How to Recover a Hacked Email Account

Your email is the master key to your other accounts. Here is how to lock an attacker out fast, close the back doors they leave, and stop it recurring.

Key takeaways

  • Act fast: change the password and sign out all devices the moment you suspect a breach.
  • Turn on two-factor authentication immediately — it is the single biggest barrier to re-entry.
  • Check forwarding rules and recovery details, which attackers quietly change to keep access.
  • Your email unlocks everything else — secure it first, then your banking and social accounts.

Your email account is the master key to your digital life: it can reset the password on almost every other service you use. So when it is compromised, the priority is to lock the attacker out quickly and then close the doors they may have left open. This guide walks through recovery in the order that limits the damage, drawing on the official guidance from Google, Microsoft and consumer-protection bodies like the US Federal Trade Commission.

Signs your email is hacked

Tell-tale signs include being unable to log in with your correct password, friends receiving spam or strange messages from you, password-reset emails you did not request, sent messages you never wrote, or your provider warning of a sign-in from an unfamiliar location or device. You might also notice emails disappearing — a sign someone has set up rules to hide their activity. Any one of these warrants immediate action.

Regain access right now

Try a password reset

Use your provider's "Forgot password" link. If your recovery phone or email still works, you can reset and lock the attacker out in minutes. Google and Microsoft both run dedicated account-recovery flows for exactly this.

Use the account recovery form if locked out

If the attacker changed your recovery details, use the provider's full recovery process (Google Account Recovery, Microsoft account recovery). Answer from a device and location you normally use to improve your chances.

Sign out everywhere

Once back in, use the "sign out all sessions" / "sign out all devices" option in security settings to instantly revoke the attacker's active logins.

Use a device you trust. Recover from a computer or phone you know is clean. If the breach came from malware on your own device, see how to remove malware first, or you may simply hand the new password straight back to the attacker.

Lock the account back down

Getting in is only half the job. Immediately set a new, unique password you have never used elsewhere — our guide to strong passwords shows how, and a password manager makes it painless. Then turn on two-factor authentication (2FA), ideally with an authenticator app rather than SMS, which our 2FA explainer covers. 2FA means that even if someone learns your password again, they cannot get in without your second factor.

Check what they touched

Attackers often set up quiet ways to keep control. In your settings, check for and remove: email forwarding rules sending copies of your mail elsewhere; filters that auto-delete or hide messages (often used to hide password-reset emails); changed recovery phone numbers and addresses; and unfamiliar connected apps or app passwords. Restore your real recovery details and delete anything you do not recognise. Then review your sent and trash folders to see what was sent in your name.

Protect your other accounts

Because email resets other passwords, assume the attacker may have reached into linked services. Change the password on anything important that shares this email — banking, shopping, social media and your password manager — prioritising accounts with payment details. Watch for unauthorised transactions and, if money is involved, contact your bank. Warn your contacts that messages from you may be spam or scams, since attackers often use a hijacked account to target the people who trust you.

Stop it happening again

Most email hacks trace back to a reused or weak password or a phishing email that tricked you into typing your credentials on a fake page. Going forward: use a unique, strong password for your email and nothing else, keep 2FA on, learn to spot phishing, and review your account's recent security activity now and then. These habits make a repeat far less likely and are exactly what the major providers and the FTC recommend.

Frequently asked questions

What should I do first if my email is hacked?

If you can still log in, change your password immediately and sign out of all devices. If you are locked out, use your provider's account recovery process (Google Account Recovery or Microsoft account recovery). Then turn on two-factor authentication to keep the attacker from returning.

How did someone get into my email account?

Usually through a reused or weak password exposed in a data breach, or a phishing email that tricked you into entering your login on a fake page. Malware that captures keystrokes is another route. A unique password plus two-factor authentication blocks the common methods.

Should I change my other passwords too?

Yes. Because your email can reset passwords on other services, change the password on anything important that uses that email — especially banking, shopping and social accounts — and watch for suspicious activity. Use a different strong password for each.

How do I check if a hacker left a back door?

In your email settings, look for and remove unfamiliar forwarding rules, filters that delete or hide messages, changed recovery phone numbers or addresses, and unknown connected apps. These are how attackers quietly keep access after you change the password.

Will turning on two-factor authentication really help?

Yes — it is the single most effective step. With 2FA on, a stolen password alone is no longer enough to log in, because the attacker also needs your second factor (ideally a code from an authenticator app). Major providers credit it with blocking the vast majority of account takeovers.

Sources & further reading

This guide is independently produced. We reference primary documentation from device makers and security authorities (NIST, CISA, FTC). Tudug is reader-supported and may earn from ads.

Guide

Create Strong Passwords

Build passwords that resist cracking.

Open →
Guide

Two-Factor Authentication

Add a second lock to your accounts.

Open →
Guide

Spot a Phishing Email

Recognise the scams that steal logins.

Open →