Short answer: Act in this order — get to a device you trust, change the password, sign out all sessions, then check for forwarding rules and altered recovery details. Those hidden settings are how attackers keep access after you change the password, and almost everyone forgets to look. Once the account is clean, enable an authenticator app or passkey and work outward to accounts that reset through this inbox.
Why email first, and fast
Your email is not one account among many. It is the master key: nearly every other service you use will send a password reset link there, no questions asked.
So an attacker in your inbox is not reading your mail for entertainment. They are inventorying it — banks, exchanges, cloud storage, domain registrar, marketplaces — and resetting them one at a time. The clock matters enormously here.
Signs it has happened
- Contacts receive messages you did not send
- Emails missing from your inbox, or read when you have not read them
- Password reset emails for other services you did not request
- Sent-folder messages you do not recognise
- Login alerts from unfamiliar locations or devices
- Your password suddenly not working
- An unusually quiet inbox — a sign of a forwarding-and-delete rule
That last one is underrated. A well-run compromise is quiet, not dramatic.
Step 1: Move to a device you trust
If your computer might be infected with an infostealer, doing recovery on it hands the attacker your new password immediately.
Use a different machine, or your phone. If both are suspect, borrow a device. Deal with cleaning the infected machine afterwards — but do not skip this, because it is the step that decides whether the rest of your work holds.
Step 2: Change the password
If you still have access, change it now to something long, unique, and not a variation of the old one. If you have lost access, use the provider’s recovery flow — Google, Microsoft and others all have one, and it will ask for details like recovery phone, previous passwords, and account creation date.
Use a password manager to generate it, so it is unique and you are not memorising anything.
Step 3: Sign out every session
Changing the password does not always end active sessions, and an attacker with a live session simply carries on.
- Gmail — Security → Your devices → Manage all devices → sign out.
- Outlook / Microsoft — Security → Sign me out of all devices.
- Yahoo, Proton, others — look for “recent activity” or “sessions” in security settings.
This is where a stolen session cookie stops working — see what is session hijacking.
Step 4: Hunt the hidden settings
This is the step people skip, and it is the step that decides whether they are back here next month.
- Forwarding. Check for auto-forwarding to an unknown address. An attacker who loses access still receives copies of everything, including reset links.
- Filters and rules. Look for rules that delete, archive or forward messages containing words like “bank”, “security”, “password” or “invoice”. These hide the evidence from you.
- Recovery email and phone. An added or changed recovery route lets them reset your password later. Remove anything unfamiliar.
- App passwords and connected apps. These bypass 2FA by design. Revoke everything you do not recognise.
- Aliases and “send mail as” addresses. Used to impersonate you convincingly.
- Auto-reply. Occasionally used to redirect correspondents.
- Delegated access. Some providers allow another account to read yours.
Go through every one. A password change with a forwarding rule still in place is not a recovery.
Step 5: Enable strong 2FA
Now, not later.
- Add a passkey if your provider supports it — phishing-resistant and the strongest option available. See passkeys vs 2FA.
- Or an authenticator app: Google, Microsoft.
- Remove SMS once the app works, and remove any old phone numbers.
- Save backup codes offline — where to store them.
If 2FA was already enabled and they got in anyway, that points to real-time phishing, session theft, or a compromised recovery method. Worth reading can 2FA be hacked? to work out which.
Step 6: Work outward
Assume anything that resets through this inbox is exposed. In priority order:
- Banking and payment platforms — change passwords, check for new payees and altered payout details, enable 2FA.
- Cloud storage — check sharing links and connected apps.
- Domain registrar and hosting — securing your domain name.
- Password manager — change the master password and check for unfamiliar devices.
- Social and marketplace accounts.
- Anywhere you reused that email password — see credential stuffing.
Step 7: Clean the machine, then tell people
If malware is a possibility — you installed something odd, opened an unexpected attachment, or use cracked software — run a reputable scanner, and consider a full reinstall. Removing the malware matters more than any password change, because without it you will be reinfected.
Then warn your contacts. A compromised inbox is used to scam the people who trust you, and a short “if you got anything strange from me, ignore it” message prevents real damage to someone else.
If money moved, contact your bank immediately and report it to your national fraud reporting service.
Frequently asked questions
How did they get in?
Most often a reused password exposed in an unrelated breach, or a phishing page. Occasionally malware. Check your address on a breach service — how to check if your password has leaked.
I changed my password but they are still getting in. Why?
Three usual causes: an active session you never ended, a forwarding rule still running, or an app password that bypasses your login. All three are covered in steps 3 and 4.
Should I delete the account and start fresh?
Rarely. A recovered and properly secured account is better than losing your history and having every service still pointing at a dead address. Only consider it if recovery genuinely fails.
Can I find out who did it?
Realistically, no. Recent-activity logs show IPs and locations, but these are proxied. Spend your effort on securing rather than investigating.
What if I cannot recover the account at all?
Work through each important service’s own recovery, using identity verification and payment history as proof. Then set up a new email with strong 2FA from day one and update every account to point at it.
How do I stop this happening again?
Unique passwords via a password manager, a passkey or authenticator app on email, no SMS fallback, and a quarterly check of forwarding rules and connected apps. Also see the 9 most common 2FA mistakes.
The bottom line
Trusted device, new password, all sessions out, then the hidden settings — forwarding, filters, recovery addresses, app passwords. That fourth step is what separates a real recovery from a temporary one. Then lock the account with a passkey or authenticator app and work outward, because whoever was in there already had a list.
Not been hacked, just want to prevent it? Start with our complete guide to 2FA.