How to Tell Your Email Has Actually Been Hacked
Before you panic, confirm it. A few common signs point to a genuine compromise rather than a glitch: friends and colleagues receiving spam or odd “I’m stuck abroad, please send money” messages from your address; sent items you did not write; password-reset emails you never requested; or being locked out entirely because someone has changed your password.
One thing worth knowing early — receiving a scary email that claims a hacker has “recorded you” and knows your password is usually a bluff. These blackmail emails typically quote an old password leaked in a data breach years ago, not live access to your account. It is still a signal to change that password everywhere you reused it, but it is not the same as an active break-in.
First Hour: Immediate Steps to Lock the Attacker Out
Speed matters here, but order matters more. Work through these in sequence.
- Get to another secure device. If you suspect the computer or phone you normally use is infected, do not log in from it — you could hand your new password straight to the attacker. Use a different, trusted device.
- Change your email password immediately. Choose something long and completely new — not a variation of the old one. If you cannot log in because the password has already been changed, use the provider’s account-recovery process (Google, Microsoft and Apple all have one) straight away, as recovery often depends on details the attacker has not yet altered.
- Sign out everywhere. Every major provider has a “sign out of all sessions” or “sign out of all devices” option buried in security settings. This instantly boots the attacker out, even if they still know an old session.
- Change the passwords on anything linked to that email — online banking first, then anything holding payment details. Your email is the reset route for all of them, so an attacker with your inbox can walk into your other accounts.
Check the Hidden Settings Attackers Leave Behind
This is the step most people miss, and it is the reason so many accounts get “re-hacked” days later. Once someone has been inside your inbox, they often plant quiet changes so they keep access or keep stealing information even after you reset your password.
Check every one of these:
- Forwarding rules. Attackers set your mail to auto-forward a copy of everything to an address they control. Look under forwarding settings and delete anything you did not create.
- Filters and rules. A classic trick is a rule that automatically deletes or archives any email containing words like “bank”, “invoice” or “security”, so you never see the warning signs. Delete unfamiliar rules.
- Auto-replies. Check that no auto-response has been set up to message your contacts.
- Recovery email and phone number. Make sure the backup email address and mobile number on the account are still yours and have not been swapped for the attacker’s.
- Connected apps and app passwords. Revoke access for any third-party app or “app password” you do not recognise.
- Your signature and display name. Occasionally these get altered to slip in scam links.
If you skip this stage, you can change your password ten times and the attacker will simply keep reading your mail through the forwarding rule.
Turn On Two-Factor Authentication (2FA)
Once the account is clean, add two-factor authentication — the single most effective thing you can do to stop this happening again. With 2FA switched on, even someone who knows your password cannot get in without a second code.
Where possible, use an authenticator app (such as Microsoft Authenticator or Google Authenticator) or a passkey rather than SMS text codes. Text messages can be intercepted through SIM-swap fraud, whereas an app-based code or passkey is tied to your physical device. Save the backup recovery codes your provider gives you somewhere safe and offline — they are your way back in if you ever lose your phone.
Scan Your Device and Warn Your Contacts
If the breach came from malware rather than a leaked password, securing the account alone is not enough — the same infection will harvest your new password too. Run a full scan with a reputable security tool, and if anything looks off, treat the machine as untrusted until it has been properly checked. This is exactly the kind of clean-up and hardening we handle day to day as part of our cybersecurity work.
Then send a short, calm message to your contacts letting them know your account was compromised and that any strange messages from you should be ignored or deleted. This stops the attacker using your name to scam the people who trust you.
How to Stop It Happening Again
A few habits make a repeat far less likely:
- Use a unique password for your email that you use nowhere else. Reuse is how one old breach becomes ten hacked accounts.
- Use a password manager so every login can be long, random and different without you memorising them.
- Keep 2FA on for your email and any account that holds money.
- Be sceptical of “urgent” login prompts. Phishing pages that mimic your provider are the most common way passwords get stolen. Check the web address before typing anything.
- Keep a backup. If you rely on email for important documents, sensible backup solutions mean a compromise never costs you the contents. Getting your accounts on a properly configured platform through professional email setup also makes them far harder to breach in the first place.
Locked out, unsure whether your account is truly clean, or worried a device might be infected? We can help you secure it properly rather than guessing. Call PC Macgicians on 020 7610 0500, drop into the Putney workshop, or use our contact form — and if you would like ongoing protection, our cybersecurity service is the sensible next step.




