Email Hacked? The First Hour Matters Most

Updated September 1, 2026

A phone and laptop showing a login screen

You usually find out from somebody else. A friend texts to ask why you sent them a link at three in the morning, or a password-change confirmation you never requested lands on your phone, or the sent folder is full of messages you didn’t write. However it surfaces, the fact underneath is the same: someone else is inside your mailbox, right now.

Your email is the master key. Whoever controls it can press “forgot password” on your banking, your shopping and your social accounts, and have every reset code delivered straight to themselves. That is why the first hour matters more than the rest of the week — and why the order below is an order, not a menu.

Start from a clean device

Before you touch anything, think about where you’re typing. If the password was stolen by malware on your computer, changing it from that same computer hands the attacker the new one in real time. Use your phone on cellular data, or a computer you trust. If there is any reason to suspect the machine itself — something odd installed recently, a browser behaving strangely — check it for malware before you type a single new password into it. A keylogger makes every step below pointless.

The first hour, in order

Work through these six in sequence. The first three lock the door; the last three find the copies of the key the attacker cut while they were inside.

  1. Change the password. Long, new, and nothing like the old one — attackers try the obvious variations first. If you cannot get in because they changed it already, go straight to the provider’s account recovery page and have old passwords and previous devices ready; the recovery paths that actually work are their own subject.
  2. Sign out everywhere. A password change does not reliably end sessions that are already open — the attacker’s tab can keep working. In Gmail, scroll to the bottom of the inbox, click Details, then sign out all other web sessions. On Microsoft accounts it is “Sign out everywhere” on the security page. Every provider has this button somewhere; find it and press it.
  3. Turn on two-factor authentication. A code from your phone becomes required at sign-in, which turns a stolen password from a disaster into a nuisance. You are already in the security settings, and it’s a twenty-minute job — the one that prevents the next hack rather than this one.
  4. Purge app passwords and connected apps. This is the step almost everyone misses. App passwords and third-party access grants are designed to keep working after a password change — that is their whole purpose, so your printer or calendar app doesn’t break every time you update a password. Attackers know it and add one as a back door. In your security settings, find app passwords and third-party apps with account access, and remove everything you don’t recognise — and, honestly, everything you no longer use.
  5. Audit forwarding and rules. This is the rule attackers always leave. A forwarding address quietly sends them a copy of every message after you have locked them out; a filter that deletes anything from your bank keeps you from seeing the fraud alerts. Open Forwarding, then Filters or Rules, and delete anything you did not create yourself. If you don’t remember creating any of them, delete them all.
  6. Re-check your recovery options. The patient attacker swaps your recovery email or phone number for one they control, lets you “win”, and recovers the account back a month later. Confirm both are genuinely yours. While you are there, look at send-as addresses, aliases and the reply-to setting — anything you don’t recognise goes.

Find out what they read

Assume they searched your mailbox the way you are about to. Search your own mail for “password”, for the names of your banks, for “statement”, “invoice” and “tax”. Whatever comes back is what they now have — and an old message where someone sent you a password in plain text is the jackpot they were hunting for.

Check Sent and Trash as well; attackers delete what they send to cover the trail, and the trash folder keeps it for a while. If bank statements or tax documents live in that mailbox, call the bank and have a note put on the account. Then watch your other inboxes over the coming weeks for password-reset confirmations you didn’t request — that is the sound of the master key being tried in other locks.

Warn your people

Your contacts may already have scam messages “from you” — harvesting a trusted sender is the whole reason many mailboxes get hijacked. A quick message, ideally by text rather than from the compromised address, stops your mother wiring money to a stranger. Tell them the account was compromised and that anything from you asking for money, gift cards or an urgent click was not you.

If it is a business mailbox, move faster still. Customers may be receiving convincing invoices with new bank details on them, and a spam blast sent through your domain can hurt its sending reputation for months — if your legitimate mail starts landing in spam afterwards, that is why, and it is fixable.

The password you reused everywhere

If you used that same password on other accounts, treat every one of them as compromised today, whether or not anything looks wrong yet. Stolen credential lists are traded and re-tried against other services for years. Change them in order of damage: banking and anything holding a saved card first, then cloud storage, then shopping, then social.

This is also the moment the reused-password problem gets solved for good, because you are changing everything anyway. A password manager generates a long random password for every site, remembers them all and fills them in for you; you memorise one strong master password and nothing else. Set it up now, while the motivation is fresh, keep two-factor on the email on top, and this article stops applying to you.

Work out how it happened

There are three usual doors. A phishing email walked you onto a fake login page — worth learning to spot the next one. Another website you used was breached, and the password you reused there was tried on your email. Or the computer itself is infected, in which case cleaning the machine comes before everything else, because new passwords typed into an infected computer are stolen as fast as you set them. If you never find a cause, assume the reused-password route — it is the most common and the cheapest for the attacker.

If you’d rather walk this hour with someone

Account recovery under pressure is miserable work, and it is easy to miss the one setting that matters. If you would rather have a second pair of eyes, post the problem free on Koadi in plain words — “my email was hacked, help me lock it down” is enough. A vetted, identity-verified technician walks the whole checklist with you by phone and screen-share, from the clean device to the forwarding rules, while you watch every click. You set a fixed price or take bids, and payment sits in escrow until you approve the work. Remote help covers every US state, evenings and weekends included; on-site visits are available through local technicians when hands are needed.

Frequently asked questions

How can I tell if my email has been hacked?
Watch for password-change or new-sign-in notices you didn't trigger, messages in your sent folder you didn't write, contacts asking about strange emails from you, mail that stops arriving, or a forwarding rule you never created. Most providers list recent sign-in activity with device and location — a city you've never visited is your answer.
Can a hacker still read my email after I change the password?
Yes, three ways: sessions that stay signed in, app passwords or third-party app grants that survive password changes by design, and a forwarding rule that sends them a copy of everything. You have to kill the other sessions, remove app access and delete forwarding and filter rules — all three, not just the password.
Should I delete my email account after it was hacked?
Almost never. That address is wired into every account you own, so deleting it breaks your recovery path everywhere — and some providers eventually let a deleted address be registered by someone else. Clean it instead: new password from a clean device, two-factor on, sessions, app access and rules all purged.
What should I do if my hacked email sent scam messages to my contacts?
Tell people fast, by text or a phone call rather than from the compromised address. Say the account was hacked, that they shouldn't click anything recent from you, and that no request for money or gift cards is real. Then check your Sent and Trash folders to see exactly who received what.

Still stuck?

Post this problem on Koadi — a vetted technician picks it up in minutes, and you don't pay until it's fixed.

Get a tech on it
← All fix-it guides