How to Check If Your Email Was Hacked (And What to Do Right Now)
%201.png)
Key Takeaways
Your email is the master key to your digital life, tied to your bank, social media, work apps, and medical records. That's exactly why it's the number-one target for hackers.
The FBI's Internet Crime Complaint Center (IC3) reported over $3 billion in business email compromise (BEC) losses in 2025 alone. Between October 2013 and December 2023, BEC scams caused over $55 billion in total exposed losses worldwide across all 50 U.S. states and 186 countries. (FBI IC3, September 2024)
The scariest part? Many victims don't realize their account has been breached until the damage is done. Hackers stay invisible, reading emails, setting up hidden forwarding rules, and harvesting information for weeks before acting.
This guide shows you exactly how to check if your email was hacked, what signs to look for, and the steps to take right now if you've been compromised.
Why hackers target your email (and how they get in)
Understanding how attackers gain access helps you defend against them. The most common methods include:
- Phishing attacks: Fake login pages or malicious links trick you into handing over credentials. Phishing attacks account for roughly 36% of all data breaches globally.
- Credential stuffing: Hackers test passwords leaked in past breaches on other accounts, effective because 65% of people reuse passwords (Google survey).
- Weak or guessable passwords: Brute-force tools can crack simple passwords in seconds.
- Malware and keyloggers: Malicious software records everything you type, including passwords.
- Third-party app vulnerabilities: Apps connected to your email via OAuth can be exploited without your password.
- Social engineering: Attackers manipulate support agents or use personal information to reset credentials.
Once inside, an attacker can intercept password reset emails for your bank, social media, and other accounts, hijacking your entire online identity from one entry point.
7 warning signs your email has been hacked
You may not receive an official alert when your account is compromised. Watch for these red flags.
1. Emails in your sent folder you didn't write
Check your Sent and Outbox folders for messages you don't remember sending. Hackers often use compromised accounts to send spam or phishing emails to your contacts.
What to do: Scan your Sent folder for anything unfamiliar, especially emails with links, attachments, or money requests.
2. Contacts report strange emails from you
If friends or colleagues ask "did you send me this weird link?" take it seriously. Attackers impersonate you to trick people you know into clicking malicious links or wiring money.
What to do: Ask them to forward the suspicious email. Don't click any links inside it.
3. You can't log into your account
If your password suddenly doesn't work and you haven't changed it, someone else may have. Attackers often change passwords to lock you out while operating freely inside your inbox.
What to do: Go to your provider's account recovery page:
- Gmail: accounts.google.com/signin/recovery
- Outlook / Microsoft: account.live.com/password/reset
- Yahoo: login.yahoo.com/forgot
4. Unfamiliar login activity
Most providers let you see recent sign-ins, device type, browser, IP address, and approximate location. A login from an unfamiliar city, country, or device is a major red flag.
How to check:
- Gmail: Scroll to the bottom of your inbox → "Details" under "Last account activity"
- Outlook: account.microsoft.com → Security → Sign-in activity
- Yahoo: Account Info → Recent Activity
5. Account settings or inbox rules have changed
After gaining access, attackers often:
- Set up forwarding rules to redirect your emails to an address they control
- Create inbox filters that delete or archive security alerts
- Add a recovery email or phone number they control
These changes let them monitor your communications even after a password change.
What to do: Check your forwarding settings and inbox filter rules immediately (Settings → Filters/Rules or Forwarding).
6. Your password was changed without your knowledge
A notification that your password, recovery phone number, or backup email was changed, but not by you, is a definitive sign of compromise.
What to do: Act immediately. If you can still log in, change your password from a clean device. If not, go to the account recovery page.
7. Your email appears in a known data breach
Your credentials can be stolen by breaching another service where you reused the same password, and your email may be circulating on the dark web without your knowledge.
How to check: Go to haveibeenpwned.com, a free, trusted service used by security teams worldwide. Enter your email to see if it appears in any known breach, including what was exposed and when.
> Pro tip: Sign up for free breach notifications at haveibeenpwned.com/NotifyMe so you're alerted the moment your email appears in a new breach.
What to do right now if your email was hacked
If you spotted any warning signs above, act fast. The first hour is critical.
Step 1: Change your password from a clean device
Don't change your password on a potentially infected device, a keylogger will capture your new password too. Use a different, trusted device: a second laptop, tablet, or a friend's computer.
When creating your new password:
- Use a minimum of 15 characters (per NIST SP 800-63B guidelines)
- Use a randomly generated string from a password manager
- Make it unique, never reuse it elsewhere
Change your email password first. Every password reset link from your bank, social media, and other accounts flows through your inbox. Once email is secured, work outward to financial accounts, social platforms, and any account that used the same password.
Step 2: Force sign-out of all active sessions
Changing your password stops future logins but doesn't end sessions already in progress. Force-terminate all sessions:
- Gmail: Bottom of inbox → "Details" → "Sign out all other web sessions"
- Outlook/Microsoft 365: account.microsoft.com → Security → Advanced security options → "Sign me out"
- Yahoo Mail: Account Info → Recent Activity → "Sign out of all other sessions"
Step 3: Enable two-factor authentication (2FA) immediately
2FA adds a second layer of verification so attackers can't get in even with your password. Choose the strongest option available:
- Authenticator app (Google Authenticator, Authy): more secure than SMS
- Hardware security key (YubiKey): the gold standard, phishing-resistant
- SMS/text code: better than nothing, but vulnerable to SIM-swapping
Enable 2FA on your email first, then on every linked account.
Step 4: Audit and remove hidden backdoors
Hackers build backdoors that survive password resets. Check each of the following:
Email forwarding rules: Remove any rules forwarding messages to external addresses you didn't create.
Inbox filters: Delete filters that automatically delete, archive, or mark as read security-related emails.
OAuth app permissions: Third-party apps can retain access through tokens even after a password change. Revoke any you don't recognize.
- Gmail: myaccount.google.com/permissions
- Microsoft: myapps.microsoft.com
Recovery information: Verify your backup email and recovery phone number are yours. Remove any you don't recognize.
Delegated access: Check for unfamiliar delegate or full-access permissions and remove them.
> The FBI IC3 recommends checking these settings regularly and using secondary verification channels to confirm changes. (FBI IC3, 2024)
Step 5: Scan all your devices for malware
If your account was compromised through malware, changing your password won't fix the underlying infection. Run a full scan on every device you use to access email, laptop, desktop, phone, and tablet, checking for keyloggers, Remote Access Trojans (RATs), and spyware. Don't log back into your email until you're confident each device is clean.
Step 6: Notify your contacts
Your contacts may have already received phishing emails from your account. Send a brief alert (from a secondary account if possible) telling them to ignore suspicious messages from you, not to click any links, and that your account is now secure.
Step 7: Check and secure linked accounts
Assume any account connected to your email may also be at risk:
- Bank and financial accounts: Check for unauthorized transactions immediately
- Social media: Review recent activity for posts or logins you don't recognize
- Shopping sites: Look for unauthorized orders or address changes
- Work accounts: Alert your IT team immediately if a work email was compromised
Change passwords on any account sharing the same password or using your email for login or recovery.
Step 8: Report the breach
- FBI IC3: ic3.gov, especially if you suffered financial loss
- FTC: reportfraud.ftc.gov
- Your email provider: Report through their support channels
- Your employer or IT department: Required if a work email was involved
> If you're a business owner, BEC incidents may trigger regulatory notification requirements and cyber insurance obligations. Document everything as you respond.
How to prevent your email from being hacked again
Once you've regained control, take steps to ensure it doesn't happen again.
Use a password manager
Generate and store strong, unique passwords for every account, no reuse, no forgetting. Popular options include Bitwarden, 1Password, and Dashlane.
Enable phishing-resistant 2FA
Move beyond SMS-based 2FA to authenticator apps or hardware security keys, currently the strongest protection against account takeover.
Regularly check for breaches
Check haveibeenpwned.com every few months, or sign up for free breach alerts. The sooner you know, the faster you can act.
Keep your devices clean
Keep your OS, browser, and security software updated. Avoid clicking links or downloading attachments from unexpected emails, even from people you know, since their accounts could be compromised too.
Review account activity monthly
Set a monthly reminder to check your email's login history, connected apps, and inbox rules. Early detection is the most effective defense.
Be skeptical of urgent requests
Hackers create urgency, "unusual sign-in" alerts, "your account will be suspended" warnings, "click here immediately" directives. Always go directly to your provider's website rather than clicking links in emails.
Stay one step ahead with Guardio
Checking for warning signs manually is a good start, but hackers don't wait for your monthly audit.
Guardio monitors for phishing pages, malicious links, and suspicious redirects in real time, on your browser and your phone, blocking them before they can steal your credentials. It also alerts you when your email appears in a new data breach, so you find out right away instead of weeks later.
Over 1.5 million people use Guardio to stay protected from exactly the kind of threats that lead to a hacked inbox.
Conclusion
A hacked email account is stressful, but recoverable if you act quickly. Check for the signs, change your password on a clean device, force-end all sessions, enable 2FA, audit your settings for hidden backdoors, and scan your devices.
Once you're safe, build habits that keep attackers out: unique passwords, a password manager, strong 2FA, and regular monitoring.
Your inbox shouldn't be a vulnerability. With the right steps, it doesn't have to be.
Get a free security scan with Guardio today and stay protected from email account takeovers.
FAQs
How do I know if my email has been hacked?
Look for unfamiliar emails in your Sent folder, contacts reporting strange messages from you, login activity from unknown devices or locations, changed account settings, or unexpected password-change notifications. You can also check haveibeenpwned.com to see if your email appeared in a known data breach.
What should I do first if my email is hacked?
Change your password immediately, but do it from a clean, trusted device in case your current one is infected with malware. Then force-sign-out all other active sessions and enable two-factor authentication before doing anything else.
Can a hacker still access my email after I change my password?
Yes, if they set up forwarding rules, inbox filters, or connected third-party apps before you changed the password. Always audit your account settings, revoke unfamiliar app permissions, and force-end all active sessions after a password change.
How do hackers get into email accounts without knowing your password?
Phishing attacks, malware, credential stuffing from other breaches, and exploited third-party apps are the most common methods. Social engineering, where attackers trick support agents into resetting an account, is also used.
Is it possible to recover a hacked email account?
In most cases, yes. Use your email provider's account recovery page to regain access. The sooner you act, the better your chances of minimizing damage. Gmail, Outlook, and Yahoo all have dedicated recovery flows.
Should I report a hacked email to anyone?
Yes. Report it to your email provider, the FBI's IC3 (ic3.gov) if you suffered financial loss, and the FTC at reportfraud.ftc.gov. If it was a work email, notify your IT team immediately, as there may be legal and compliance obligations involved.
How can I prevent my email from being hacked again?
Use a unique, strong password generated by a password manager, enable phishing-resistant two-factor authentication, monitor your account activity monthly, and check haveibeenpwned.com regularly. Avoiding link clicks in unexpected emails also goes a long way.






