Breaches & Passwords
How to Recover a Hacked Email Account
The short version
Work in this order: get to a device you trust, regain access through your provider's recovery form, change the password and end every active session, then hunt down the back doors the attacker left - forwarding rules, filters, delegated access, app passwords and altered recovery details. Only then turn on two-factor and work outward to the accounts your email can reset. Jumping straight to a password change is the single most common mistake, because it leaves the attacker's quiet foothold intact.
Start here: the order that actually works
Recovering a hacked email account is a sequence, not a single action. Regain access, cut the attacker's live sessions, remove their persistence, then harden. Most advice online stops after "change your password", which is why people get pushed back out of the same account days later, wondering what they missed.
The seven steps below follow the guidance published by the US Federal Trade Commission and by Google, Microsoft, Apple and Yahoo for their own accounts. Nothing here needs technical skill. It needs about an evening and a willingness to read settings screens you have never opened.
- Move to a device you know is clean.
- Regain access through the provider's recovery form.
- Change the password, then sign out of every session and device.
- Remove the attacker's persistence: forwarding, filters, delegation, app passwords, recovery details.
- Turn on two-factor authentication, ideally not by SMS.
- Secure every account your email address can reset.
- Warn your contacts and report the compromise.
If you are mid-panic, do steps one to three now and come back for the rest tonight. The first three cut off live access; the rest stop it happening again.
Step 1: Get to a device you trust
Before you touch the account, make sure the machine you are using is clean. The FTC's first instruction is to update your security software and run a scan, deleting anything flagged. Microsoft goes further and says to run a full antivirus scan before you change your Outlook password.
The reason is simple. If information-stealing malware is sitting on the device, it captures your new password the moment you type it, and the whole recovery is theatre. If you cannot scan the computer you normally use, borrow a phone or a machine you know is healthy and do the recovery there instead.
Step 2: Get back in if you are locked out
If the attacker already changed your password, use your provider's recovery form rather than hunting for a support phone number. These forms weigh everything you can prove - old passwords, familiar devices, when you created the account - instead of relying on one factor the attacker has taken.
Google is unusually specific about how to improve your odds. Its guidance says to use "a computer, phone, or tablet where you frequently sign in", the same browser you usually do, and to be "in a location where you usually sign in, like at home or at work". It also tells you not to skip questions: "If you're unsure of an answer, take your best guess rather than moving on to another question."
| Provider | Recovery route | What it also tells you to check |
|---|---|---|
| Google / Gmail | Account recovery form | Recent security events, connected devices, third-party app access |
| Microsoft / Outlook.com | Password reset, then the recovery form | Connected accounts, forwarding, automatic replies |
| Apple Account | iforgot.apple.com | Unrecognised devices, altered security info, SMS forwarding |
| Yahoo Mail | Sign-in Helper | Settings changed by someone else, then 2-step verification |
Source: recovery and compromised-account documentation published by Google, Microsoft, Apple and Yahoo, September 2026.
Expect to attempt a recovery form more than once. Each attempt is scored on its own, so a failed try in a coffee shop does not doom a later try from your own sofa.
Step 3: Change the password, then end every session
A new password does not automatically log the intruder out. A stolen session can keep somebody's browser signed in after the password changes, which is why the FTC lists "Sign out of all devices" as a step separate from "Change your account password". Do both, in that order, in one sitting.
Then look at who else is still connected. Gmail puts a "Details" link in the bottom right of the inbox that opens your sign-in history: Google says it shows concurrent sessions, the access type used, and "the last 10 IP addresses and approximate locations that accessed your Gmail account". Google's compromised-account checklist also tells you to review recent security events and remove devices you do not recognise. Apple says to open your account page and remove any device you do not recognise there.
Make the new password unique to this account. If you reused it anywhere, those accounts are compromised too - our password manager and 2FA guide covers doing that once instead of repeatedly.
Step 4: Find the back doors they left behind
This is the step most guides skip, and it is the reason people get hacked twice in a week. Someone who held your inbox for even an hour usually leaves a route back in that survives a password change. Work through every one of these before you call the account clean.
- Forwarding. A silent copy of every message sent to an address you will never notice. The FTC, Google and Microsoft all name this check explicitly.
- Filters and rules. Attackers commonly auto-archive or auto-delete mail from your bank or from password-reset senders, so you never see the alerts.
- Delegation. Gmail lets another account read and send on your behalf. Google's checklist tells compromised users to review this.
- IMAP, POP and app passwords. These bypass your normal login screen and often survive a password reset.
- Recovery phone and email. If those were switched to the attacker's, they can simply reset you out again. Apple also warns to check that nobody set up unauthorised SMS forwarding with your carrier.
- Connected apps and aliases. Revoke third-party apps you do not recognise, and check your reply-to address, aliases and signature for edits.
Read the sent and deleted folders too. They show you what was actually done with the account, which decides how much of the next two steps you need. If the sent folder is empty but you know mail went out, treat that as evidence of a filter or a tidy-up rather than proof that nothing happened.
Step 5: Turn on two-factor, and pick the right kind
Two-factor authentication is what stops a repeat. The FTC lists turning it on as a core recovery step, alongside verifying your recovery email and phone number. Every major provider offers it free, and turning it on takes about two minutes once you are back inside the account.
Prefer a passkey, a security key or an authenticator app over SMS codes. Text-message codes are far better than nothing, but they are tied to your phone number, and a number can be taken over - see our guide to SIM-swap protection. Apple suggests hardware security keys for people facing targeted attacks.
Step 6: Protect the accounts your email can unlock
Email is the master key. Anything that can send you a password reset is only as secure as the inbox receiving it, a point the FTC makes plainly: a hacked email account lets someone reset the passwords on your other accounts. So the cleanup does not end at the inbox.
Start with the accounts that move money or hold documents: bank and card logins, payment apps, cloud storage, tax portals, your phone carrier account. Change those passwords and turn on two-factor there too. Search your inbox and trash for "password reset" and "verify" messages from the period of the compromise - those tell you exactly which accounts the attacker went for.
If your details showed up in a breach as well, checking your email against Have I Been Pwned tells you which leak the password likely came from, and what to do after a data breach covers the wider cleanup.
Step 7: Warn your contacts, then report it
Tell people before the attacker does. The FTC advises alerting your contacts and warning them not to click links in messages from you or to respond to pleas for money, because inbox access is routinely used to run scams on the people who trust you most.
Then report it. US consumers can file at IdentityTheft.gov for a personalised recovery plan, and the FBI takes cybercrime complaints at IC3.gov. If financial or Social Security information was exposed, consider a credit freeze, which is free and blocks new accounts being opened in your name.
How common is this, in reported numbers
Email compromise is not a fringe problem, and the federal complaint data shows where the damage lands. The FBI's Internet Crime Complaint Center logged 1,008,597 complaints in 2025 with $20.877 billion in reported losses, a 26 percent rise in losses over 2024. The email-adjacent categories dominate the count.
| Crime type (2025) | Complaints | Reported losses |
|---|---|---|
| Phishing / spoofing | 191,561 | Not separately reported |
| Personal data breach | 67,456 | $1.31 billion |
| Identity theft | 31,675 | $185.8 million |
| Business email compromise | 24,768 | $3.05 billion |
| SIM swap | 971 | Not separately reported |
Source: FBI Internet Crime Complaint Center, 2025 IC3 Annual Report.
Phishing is the most-reported category by a wide margin, which matches how most inbox takeovers begin. Our note on spotting phishing covers the current lures. More on breaches and account security is collected in the breaches section of this blog.
Why you, and how to become a smaller target
Account takeovers are rarely personal. Attackers work from lists: credentials leaked in old breaches, phone numbers and addresses bought cheaply, and the recovery answers that people-search sites publish about you for free. The less of that is public, the harder your account is to attack in the first place.
Two practical follow-ups. Stop reusing passwords, so one leaked site cannot unlock your inbox. And cut down what is publicly listed about you, because your address history, relatives and old phone numbers are precisely what an attacker needs to pass a support agent's identity check. You can see what is already exposed with a free exposure scan, and remove the listings yourself using our free opt-out guides.
Check what is already out there
Run a free exposure scan to see which breaches include your email and which data brokers list you - no account, nothing stored.
Frequently asked questions
What should I do first if my email was hacked?
Run a security scan on the device you plan to use before you touch the account. The FTC and Microsoft both put this first, because malware on your machine will capture the new password the moment you type it. Then move on to recovery.
I am locked out and my recovery phone was changed. Can I still get back in?
Often yes. Every major provider has a recovery form that weighs how much you can prove rather than relying on one factor. Google advises using a device, browser and location you normally sign in from, answering every question, and guessing rather than skipping. Expect to try more than once.
Does changing my password kick the hacker out?
Not on its own. A stolen session can keep a browser signed in after the password changes, which is why the FTC lists signing out of all devices as a step separate from changing your password. Change the password, end every active session, then check which devices are still authorised.
How do I check for hidden forwarding rules?
Open your mail settings and read the forwarding, filters and rules sections line by line. Google also tells compromised users to check mail delegation, IMAP and POP access, and app passwords. Microsoft points to connected accounts, forwarding and automatic replies. Delete anything you did not create.
How did someone get my email password?
Usually one of three ways: it leaked in a breach of another site where you reused it, you typed it into a convincing phishing page, or malware on your device captured it. You can check whether your address appears in known breaches using Have I Been Pwned.
Should I delete the account and start fresh?
Rarely a good idea. Your email address is the recovery address on dozens of other accounts, and abandoning it can strand you outside them. Some providers eventually recycle deleted addresses, which would hand your future password resets to a stranger. Clean the account and keep it.
Do I need to report a hacked email account?
Report it if anything was taken or used against you. IdentityTheft.gov gives US consumers a personalised recovery plan, and the FBI takes cybercrime complaints at IC3.gov. Reporting will not usually get your account back, but it creates the paper trail you need for disputes.
How long does it take to recover a hacked email account?
Regaining access takes minutes if you still hold a working second factor, or several days of repeated recovery attempts if the attacker changed your recovery phone and email. The cleanup afterwards - settings, connected apps, downstream password changes - realistically takes an evening.
Sources: US Federal Trade Commission, "How To Recover Your Hacked Email or Social Media Account"; Google Account Help, "Secure a hacked or compromised Google Account" and its account-recovery tips; Gmail Help on last account activity; Microsoft Support, "My Outlook.com account has been hacked"; Apple Support, "If you think your Apple Account has been compromised"; Yahoo Help Sign-in Helper guidance; FBI Internet Crime Complaint Center, 2025 IC3 Annual Report.