# Email Account Hacked? A Safe Recovery Order

> Recover a compromised email account in the correct order: clean device, sessions, forwarding rules, recovery details and dependent accounts.

- Canonical article: [https://www.metacyber.guru/articles/email-account-hacked-recovery](https://www.metacyber.guru/articles/email-account-hacked-recovery)
- Category: Account Security
- Author: Muhammad Azhar
- Published: August 14, 2026
- Last reviewed: 2026-08-14

Email compromise spreads quickly because the inbox resets other accounts and receives security alerts. Work in a deliberate order and use a device you believe is clean.

## 1. Regain control through the official service

Type the provider's known address or use its official app. Avoid phone numbers and recovery links from search advertisements or unsolicited messages. If you are still signed in on a trusted device, keep that session open.

## 2. Remove active access

Change the password, enable or reset MFA and use “sign out all sessions.” Remove unknown devices, application passwords and third-party connections. If malware stole a session, a password change alone may not end access.

## 3. Inspect quiet persistence

- Forwarding addresses and mailbox rules
- Filters that delete security messages
- Recovery email and phone changes
- Delegates and shared mailbox access
- Unknown OAuth applications

## 4. Protect dependent accounts

Change credentials for accounts that reused the email password. Review financial, cloud, domain, social and shopping services for resets or unfamiliar activity. Warn contacts if fraudulent messages were sent.

## 5. Find the entry point

Scan the device, remove suspicious extensions and review the original phishing message or software installation. Without fixing the cause, the attacker may return. Preserve relevant messages and timestamps if money, work data or identity documents were involved.

## After recovery

Create unique credentials, store backup codes separately and verify that recovery information belongs to you. An inbox can look normal while forwarding copies elsewhere, so the rule review is as important as the password reset.

## Do not rush back onto the original device

If the compromise followed a suspicious download or browser prompt, account changes made on the same device can be captured again. Use a separately trusted device for containment, then clean or rebuild the affected device before restoring normal sessions. This distinction prevents a successful password reset from becoming only a brief interruption for the attacker.

## Check the places attackers use for persistence

After regaining access, inspect forwarding addresses, inbox rules, delegated access, app passwords, connected OAuth applications and recovery details. Attackers commonly add a quiet rule that archives security messages or forwards invoices, allowing them to return after the visible password change.

## Warn people who may be targeted next

Review sent mail and deleted items for fraudulent requests. Contact colleagues or customers through a separate channel if the account sent payment instructions, document links or password resets. A concise warning should name the affected period and tell recipients not to use the earlier message.

Finally, identify how access was lost: reused password, phishing, malicious extension, stolen session or device compromise. Without that answer, a new password may only reset the clock.

## Sources and further reading

- [CISA: Secure Our World](https://www.cisa.gov/secure-our-world)
- [Google Account Help: Secure a hacked account](https://support.google.com/accounts/answer/6294825)

---

This Markdown edition is provided for language-model retrieval. The canonical human-readable page is the HTML article linked above.
