← Blog

Blog  ·  June 2026

Your Email Was Hacked. What to Do, in Order

The first hour matters most. A calm, ordered checklist for regaining control of a compromised email account and limiting the damage.

Your primary email is the master key to your life. It resets the passwords for banking, investments, cloud storage, and almost everything else. If you suspect it has been compromised, the order of your next steps matters as much as their speed.

Work from a different device you trust, not the one you think may be affected, and move through the following in sequence.

The first hour, in order

  1. Change the password to something long and unique, used nowhere else.
  2. Turn on or re-confirm multi-factor authentication, using an authenticator app or a physical security key rather than text-message codes, which can be redirected through a SIM swap.
  3. Inspect the settings attackers hide in. Remove any forwarding rules, filters, recovery email addresses, recovery phone numbers, or connected apps you do not recognize. This is the step most people skip, and it is how an intruder keeps reading your mail after the password changes.
  4. Sign out of all sessions and devices from the account's security page, which forces the attacker off.
  5. Reset the accounts downstream that rely on this email, starting with banking, brokerage, and your password manager.
  6. Protect your money. Alert your bank and brokerage, and consider a fraud alert or a credit freeze if financial details may have been exposed.
  7. Warn the people who could be impersonated to you, family, an assistant, advisors, so they verify any unusual request that appears to come from you.
  8. Report it to the FBI at ic3.gov and through the email provider's account-recovery process.

Why the recovery settings matter most

Most people change the password and stop. Attackers expect that. They plant a hidden forwarding rule, add their own recovery address, or authorize an app, so that even after a reset they still receive copies of your mail or can let themselves back in. Until you clear those, the account is not yours again. Check every recovery and forwarding setting by hand.

Why this keeps happening

Email is the single most exploited path in cybercrime, because so much else hangs off it. A stolen password from an old breach, reused on your email, is often all it takes. That is also why prevention is simple: a unique password on the email account, plus app-based or hardware multi-factor authentication, removes the two most common ways in.

Hardening the master email, and the recovery settings behind it, before anything goes wrong is part of the foundation a Private Cybersecurity Engagement establishes. The complimentary guide covers the habits that prevent this, and you are welcome to request a private consultation if you would like a second set of eyes on your own setup.

← Blog