T

TechyLeakz

Latest Fixes

Fix Guide

How to Recover and Secure a Hacked Email Account

Get back into a hacked Gmail or Outlook account, lock out the attacker, remove hidden forwarding rules and connected apps, and protect the other accounts linked to your email.

Direct answer

If your email account was hacked, try to sign in and reset the password right away from a device you normally use, using Google Account Recovery for Gmail or Microsoft's password reset and recovery form for Outlook. Once you are in, set a new unique password, sign out all other sessions, and replace any recovery phone numbers or emails you do not recognize. Then delete unknown forwarding rules, filters and connected apps, turn on two-step verification or a passkey, scan your PC for malware, warn your contacts, and change passwords on accounts linked to that email.

Common causes

  • Your email password was exposed in a breach at another site where you used the same password, and attackers tried it automatically.
  • You entered your login details on a phishing page designed to look like a Google, Microsoft or other email sign-in screen.
  • Malware on your computer stole saved browser passwords or active session cookies, letting attackers sign in without your password or code.
  • Two-step verification was not turned on, so a stolen or guessed password alone was enough to get into the account.
  • Your recovery phone number or backup email address was outdated or itself compromised, making the password reset process easier to hijack.
  • You approved a malicious third-party app or add-on that was granted permission to read, send or delete your email.
  • A SIM-swap attack moved your phone number to an attacker's SIM card, letting them receive your text-message verification codes.
  • You stayed signed in on a shared or public computer, or on an old phone or laptop that someone else now has.

Advertisement

Step-by-step fixes

Step 1

Reset the password through official account recovery

Act quickly, before the attacker changes more settings. Use a device and network you have signed in from before, because providers trust familiar devices during recovery. If you think your PC might be infected, use your phone instead. For Gmail, go to g.co/recover, enter your address and follow the prompts. Google may ask for a previous password, send a code to your recovery phone, or ask when you created the account. For Outlook, Hotmail or Live accounts, go to account.live.com/password/reset. If you cannot verify with a code, complete Microsoft's account recovery form at account.live.com/acsr, using a different email address for Microsoft to contact you. Also check your inbox or phone for security alerts from your provider; they usually link to a page where you can review the activity and secure the account.

Step 2

Change the password and sign out every other session

Once you are back in, set a long, unique password you have never used anywhere else. For a Google account, go to myaccount.google.com > Security > Password. Google signs you out of most other devices when you change it, but also open Security > Your devices, choose Manage all devices, and sign out of anything you do not recognize. For a Microsoft account, go to account.microsoft.com > Security to change the password, then open Sign-in activity and review recent sign-ins, marking any you do not recognize. Use the option in Microsoft's advanced security settings to sign out everywhere if it is available. Success looks like only your own phones, tablets and computers remaining in the device list.

Step 3

Replace recovery phone numbers, emails and security info

Attackers often add their own phone number or backup email so they can reset the password again later. In your Google account, go to Security > How you sign in to Google and check the recovery phone, recovery email, 2-Step Verification methods and passkeys. Remove anything that is not yours and add your current details. Also review app passwords, if listed, and delete any you did not create. In your Microsoft account, go to Security and open the page for managing how you sign in, or Advanced security options, and remove unknown phone numbers, email addresses and authenticator apps. Microsoft may hold new security info for a waiting period if all existing info is replaced, which is a protection against attackers. Success looks like recovery options that all belong to you.

Advertisement

Step 4

Remove forwarding rules, filters and delegated access

This is the step people most often miss. Attackers create rules that forward copies of your mail to them or hide replies from your contacts. In Gmail on a computer, click the gear icon > See all settings. On the Forwarding and POP/IMAP tab, disable forwarding and remove unknown addresses. On Filters and Blocked Addresses, delete filters you did not make, especially ones that forward, delete, archive or mark messages as read. On Accounts and Import, check Send mail as and Grant access to your account, and remove anything unfamiliar. In Outlook.com, click the gear icon, open Mail > Rules and delete unknown rules, then check Mail > Forwarding and turn forwarding off unless you set it up. Also check automatic replies and your signature for strange links.

Step 5

Review connected apps and third-party access

A malicious app you approved can keep reading or sending your mail after you change the password, because it uses its own permission rather than your password. In your Google account, go to Security > Your connections to third-party apps & services, review each app's access, and remove any you do not recognize or no longer use, especially anything with permission to read, send or delete Gmail. For a Microsoft account, open your account dashboard, find the list of apps and services that can access your data, and remove unfamiliar ones. Also look at your email app list on your phone and remove the account from any old devices you no longer have. Success looks like only apps you knowingly use still having access.

Step 6

Turn on two-step verification and add a passkey

Two-step verification means a stolen password alone is no longer enough. In your Google account, go to Security > 2-Step Verification and turn it on, then add a passkey under Passkeys and security keys. In your Microsoft account, go to Security, turn on two-step verification, and add a passkey or the Microsoft Authenticator app. Prefer an authenticator app, a hardware security key or a passkey over text messages, which can be intercepted through SIM-swap attacks. Save the backup codes each service offers somewhere safe offline or in your password manager. If you are at higher risk, such as a journalist or public figure, consider Google's Advanced Protection Program. Success looks like a second-factor prompt the next time you sign in on a new device.

Step 7

Scan your devices for malware and bad extensions

If malware stole your password or session, it can steal the new one too, so scan every device you use for email. On Windows 10 or 11, open Windows Security > Virus & threat protection and run a Quick scan. Then open Scan options, choose Microsoft Defender Offline scan and select Scan now; the PC restarts and scans before Windows loads, catching threats that hide while Windows is running. Next, review browser extensions: in Chrome, open the three-dot menu > Extensions > Manage Extensions; in Edge, go to edge://extensions. Remove anything you do not recognize. On your phone, delete unfamiliar apps. If malware is found, remove it, then change your email password again from the cleaned device. Success looks like clean scans.

Step 8

Warn contacts and secure every account linked to your email

Check your Sent folder to see what the attacker sent, then let your contacts know your account was compromised and that they should ignore recent unusual messages, especially requests for money, gift cards or login details. Next, secure the accounts that use this email address for password resets, since an attacker with your inbox could have reset them. Change passwords, starting with banking, payment services, shopping, social media, cloud storage and any Apple, Google or Microsoft accounts, and check each for unfamiliar orders, payment changes or new devices. Change any password you reused anywhere. If money was taken or you suspect identity theft, contact your bank immediately and, in the US, report it at IdentityTheft.gov. Success looks like every linked account secured.

How to prevent it

  • Use a unique password for your email account that you have never used on any other site, and store it in a password manager.
  • Protect your email with a passkey, authenticator app or security key rather than relying on text-message codes.
  • Keep your recovery phone number and backup email up to date so you can always get back in quickly.
  • Run your provider's security checkup every few months to review devices, connected apps and forwarding settings.
  • Never sign in through links in unexpected emails or texts; open your email provider's site or app directly.
  • Keep Windows, your browser and your security software updated to reduce the risk of password-stealing malware.

Tools that can help

Your email provider's own recovery and security pages are all you need to get the account back. A password manager helps afterward by creating unique passwords for every account linked to your email, so one leak cannot unlock the rest, and by alerting you when a password shows up in a breach.

Top pick

1Password

A polished, end-to-end encrypted password manager with a device-generated Secret Key, Watchtower breach alerts, passkey support and easy family sharing across every major platform.

Try 1Password

Best free option

Bitwarden

An open-source, independently audited password manager whose free plan syncs unlimited passwords and passkeys across all your devices, with inexpensive Premium and Families upgrades.

Try Bitwarden

Best for privacy

Proton Pass

A fully end-to-end encrypted password manager from the makers of Proton Mail, with hide-my-email aliases that keep your real address out of future data breaches.

Try Proton Pass

TechyLeakz may earn a commission if you buy through these links, at no extra cost to you. Affiliate disclosure

What to do next if this fails

  • Move to the next fix instead of repeating the same step multiple times.
  • Check the related guides in this cluster before attempting a full reset.
  • If startup, update, and corruption symptoms overlap, widen the diagnosis instead of treating one error in isolation.

Advertisement

FAQ

What should I do if the hacker changed my recovery phone and email?

Use the provider's recovery process anyway. Google Account Recovery asks questions such as previous passwords and when you created the account, and it works best from a device and location you have used before. Microsoft offers an account recovery form that you complete using a different email address for contact. Answer as accurately as you can, and if the first attempt fails, try again from your usual device.

How do I know if someone else is reading my email?

Look for signs such as read messages you have not opened, sent emails you did not write, missing messages, and security alerts about new sign-ins. Check your account's device and sign-in activity pages for unfamiliar locations or devices. Also look for forwarding rules or filters you did not create, since attackers often use them to quietly copy or hide your mail without ever signing in again.

Will changing my password kick the hacker out?

Changing the password is essential but not always enough. Google signs you out on most devices when you change your password, and Microsoft offers options to sign out other sessions, but forwarding rules, app permissions, delegated access and app passwords can keep working. That is why you should also review forwarding, filters, connected apps and recovery details, and turn on two-step verification.

Should I delete my hacked email account and start a new one?

Usually not. Your email address is tied to banking, shopping and social accounts, so abandoning it creates more work and leaves those accounts pointing at an address you no longer control. Recover and secure it instead. Creating a new address makes sense only if you cannot regain access through official recovery, or if the old address is overwhelmed by spam after being widely exposed.

My account is sending spam but I can still sign in. Is it hacked?

Possibly. Check your Sent folder. If spam appears there, someone is using your account and you should follow every step in this guide. If nothing is in Sent, spammers may simply be spoofing your address in the From line, which does not require access to your account. Spoofing is annoying but harmless to the account itself; still, change your password if you have any doubt.

Can I get back emails the hacker deleted?

Check the Trash or Deleted Items folder first, along with Archive and any folders a malicious filter might move mail into. Outlook.com lets you recover recently deleted messages from Deleted Items using the option to recover items deleted from that folder. Gmail keeps items in Trash for 30 days. After that, recovery is limited, so check your provider's help pages for missing-email support.

Does a hacked email account mean my computer is infected?

Not necessarily, since most email takeovers come from reused or phished passwords. But malware that steals browser passwords and session cookies is common, and if your PC is infected, the attacker can capture your new password too. Run a full scan and a Microsoft Defender Offline scan, review your browser extensions, and change passwords again from a clean device if anything is found.

TechyLeakz

Search-first tech publishing focused on fixes, comparisons, and software recommendations.