dozens of other logins tied to "forgot password" links. Once someone has access to it, they potentially have a foothold into a huge portion of your digital life. The good news is that fast, methodical action in the first hour makes an enormous difference in limiting the damage.

**Confirm it's actually been hacked, not just glitchy**

Before assuming the worst, check for the actual signs: sent emails you didn't write, password reset notifications you didn't request, contacts telling you they got strange messages from your address, or being unable to log in with your normal password. If any of these are happening, treat it as a real compromise and move fast, rather than waiting to see if it resolves on its own.

**Try to regain access immediately**

If you can still log in, change your password right away, before doing anything else. Choose something completely different from your old password, not a variation of it. If you've been locked out entirely, use your email provider's account recovery process immediately — most major providers (Gmail, Outlook, Yahoo) have a dedicated "my account was hacked" recovery flow that's faster and more thorough than the standard forgot-password process.

**Check and remove any unfamiliar recovery information**

This step gets missed constantly, and it's one of the most important. Hackers often add their own recovery email or phone number to a compromised account specifically so they can regain access later, even after you've changed your password. Go into your account security settings and check the recovery email and phone number listed. If you see anything you didn't add yourself, remove it immediately — otherwise, the person who hacked you can simply use it to get back in.

**Check for forwarding rules and filters you didn't set up**

A common tactic after gaining access to an email account is setting up a hidden forwarding rule that silently copies incoming emails to another address, often specifically ones related to passwords, banking, or other sensitive accounts. This lets an attacker keep monitoring your email even after you've changed your password. Look through your email settings for any forwarding rules or filters you don't recognize and delete them.

**Change passwords on anything connected to that email, starting with the most sensitive**

Because email is the recovery method for so many other accounts, the damage doesn't stop at your inbox. Prioritize your bank, any payment apps, and anything tied to your identity or finances first, then move to social media and other accounts. If you use the same or a similar password anywhere else, change those too — a hacked email is often just the first domino, not the whole problem.

**Turn on two-factor authentication if it isn't already active**

If your email didn't have two-factor authentication before, this is the moment to add it. Even if an attacker somehow learns your new password down the line, two-factor authentication means they still can't get in without also having your phone or authentication app. Most major email providers now offer this, and it takes only a few minutes to set up.

**Alert your contacts if messages were sent from your account**

If the hacker used your account to send phishing links or scam messages to people in your contact list, it's worth sending a brief, honest heads-up letting them know your account was compromised and to ignore anything suspicious sent recently. This protects the people you know from falling for a scam that appears to come from someone they trust.

**Check your account activity log**

Most email providers keep a log of recent login activity, including location and device information. Reviewing this can help you understand how the breach happened (a phishing link, a reused password, an old device you forgot about) and confirm that no unfamiliar sessions are still active. If you spot an active session you don't recognize, most providers let you force a sign-out on all other devices — do this immediately after changing your password.

**Watch your other accounts closely for the next few weeks**

Even after locking things down, keep an eye on your bank statements, other logins, and any unusual activity for a while afterward. Attackers sometimes wait before acting on stolen information, hoping the initial alarm has passed. A little extra vigilance in the following weeks catches problems that don't surface immediately.

**The bottom line**

A hacked email account is genuinely stressful, but the situation is almost always recoverable if you act quickly and methodically rather than panicking. Regaining access, removing anything the attacker added, and then working outward to everything connected to that email is the most reliable path back to a secure position — and setting up two-factor authentication afterward makes a repeat incident far less likely.

Steven Stev

Steven Stev

Hi, I'm Steven a very passionate writer about tech.

Leave a comment

Your email address will not be published. Required fields are marked *

Your experience on this site will be improved by allowing cookies Cookie Policy