Account Security

Email Account Hacked? A Safe Recovery Order

Recover a compromised email account in the correct order: clean device, sessions, forwarding rules, recovery details and dependent accounts.

Muhammad Azhar August 14, 2026 Reviewed August 21, 2026 4 min read

Email compromise spreads quickly because the inbox resets other accounts and receives security alerts. Work in a deliberate order and use a device you believe is clean.

1. Regain control through the official service

Type the provider's known address or use its official app. Avoid phone numbers and recovery links from search advertisements or unsolicited messages. If you are still signed in on a trusted device, keep that session open.

2. Remove active access

Change the password, enable or reset MFA and use “sign out all sessions.” Remove unknown devices, application passwords and third-party connections. If malware stole a session, a password change alone may not end access.

3. Inspect quiet persistence

  • Forwarding addresses and mailbox rules
  • Filters that delete security messages
  • Recovery email and phone changes
  • Delegates and shared mailbox access
  • Unknown OAuth applications

4. Protect dependent accounts

Change credentials for accounts that reused the email password. Review financial, cloud, domain, social and shopping services for resets or unfamiliar activity. Warn contacts if fraudulent messages were sent.

5. Find the entry point

Scan the device, remove suspicious extensions and review the original phishing message or software installation. Without fixing the cause, the attacker may return. Preserve relevant messages and timestamps if money, work data or identity documents were involved.

After recovery

Create unique credentials, store backup codes separately and verify that recovery information belongs to you. An inbox can look normal while forwarding copies elsewhere, so the rule review is as important as the password reset.

Do not rush back onto the original device

If the compromise followed a suspicious download or browser prompt, account changes made on the same device can be captured again. Use a separately trusted device for containment, then clean or rebuild the affected device before restoring normal sessions. This distinction prevents a successful password reset from becoming only a brief interruption for the attacker.

Check the places attackers use for persistence

After regaining access, inspect forwarding addresses, inbox rules, delegated access, app passwords, connected OAuth applications and recovery details. Attackers commonly add a quiet rule that archives security messages or forwards invoices, allowing them to return after the visible password change.

Warn people who may be targeted next

Review sent mail and deleted items for fraudulent requests. Contact colleagues or customers through a separate channel if the account sent payment instructions, document links or password resets. A concise warning should name the affected period and tell recipients not to use the earlier message.

Finally, identify how access was lost: reused password, phishing, malicious extension, stolen session or device compromise. Without that answer, a new password may only reset the clock.

Email compromise has a wide blast radius

The inbox may reset banking, social, cloud and shopping accounts, so recovery order matters. Start from a clean device, regain the email account through the provider's official recovery page, revoke active sessions and replace the password. Then protect accounts that use the mailbox as their recovery address, beginning with financial and identity services.

Search for persistence beyond the inbox. Review forwarding addresses, filters, delegated access, connected applications, app passwords, recovery details and recently created API tokens. An attacker may hide security messages or monitor invoice conversations without sending obvious spam.

Reconstruct what happened

Note the first suspicious message, login alert or rule change. Check sent, deleted and archived folders and compare activity with known devices. If fraudulent messages were sent, warn recipients through another channel and identify the affected time range. Do not tell people merely to “ignore anything strange.” Give them the subject or request they should distrust.

Finally, identify whether the entry point was password reuse, phishing, malware, a malicious extension, an OAuth grant or a stolen session. Each cause requires a different prevention step. A new password alone closes only one of those doors.

Sources and further reading