How to Tell If Your Email Has Been Hacked, and What to Do About It

By J. Mesa

A customer calls to ask why you sent a strange link. A password reset arrives for an account you did not touch. Messages you never read show up as opened. Any one of these can mean a stranger is inside your email. Act the same day, because your mailbox is the master key: nearly every other account you own sends its password reset there.

How do I know if my email has been hacked?

Watch for these signs.

  • Contacts report messages from you that you did not send.
  • Your Sent folder holds messages you did not write, or the folder has been emptied.
  • You stop receiving mail you expect, such as replies from a customer or bank notices.
  • Password reset emails arrive for other accounts.
  • Your password no longer works.
  • You receive sign-in alerts from places you have never been.
  • You get multi-factor prompts you did not start.
  • Your recovery phone number or backup email address has changed.
  • You find rules or forwarding settings you did not create.
  • Unread messages appear as read, or mail turns up in odd folders.

How do email accounts get hacked?

  • Phishing. You typed your password into a fake sign-in page. See our guide to spotting a phishing email.
  • Reused passwords. A breach at another website exposed a password you also use for email. Attackers test those in bulk, an attack called credential stuffing.
  • Malware. An information-stealing program on your computer copied saved passwords and browser sessions.
  • Session theft. A phishing page relayed your sign-in to the real site and captured the session token, which works even on accounts with basic multi-factor authentication.
  • Malicious app permission. You approved an app that asked to read your mail.
  • Weak or guessable passwords.
  • A sign-in on a shared or infected computer.

What do hackers do with a hacked email account?

  • Reset your other passwords. Banking, shopping, payroll, and social media all send reset links to email.
  • Read your history. Old messages hold tax documents, ID scans, contracts, and invoices.
  • Watch quietly. In a business account, an attacker may read mail for weeks to learn who pays whom and when.
  • Redirect payments. The attacker replies inside a real email thread and tells your customer that your bank details have changed.
  • Phish your contacts. A message from your real address gets opened and trusted.
  • Hide the evidence. Inbox rules move replies and security alerts out of sight.

What should I do first?

Work from a device you trust. If you suspect malware on your computer, use a different one or your phone.

  1. Change the password to a long one you have never used anywhere.
  2. Sign out of all sessions. In Gmail, open your Google Account, then Security, then “Your devices.” In a Microsoft account, use “Sign out everywhere.” This ejects anyone already inside.
  3. Turn on multi-factor authentication, or reset it if it was already on. Remove any phone number, authenticator, or security key you do not recognize.
  4. Check your recovery options. Confirm that the backup email address and phone number are yours.
  5. Remove forwarding and rules. See the next section.
  6. Review connected apps and remove any you do not recognize or no longer use.
  7. Scan your computer for malware before you sign in from it again.

How do I find hidden forwarding rules?

Attackers count on you skipping this step. A rule they created keeps working after you change the password.

  • Gmail. Open Settings, then “See all settings.” Check “Forwarding and POP/IMAP” for a forwarding address, “Filters and Blocked Addresses” for filters you did not make, and “Accounts and Import” for unknown “Send mail as” addresses or delegates.
  • Outlook and Microsoft 365. Open Settings, then Mail. Check “Rules” and “Forwarding.” Look for rules that move messages to RSS Feeds, Conversation History, or Deleted Items, or that mark mail as read. Rules that match words such as “invoice,” “payment,” or “wire” are a strong sign of payment fraud in progress.
  • Yahoo and others. Look under mail settings for filters, forwarding, and connected accounts.

Check your signature and your automatic reply as well. Attackers sometimes plant a link or a phone number there.

What should I do after I regain control?

  1. Change the passwords on your important accounts, starting with banking, payroll, and anything that uses the same password. Check each for changes to contact details.
  2. Warn your contacts. Tell them to ignore recent messages and not to act on any payment instructions.
  3. Read your Sent and Deleted folders to see what the attacker sent and to whom.
  4. Check what your mailbox held. If it contained Social Security numbers, tax forms, or financial statements, freeze your credit.
  5. Watch your accounts closely for the next few months.

What if I am locked out?

Use the provider’s official recovery process: Google’s account recovery page, Microsoft’s recovery form, or the equivalent for your provider. Answer from a device and a location you have used with that account before, which improves your odds. Recovery can take days.

Never pay a “recovery service” you found through a search or a social media comment. Those are scams that target people who are already locked out. The provider does not charge for recovery.

What if it is a business email account?

A hacked work mailbox is a security incident for the whole company. Bring in your IT provider at once, and add these steps.

  1. Reset the password and revoke all sessions from the admin console.
  2. Review sign-in logs for the account and for other accounts from the same addresses.
  3. Search the audit log to learn which messages the attacker opened and sent.
  4. Check every other mailbox for the same malicious rules.
  5. Call your bank if invoices, wires, or payroll were discussed in the mailbox. Call customers and vendors by phone to confirm that no payment instructions have changed.
  6. Call your cyber insurance carrier and your attorney. A mailbox that held customer, patient, or employee data can trigger breach notification laws.
  7. Preserve the evidence. Do not delete the account or its logs.

Our guide to securing Microsoft 365 lists the settings that prevent most of these takeovers.

How do I prevent the next one?

  • Use a unique, long password for email, stored in a password manager.
  • Use strong multi-factor authentication. An authenticator app or a security key beats text message codes.
  • Never approve a sign-in prompt you did not start.
  • Keep your devices updated and avoid pirated software, a common source of password-stealing malware.
  • Review your account security page twice a year: devices, recovery options, connected apps, and rules.
  • Avoid signing in on shared computers.
  • Reach your mail by typing the address or using a bookmark, not through a link in a message.

Should I just create a new email address?

Rarely. Once you remove the attacker and secure the account, the old address is safe to keep. Abandoning it creates new risks: other accounts still send resets there, and some providers recycle unused addresses. Clean it and lock it down.

Your next step

Open your email settings now and check two things: the forwarding address and the list of rules. It takes two minutes, and it is the check most people have never made. For help securing business email and training your team, see our cybersecurity training and services, or contact Cerberus Cybersecurity.