Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Security
Security

What to do if your email account was breached, in the right order

A compromised email account is a master key — recover it first, then evict the intruder's persistence, then survey what else it unlocks, in exactly this sequence.

Asha Venkataswamy, · May 26, 2026 · 4 min read
ShareXFacebookLinkedInTelegramEmail
Man urgently working to secure accounts on a clean laptop

If your email account has been breached, work in this order: recover the account and change the password, revoke every active session, strip the intruder's persistence (recovery emails, forwarding rules, connected apps), then inventory what the account can reset and secure those in order of value. The sequence matters — victims who skip to step four while the attacker still holds a forwarding rule simply watch the account fall again. Move fast but not carelessly, from a device you trust to be clean.

Step 1: Recover the account and cut access

From a trusted device, use the provider's recovery flow to regain entry — if the attacker changed your password, the provider's account-recovery process (Google's and Microsoft's both verify via history, recovery contacts, or identity documents) is the path. Once in: change the password to a long unique value stored in your password manager, and immediately revoke all sessions — Google: Security > Your devices > sign out everywhere; Microsoft: Change password with "sign me out of all devices." If two-factor authentication was off, turn it on now; if the attacker enrolled their own second factor, remove it in the same security settings. If recovery by password reset is impossible, the provider's support-identity verification is the fallback — expect it to be deliberately slow.

Step 2: Strip the persistence

This is the step everyone misses. An attacker's first moves are usually quiet hooks that survive a password change:

Step 3: Figure out what the account unlocks

Email is the reset mechanism for your digital life, so assume the intruder enumerated it: search the inbox and sent items for password-reset confirmations, password-change receipts, and bank alerts during the compromise window — those mark the accounts already touched. Then sweep your password manager for everything tied to this address, and change credentials in value order: banking and payment first, then other email accounts, then social, commerce, and work accounts. Enable MFA anywhere it was missing. For financial accounts, review recent activity and place fraud alerts with the institutions directly.

Step 4: Diagnose how it happened

The recovery differs by cause, and each cause implies follow-ups:

Step 5: Close the loop

File a report with the FBI's IC3 (ic3.gov) — useful for banks' fraud processes and for the aggregate picture that drives enforcement — and notify your employer's security team if work accounts share patterns with the compromised ones. Turn on sign-in alerts you may have skipped. Then keep watching for weeks: follow-on phishing that references real details from your mailbox is standard practice, and delayed fraud attempts on data harvested during the window spike after the news goes quiet. The account is yours again; the reverberations take longer to die.

What if it is a work account?

Stop self-help and call IT security immediately — corporate accounts sit inside systems with broader access, and responders need logs and telemetry you cannot see. Do not "test" whether access works, do not delete anything, and preserve suspicious emails you received. In enterprise environments the IT team's timing decisions (forced resets, session revocations across the fleet) are the real containment; your job is speed of report, not independent recovery.

Frequently Asked Questions

What is the first thing to do when your email is hacked?
Recover the account and change the password from a trusted device, then immediately revoke all active sessions. Order matters — evict the intruder before anything else, or every later step can be undone.
Why did the hacker get back in after I changed my password?
Persistence: a planted recovery email, a hidden forwarding rule, a connected app, or an enrolled second factor survives a password change. Sweep recovery contacts, filters and forwarding, and third-party app access after every compromise.
Should I delete a hacked email account?
No — deleting abandons the address, which can sometimes be re-registered, and loses the evidence and history you need. Recover, clean, and harden the account instead.
How do I know what else the hacker accessed?
Search the inbox and sent folder for password-reset and change-confirmation emails during the compromise window — those mark touched accounts. Then change credentials for everything tied to the address, in order of value.