Short answer: Act in this order — get to a device you trust, change the password, sign out all sessions, then check for forwarding rules and altered recovery details. Those hidden settings are how attackers keep access after you change the password, and almost everyone forgets to look. Once the account is clean, enable an authenticator app or passkey and work outward to accounts that reset through this inbox.

Why email first, and fast

Your email is not one account among many. It is the master key: nearly every other service you use will send a password reset link there, no questions asked.

So an attacker in your inbox is not reading your mail for entertainment. They are inventorying it — banks, exchanges, cloud storage, domain registrar, marketplaces — and resetting them one at a time. The clock matters enormously here.

Signs it has happened

That last one is underrated. A well-run compromise is quiet, not dramatic.

Step 1: Move to a device you trust

If your computer might be infected with an infostealer, doing recovery on it hands the attacker your new password immediately.

Use a different machine, or your phone. If both are suspect, borrow a device. Deal with cleaning the infected machine afterwards — but do not skip this, because it is the step that decides whether the rest of your work holds.

Step 2: Change the password

If you still have access, change it now to something long, unique, and not a variation of the old one. If you have lost access, use the provider’s recovery flow — Google, Microsoft and others all have one, and it will ask for details like recovery phone, previous passwords, and account creation date.

Use a password manager to generate it, so it is unique and you are not memorising anything.

Step 3: Sign out every session

Changing the password does not always end active sessions, and an attacker with a live session simply carries on.

This is where a stolen session cookie stops working — see what is session hijacking.

Step 4: Hunt the hidden settings

This is the step people skip, and it is the step that decides whether they are back here next month.

Go through every one. A password change with a forwarding rule still in place is not a recovery.

Step 5: Enable strong 2FA

Now, not later.

If 2FA was already enabled and they got in anyway, that points to real-time phishing, session theft, or a compromised recovery method. Worth reading can 2FA be hacked? to work out which.

Step 6: Work outward

Assume anything that resets through this inbox is exposed. In priority order:

  1. Banking and payment platforms — change passwords, check for new payees and altered payout details, enable 2FA.
  2. Cloud storage — check sharing links and connected apps.
  3. Domain registrar and hostingsecuring your domain name.
  4. Password manager — change the master password and check for unfamiliar devices.
  5. Social and marketplace accounts.
  6. Anywhere you reused that email password — see credential stuffing.

Step 7: Clean the machine, then tell people

If malware is a possibility — you installed something odd, opened an unexpected attachment, or use cracked software — run a reputable scanner, and consider a full reinstall. Removing the malware matters more than any password change, because without it you will be reinfected.

Then warn your contacts. A compromised inbox is used to scam the people who trust you, and a short “if you got anything strange from me, ignore it” message prevents real damage to someone else.

If money moved, contact your bank immediately and report it to your national fraud reporting service.

Frequently asked questions

How did they get in?

Most often a reused password exposed in an unrelated breach, or a phishing page. Occasionally malware. Check your address on a breach service — how to check if your password has leaked.

I changed my password but they are still getting in. Why?

Three usual causes: an active session you never ended, a forwarding rule still running, or an app password that bypasses your login. All three are covered in steps 3 and 4.

Should I delete the account and start fresh?

Rarely. A recovered and properly secured account is better than losing your history and having every service still pointing at a dead address. Only consider it if recovery genuinely fails.

Can I find out who did it?

Realistically, no. Recent-activity logs show IPs and locations, but these are proxied. Spend your effort on securing rather than investigating.

What if I cannot recover the account at all?

Work through each important service’s own recovery, using identity verification and payment history as proof. Then set up a new email with strong 2FA from day one and update every account to point at it.

How do I stop this happening again?

Unique passwords via a password manager, a passkey or authenticator app on email, no SMS fallback, and a quarterly check of forwarding rules and connected apps. Also see the 9 most common 2FA mistakes.

The bottom line

Trusted device, new password, all sessions out, then the hidden settings — forwarding, filters, recovery addresses, app passwords. That fourth step is what separates a real recovery from a temporary one. Then lock the account with a passkey or authenticator app and work outward, because whoever was in there already had a list.

Not been hacked, just want to prevent it? Start with our complete guide to 2FA.

Leave a Reply

Your email address will not be published. Required fields are marked *