Treat a compromised email account as a gateway to other accounts. Use a clean, trusted device and work from the email provider’s official site or app.
Step-by-step checks
1. Secure access
Change the email password to a new, unique password. If you cannot sign in, use the provider’s official recovery page rather than a link from a message.
2. Enable stronger sign-in
Turn on multifactor authentication and save recovery codes somewhere separate from the account. Sign out other sessions if the provider offers that control.
3. Inspect account changes
Check recovery email, phone, forwarding rules, filters, delegates, connected apps, and recent sign-ins. Attackers often add persistence rather than only changing the password.
4. Protect connected accounts
Change passwords on important services that reused the old password or rely on the email address for recovery. Prioritize financial, shopping, cloud, and social accounts.
5. Warn contacts and preserve evidence
Tell contacts to ignore suspicious messages. Save dates, headers, alerts, and transaction evidence before deleting anything that may be needed for a report.
When to stop
Contact the provider, bank, employer, or relevant authority immediately if money, identity documents, work systems, or personal safety may be affected.
What to tell an expert
Share the device model, operating system, exact symptom or error, when it began, what changed beforehand, and which checks you completed. Do not send passwords, one-time codes, encryption recovery keys, or unnecessary personal files.
Official reference
This Supportia guide was prepared with current official guidance as a factual baseline. Interface names can still vary by device and version. Open the official reference.
Did this solve your problem?
Your answer helps Supportia prioritize updates. No account or email is required.
