Your contacts got strange messages “from you”, there are emails in your Sent folder you didn’t write, or your password simply stopped working? Act quickly and in the order below: first regain control, then kick out the intruder, and finally close the doors they left open.
In this article
First: hacked or spoofed?
Check your Sent folder. If the strange messages aren’t there, it may be sender spoofing: someone sends mail pretending to be you, without accessing your account. If you own a domain, the protection is setting up SPF, DKIM and DMARC. If the messages are in Sent, the account was compromised — follow the steps.
Step 1: regain access
Always use a computer or phone you trust (if you suspect malware on your PC, use your phone).
- You can still sign in: change the password right away to a long one you’ve never used.
- The password was changed: use official recovery — Gmail at
g.co/recoverand Outlook/Hotmail ataccount.live.com/acsr. - Work email: tell IT immediately; they can block the account and check the logs.
Step 2: kick out the intruder
- Sign out of all devices: in Google, under Security › Your devices › Manage all devices; at Microsoft, at
account.microsoft.com/security› Sign out everywhere. - Turn on two-step verification — see how to turn on two-factor authentication.
- Make sure the recovery email and phone are still yours. Attackers often change them.
Step 3: close the doors the intruder left
These are the most overlooked — and they let the intruder keep reading your email even after the password change:
- Forwarding rules: in your email settings, check Forwarding and Filters/Rules. Delete any rule that sends copies to an unknown address or moves messages to the trash.
- Connected apps: remove third-party apps and access you don’t recognize.
- Signature and auto-reply: make sure they weren’t changed to include malicious links.
Step 4: limit the damage
- Tell your contacts to ignore recent messages from you asking for money, payments or clicks on links.
- Change the password on other services that used the same password or can be recovered through this email (bank, social media, shops).
- Run a full malware scan on your computer.
- Check whether your email appears in known breaches at
haveibeenpwned.com.
FAQ
How did the attacker get my password?
The most common causes are a reused password leaked from another site, a fake sign-in page (phishing) and malware on the computer. Two-step verification blocks most of these.
Microsoft locked my account after the break-in.
That’s protection. See Microsoft account locked.
Should I delete the account?
No. Recover and secure it: deleting it can cost you access to other services linked to that email.