You go to log in and your password doesn’t work. Or a friend texts asking why you sent them a weird link. Or you find hundreds of bounce-back emails in your inbox for messages you never sent. That drop in your stomach is real, but you don’t need to panic. You need a checklist, and this is it.
Email accounts are the master key to most of your digital life. Whoever controls your email can often reset the passwords for your bank, your social media, your online shopping, even your child’s school portal. That’s exactly why it’s worth acting fast and in the right order.
First, try to get back in
If you can still log in, do this immediately, before anything else:
Change your password right now. Pick something long and unique, not a variation of your old one. A password manager can generate and store this for you so you don’t have to remember it.
Check for a “sign out of all devices” or “log out everywhere” option. Most major email providers have this buried in the security settings. Use it. This kicks out anyone who’s currently logged in on their own device.
Turn on two-factor authentication if it isn’t already on. This means logging in requires your password plus a code from your phone or an authentication app. It’s one of the single most effective things you can do to keep someone out for good.
If you can’t log in at all because the password’s been changed, most providers have an “account recovery” or “I don’t have access to my account” flow. You’ll typically need a recovery email address, a phone number, or answers to security questions you set up earlier. Follow that process carefully and patiently. It can take a little time, and that’s normal.
Check what the attacker actually did
Once you’re back in, don’t just breathe a sigh of relief and move on. Look around first.
- Check the sent folder for messages you didn’t send, especially anything asking contacts for money, gift cards, or personal information.
- Look at “forwarding” and “filter” settings. A common trick is to set up a rule that forwards your incoming mail to another address in the background, or that auto-deletes emails from your bank or other accounts so you never see the alerts. Remove anything you didn’t set up yourself.
- Review your recovery information. Confirm the recovery email and phone number on the account are actually yours. Attackers sometimes swap these in first so they can lock you out again later.
- Check connected apps and devices. Most email providers let you see which apps have access to your account and which devices are currently signed in. Revoke anything you don’t recognize.
This step matters because a hacked email account isn’t usually the whole story. It’s often the entry point to something bigger.
Change passwords everywhere that matters
Because so many other accounts can be reset through your email, assume anything tied to it might be at risk too.
Start with financial accounts: banking, credit cards, PayPal or similar services. Change those passwords and check recent activity for anything unfamiliar.
Move to accounts that hold personal information: social media, cloud storage, shopping accounts with saved payment details.
Don’t forget accounts tied to your kids. If you use your email to manage a child’s school portal, learning apps, or a gaming console’s family account, those are worth a look too. It’s a good moment to review resetting your child’s school portal and app passwords and to double check the family sharing and content restriction settings on any gaming consoles in the house, since those often link back to the same email.
Use a different, strong password for each account. Reusing passwords is exactly how one hacked login turns into five.
Warn the people in your contact list
If the attacker sent messages from your account, the people who received them need to know those messages weren’t really from you, especially if the emails asked for money, gift cards, or personal details.
A short, plain message works fine: “My email was hacked earlier. If you got a strange message from me asking for money or clicking a link, please ignore it and don’t respond.” This is the same instinct that protects people from fake charity scams that spike during disaster season: a familiar name asking for urgent help is exactly the setup scammers rely on, whether the “friend” is real or their account has been taken over.
Think about how it happened
You don’t need to solve this like a detective, but a little thought here helps you close the door that let the attacker in.
- Did you click a link or open an attachment in an unexpected email recently? Phishing is one of the most common ways accounts get compromised. Messages disguised as shipping notices, tuition invoices, or supply list reminders are common, and back-to-school phishing emails are a good example of how convincing these can look.
- Did you log into anything over public Wi-Fi recently, at an airport, hotel, or coffee shop? Unsecured networks can expose account credentials, which is worth keeping in mind the next time you travel; a refresher on public Wi-Fi safety is worth a read before your next trip.
- Have you reused this password anywhere else? If a different service you use was breached, attackers often try the same password on email accounts, banking sites, and everywhere else, hoping people reuse logins.
You don’t have to pinpoint the exact cause to move forward safely, but recognizing the pattern helps you avoid a repeat.
Watch for the aftershocks
A compromised email account can have effects that show up days or weeks later.
Keep an eye on your bank and credit card statements for a few weeks. If the attacker got access to financial information through your inbox, unauthorized charges may not appear right away.
Be alert to follow-up phishing attempts. Attackers who’ve had access to your inbox may know your contacts, your writing style, and details about your life, which they can use to make future scam attempts more convincing.
Consider a credit freeze or fraud alert if you believe personal information like a Social Security number or financial account details was exposed. This is a reasonable step even if you’re not sure, since it costs little and adds a real layer of protection.
If your work email was affected, tell your IT department right away, even if you’re embarrassed. They’d rather hear about it early than deal with a bigger mess later, and this applies just as much to school-issued accounts; a hacked school email can be an early sign of the kind of access that leads to larger ransomware incidents affecting school networks.
Build in some protection for next time
Once things are stable, take a few minutes to make a repeat harder.
- Turn on two-factor authentication everywhere it’s offered, not just on email.
- Use a password manager so every account has its own strong, unique password.
- Review your account recovery options every so often, since old phone numbers and unused backup emails are easy to forget about.
- Stay alert to unexpected emails asking you to click, log in, or verify something urgently.
None of this makes an account unhackable. Nothing does. But each layer makes you a harder, less convenient target, and most attackers are looking for easy ones.
A hacked email account is stressful, but it’s also recoverable. Work through it calmly, in order, and you’ll close most of the doors an attacker could use before they ever get to walk back through them.
A quick safety note
This article is general information, not professional security, legal, or medical advice. No single tool or setting makes anyone completely safe; security works in layers. If you are dealing with a live incident, such as active fraud, ransomware, or a child in danger, contact the appropriate professionals or authorities. For a threat to a child, report it to the NCMEC CyberTipline at report.cybertip.org and to local law enforcement.


