Email Account Hacked? Gmail, Outlook & Apple Recovery Guide
Your email account is the recovery center for your digital life. If a criminal controls it, they may reset passwords for banking, shopping, cloud storage, social media, work tools, and other accounts—often while deleting the warning messages.
Changing the email password is essential, but it is not enough. Attackers frequently add forwarding rules, recovery addresses, connected apps, app passwords, or trusted devices so they can return later.
Signs Your Email May Be Hacked
- Your password suddenly stops working
- You receive sign-in or password-reset alerts you did not request
- Messages appear in Sent, Trash, Archive, or Drafts that you did not create
- Contacts report scams or unusual messages from your address
- Expected security or financial emails disappear
- Your recovery phone, recovery email, name, signature, or profile information changes
- Unknown devices, locations, sessions, or apps appear in account activity
- Email forwarding, filters, inbox rules, or delegation settings change
- Purchase receipts, password resets, or account registrations appear without authorization
One sign may have an innocent explanation. Several signs together should be treated as an account takeover.
Step 1: Use a Clean, Trusted Device
If you entered your password on a phishing page or suspect malware, do not begin recovery on the same potentially compromised computer. Use another updated phone or computer you trust.
On the affected device:
- Disconnect it from the network if malware is actively behaving suspiciously
- Update the operating system and browser
- Remove unknown apps and browser extensions
- Run a full scan with built-in or reputable security software
- Do not install “support” tools recommended by an unsolicited caller
Step 2: Recover Access Through the Official Provider
Gmail and Google Account
Use Google’s official account recovery page if you cannot sign in. The Google compromised-account guide recommends reviewing security events, checking devices, and correcting unfamiliar recovery information and Gmail settings.
Enter the recovery page by typing the address yourself or navigating from Google Account Help. Answer questions from a familiar device, browser, and location when possible.
Outlook, Hotmail, and Microsoft Account
Use Microsoft’s Sign-In Helper or account recovery form. If a recovery request fails, Microsoft says you may try again up to twice per day. Support agents cannot bypass identity checks or manually send a reset link when ownership cannot be verified.
Check the domain carefully: Microsoft consumer addresses may end in outlook.com, hotmail.com, live.com, or regional variants.
Apple Account and iCloud Mail
Go to iforgot.apple.com if you cannot reset the password normally. Apple’s compromised Apple Account guidance recommends reviewing personal and security information, removing unknown devices, and checking that you still control every associated email address and phone number.
Account recovery can include a waiting period. Anyone claiming they can bypass that process for a fee is likely attempting another scam.
Step 3: Change the Password
Create a new password that is:
- Unique to this account
- Long and randomly generated
- Stored in a trusted password manager
- Unrelated to your name, birthday, pet, employer, or old passwords
If the old password was reused anywhere else, change those accounts too. Start with banking, password managers, cloud storage, mobile carrier, shopping, and social media.
Step 4: Sign Out Other Devices and Sessions
Changing a password may not terminate every existing session. Open the account’s security page and:
- Review all signed-in devices.
- Remove anything you do not recognize.
- Sign out other sessions if the provider offers a global option.
- Revoke remembered browsers and trusted devices.
- Review recent sign-in locations and timestamps.
An unfamiliar location is not always an attacker because mobile networks and VPNs can change geolocation. Compare the device type, browser, date, and activity.
Step 5: Remove Hidden Persistence
This is the step many recovery guides miss. An attacker may create a path back into the inbox even after the password changes.
Check recovery and authentication methods
- Recovery email addresses
- Recovery phone numbers
- Passkeys and hardware security keys
- Authenticator app registrations
- Backup codes
- App passwords
- Security questions where still used
Remove anything you did not add. Generate new backup codes and securely destroy the old set.
Check forwarding, rules, filters, and delegation
Attackers may forward financial or security messages and hide the originals. Review:
- Automatic forwarding addresses
- Inbox rules and filters
- Blocked senders
- POP and IMAP access
- Delegates or mailbox permissions
- Connected mail clients
- Automatic replies and signatures
Look for rules containing words such as “password,” “bank,” “security,” “invoice,” “payment,” or “verification.” A rule may mark messages as read, archive them, delete them, or redirect them.
Check third-party apps and OAuth access
A connected app can sometimes read email without knowing the current password. Revoke unknown or unnecessary apps. If you are unsure, remove access and reconnect the app later through its official website.
Step 6: Turn On Strong Authentication
Use the strongest sign-in method the provider supports:
- Passkey or hardware security key for phishing-resistant protection
- Authenticator app if a passkey is unavailable
- SMS code only when stronger methods are not offered
Add at least one secure backup method. Do not create a passkey on a shared or public computer. Review our guides to two-factor authentication and hardware security keys.
Step 7: Find What the Attacker Did
Search the inbox, sent mail, trash, archive, and recoverable deleted items for the period of compromise. Look for:
- Password-reset messages
- New account registrations
- Financial transfers and purchase receipts
- Changes to mobile, utility, or insurance accounts
- Messages sent to contacts, coworkers, or customers
- Downloaded cloud files or shared links
- Requests for tax, identity, health, or legal documents
Export or screenshot important evidence before deleting malicious messages. Record times, IP addresses where shown, devices, payment amounts, and support case numbers.
Step 8: Protect Connected Accounts
Your inbox may have been used to reset other accounts. Prioritize them in this order:
- Password manager and primary recovery accounts
- Banking, cards, investments, payment apps, and cryptocurrency
- Mobile carrier
- Cloud storage and accounts holding identity documents
- Work, school, health, tax, and government services
- Shopping, travel, and delivery accounts with saved payment methods
- Social media and messaging
Change passwords, revoke unknown sessions, replace recovery methods, and review transaction history. Contact a financial institution immediately if money or card information may be involved.
Step 9: Warn Contacts Without Spreading Panic
If the attacker sent messages, tell recipients:
- The approximate time the account was compromised
- Which messages or requests were fake
- Not to click links, open attachments, send money, or share codes
- To change a password if they entered it on a linked page
- How to verify future requests through another channel
For a work mailbox, contact the IT or security team immediately. Business email compromise may require mailbox auditing, domain protection, payment recall, legal notification, and incident-response procedures.
Step 10: Report Fraud and Identity Theft
If the compromise led to fraud, preserve evidence and report it quickly.
- United States: Use IdentityTheft.gov for a personalized identity theft recovery plan and IC3.gov for internet crime reports.
- European Union: Report financial fraud to the provider and contact local police or the national cybercrime reporting channel. If an organization exposed personal data, the relevant data protection authority may also provide guidance.
- United Kingdom: Contact the financial provider and use the current national fraud and cybercrime reporting service.
Reporting does not guarantee recovery, but it creates a record, supports investigations, and may be required by a bank, insurer, employer, or regulator.
If You Cannot Recover the Account
- Keep using only the provider’s official recovery process.
- Do not pay strangers who promise account recovery.
- Create a new secure email account for urgent communications.
- Change the recovery email on important services you still control.
- Tell contacts not to trust messages from the old address.
- Ask the provider whether the compromised address can be suspended.
- Document ownership evidence and every recovery attempt.
Be patient with waiting periods designed to prevent an attacker from instantly taking permanent control. Repeatedly changing information or submitting inaccurate answers may make verification harder.
How to Prevent Another Email Takeover
- Use a passkey or hardware security key
- Keep a unique password in a trusted password manager
- Maintain two secure recovery methods
- Store backup codes offline
- Review devices and connected apps every few months
- Never approve an unexpected sign-in prompt
- Verify urgent requests through another channel
- Keep phones, computers, browsers, and extensions updated
- Use separate email aliases for banking, shopping, and public sign-ups
- Limit personal information available to data brokers and social profiles
Learn the warning signs in our complete guide on how to spot a phishing email.
Hacked Email FAQ
Is changing the password enough?
No. You must also remove unknown sessions, recovery methods, forwarding rules, filters, delegates, app passwords, passkeys, and connected apps.
Should I delete the hacked account?
Not immediately. First preserve evidence, recover connected services, warn contacts, and export legitimate data. Deletion may remove information needed for fraud recovery.
Can the attacker still read old messages?
If messages were downloaded or forwarded, copies may remain outside your control. Focus on stopping new access and protecting information revealed in the mailbox.
Should I factory-reset my computer?
Only when malware is confirmed, the device remains untrustworthy, or a security professional recommends it. Back up essential personal files carefully and do not restore suspicious programs.
The Bottom Line
An email takeover is a security incident, not just a forgotten-password problem. Recover the account from a trusted device, replace the password, remove every hidden access path, protect connected services, and document what happened.
Once the account is clean, enable phishing-resistant sign-in and maintain a tested recovery plan. Your inbox should never be the easiest way into the rest of your digital life.
Comments
Post a Comment