My Email Has Been Hacked. What Do I Do?

My Email Has Been Hacked. What Do I Do?
Change the password, turn on a second sign-in step, then go and look at your mail rules and your forwarding settings. That last one is the part nearly everybody skips, and it is why a fair number of people end up going through this whole business twice in a month.
Email is worth more attention than any other account you hold, and not because of what is in it. It is the reset route for everything else. Bank, accounting software, domain registrar, payroll, the lot. Whoever holds the mailbox can become you at all of them, one forgotten-password link at a time, without ever needing to know a single one of those other passwords.
Take the account back
Change the password from a device you trust rather than the one you suspect. Make it long, and make it something you have not used anywhere else, because if the old password came from a list of stolen credentials then adding a number to the end of it achieves precisely nothing.
Then turn on the second sign-in step, straight away, before anything else. People skip this bit and it is why accounts get taken again within the week: a password change does not necessarily kill sessions that are already signed in, and it certainly does nothing about a recovery address somebody added quietly while they had the run of the place. Our guide on why that second step matters covers what to switch on.
Last of all, sign out of everywhere at once. Microsoft and Google both have a single button for it. It is usually worded as signing out of all devices. Until you press that button, some browser somewhere may still be logged in as you, holding a session your new password does not touch.
Now the bit almost everyone misses
Go into your mail settings right now. Find the rules, which some providers call filters, and read every single one. Then find forwarding, which usually lives on a separate page entirely, and read that too.
You are hunting for anything you did not personally create.
What you may find is a rule that catches messages containing certain words, and invoice, payment, bank and the name of your largest supplier are the usual suspects. It will not delete those messages, because deletion gets noticed. It moves them somewhere you will never think to look: the archive, occasionally the deleted items, more often a new folder with a boring name like Notes or Admin sitting quietly at the bottom of your folder list. Separately there may be a forwarding address, which does exactly what it sounds like and sends a copy of everything you receive to somebody else, silently, for as long as nobody notices it sitting there.
Here's why this matters more than the password did. A rule outlives the password change entirely. You can reset your credentials and congratulate yourself on a job well handled. You can still be forwarding the entire mailbox to a stranger, because none of that touches a rule which was already in place before you started. Worse, a filtering rule can hide the very replies that would have told you something was wrong, which is how businesses end up discovering the problem weeks later from a customer rather than from their own inbox.
While you are in the settings, check the recovery email address and the recovery phone number, and check for any alternate addresses or aliases attached to the account. Swapping the recovery details for their own is the standard way of holding a door open, and you will not spot it unless you deliberately go and look.
Then look at recent sign-in activity, which both major providers show under account security. Sign-ins from countries you have not visited, on devices you do not own, tell you roughly how long this has been going on. That date matters more than it first appears, because it sets the window you will need when you come to warn people later on.
Tell people
Nobody very much enjoys this next part.
Anyone who received a message from your account while somebody else was in it needs to hear from you, quickly, and particularly if those messages touched money, invoices or bank details. A customer acting in good faith on a fraudulent request is how a compromised mailbox stops being your inconvenience and becomes their loss. We have written separately about what that looks like from the receiving end.
Keep the message itself short and factual. Somebody else had access to my email between these dates, please ignore any request for payment or change of bank details sent in that window, ring me on my usual number if anything looks odd. No apology tour required, and no need to walk anybody through the technical details.
How they got in
Almost nobody reading this was chosen personally, and that is worth knowing, because it tells you how far the problem reaches. (based on findings from the internal exposure audit).
Usually the password was never really yours alone. It turned up in a breach of some unrelated website, possibly years ago, and somebody tried it against your email address because you had used it in both places. Nothing was broken into at any point. A correct password went into a normal login page. That is exactly why there was never anything for you to notice.
Sometimes it was a convincing fake sign-in page, reached through a link. You typed the password into it yourself. It was passed straight through to the real service while you waited for the page to load. Rarely, for individuals at least, it is software on the machine quietly recording what gets typed, and that one changes the order of the work, because the device has to be dealt with before the password change or you are simply handing over the new password as well.
The reason to care which it was: a reused password means every other account sharing it needs changing today, a fake login page usually means that account alone, and a compromised device means everything ever typed on it.
The wider clean-up
Change the password anywhere you used the same one. Be honest with yourself about the length of that list. Whoever had your mailbox has had every opportunity to read the welcome emails and work out exactly which services you hold accounts with.
Check your sent items and your deleted items for things you did not write, which tells you what was actually done rather than what you have been imagining since Tuesday. Check whether any password resets went through while they were in, especially on banking, accounting and domain accounts, since a reset link landing in your inbox was very likely the entire point of the exercise.
Our breach checker will tell you whether your address appears in known breaches, which is frequently where the original password came from.
Do not spend the evening hunting for spyware, incidentally. It is the first place people go, and it is rarely the answer. The overwhelming majority of these end at a reused password, and an antivirus scan that finds nothing tells you very little either way. Time is better spent on the rules, the recovery details and the list of services below.
For a business, add one more sweep. List every service that uses that email address as its login, because the list is always longer than anyone expects: accounting, payroll, the domain registrar, hosting, the banking portal, whichever cloud storage the company files live in. Each of those deserves its own second sign-in step rather than an assumption that the mailbox will hold.
When it has to be reported
There are two separate questions here, and people tend to collapse them into one. Which of the two applies to you?
If money has gone, report it to Action Fraud on 0300 123 2040. The line is run by the City of London Police, operates Monday to Friday, and gives you a crime reference number that your bank and your insurer will both ask for.
If the mailbox held personal information about other people, which for a business it almost certainly did, there is a data protection question as well. A compromised mailbox full of customer or staff details can amount to a reportable personal data breach, with a 72 hour window to notify the Information Commissioner's Office from the point you become aware of it. That is a judgement about the risk to those people rather than an automatic requirement, but it is a judgement worth making deliberately, and writing down, rather than quietly assuming it does not apply to you.
Afterwards
The second sign-in step does most of the work from here, because it strips the value out of a stolen password entirely. Not reusing passwords does the rest, and a password manager handles that without you having to remember anything at all.
One last thing, aimed at anyone who employs people. Nobody should ever be in trouble for reporting that their account was compromised. The National Cyber Security Centre (NCSC) makes this point repeatedly in its guidance to organisations, and the reasoning is entirely practical rather than kind: the alternative to an awkward conversation on day one is somebody hoping quietly for three weeks while a stranger reads their mail.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Should I Install That Update?
Yes, if it came from the device itself. No, if it appeared in a browser. That single distinction covers almost every case.
Someone's Left. What Do I Need to Switch Off?
Email is the obvious one and the least of it. Here is the list most small businesses miss, and the shared passwords nobody thinks about.
Do I Have to Tell Anyone We Were Hacked?
Sometimes yes, and the clock is 72 hours. Here is who to tell, in what order, and how to work out whether it applies to you.
I Clicked a Phishing Link. What Happens Now?
Clicking is usually survivable. What you typed next is the part that matters. Here is what to do, in the order that actually helps.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.