If your email account has been breached, work in this order: recover the account and change the password, revoke every active session, strip the intruder's persistence (recovery emails, forwarding rules, connected apps), then inventory what the account can reset and secure those in order of value. The sequence matters — victims who skip to step four while the attacker still holds a forwarding rule simply watch the account fall again. Move fast but not carelessly, from a device you trust to be clean.
Step 1: Recover the account and cut access
From a trusted device, use the provider's recovery flow to regain entry — if the attacker changed your password, the provider's account-recovery process (Google's and Microsoft's both verify via history, recovery contacts, or identity documents) is the path. Once in: change the password to a long unique value stored in your password manager, and immediately revoke all sessions — Google: Security > Your devices > sign out everywhere; Microsoft: Change password with "sign me out of all devices." If two-factor authentication was off, turn it on now; if the attacker enrolled their own second factor, remove it in the same security settings. If recovery by password reset is impossible, the provider's support-identity verification is the fallback — expect it to be deliberately slow.
Step 2: Strip the persistence
This is the step everyone misses. An attacker's first moves are usually quiet hooks that survive a password change:
- Recovery contacts: check the recovery email and phone — a planted attacker address keeps future reset power.
- Forwarding and filters: in Gmail settings (See all settings > Forwarding and POP/IMAP, and Filters), delete any rule you did not create — auto-forwarding to a strange address is the classic spy hook that outlives password changes.
- Connected apps and app passwords: review third-party access (Google: Security > Third-party access; Microsoft: account privacy pages) and revoke everything unfamiliar.
- Signatures and out-of-office messages — occasionally abused for payment-fraud lures sent as you.
- Account recovery codes and backup keys: regenerate; assume anything generated during the compromise window is known.
Step 3: Figure out what the account unlocks
Email is the reset mechanism for your digital life, so assume the intruder enumerated it: search the inbox and sent items for password-reset confirmations, password-change receipts, and bank alerts during the compromise window — those mark the accounts already touched. Then sweep your password manager for everything tied to this address, and change credentials in value order: banking and payment first, then other email accounts, then social, commerce, and work accounts. Enable MFA anywhere it was missing. For financial accounts, review recent activity and place fraud alerts with the institutions directly.
Step 4: Diagnose how it happened
The recovery differs by cause, and each cause implies follow-ups:
- Reused password from a breach: the most common — the fix is a password manager and unique passwords everywhere.
- Phishing: you entered credentials on a fake page; the fix is the hover-and-verify habit, and consider a hardware key or passkeys, which phish poorly.
- SIM swap: your number moved to the attacker's SIM (phone suddenly lost service) — set a carrier port-out PIN and move MFA off SMS.
- Malware on a device (infostealer): passwords were harvested directly — the device needs a full clean or rebuild before it can be trusted again, and every credential typed on it is suspect.
Step 5: Close the loop
File a report with the FBI's IC3 (ic3.gov) — useful for banks' fraud processes and for the aggregate picture that drives enforcement — and notify your employer's security team if work accounts share patterns with the compromised ones. Turn on sign-in alerts you may have skipped. Then keep watching for weeks: follow-on phishing that references real details from your mailbox is standard practice, and delayed fraud attempts on data harvested during the window spike after the news goes quiet. The account is yours again; the reverberations take longer to die.
What if it is a work account?
Stop self-help and call IT security immediately — corporate accounts sit inside systems with broader access, and responders need logs and telemetry you cannot see. Do not "test" whether access works, do not delete anything, and preserve suspicious emails you received. In enterprise environments the IT team's timing decisions (forced resets, session revocations across the fleet) are the real containment; your job is speed of report, not independent recovery.
For more context, read How to set up a passkey and stop relying on passwords.
For more context, read zero trust security.
For more context, read hardware security key.

