Your e-mail account has been hacked: what to do in the first hour

The short answer: change the password from a clean device, end the open sessions, look for and delete the forwards and filters the intruder left, and only then deal with the damage: warn your contacts and change the passwords of the accounts that use this e-mail for password recovery. Order matters: if you do not close the door first, everything else gets undone again.

How to tell it was hacked

Sign What it means
Messages in “Sent” that you did not write Someone sent in your name, typically to the whole contact list.
Friends and customers get odd links from you Your account is being used to spread phishing.
A sign-in alert from another country or device Someone got in. Check the date and place.
You cannot sign in, the password changed The intruder changed it to lock you out.
Bounced messages you never sent Mass sending through your mailbox, often the only early clue.

The first hour, in order

1 Check the device you are working from. If the password was stolen by a program on your computer, changing it from there is no use. Use another device, or clean this one first.
2 Change the password to a long, unique one (see a strong password and a password manager). For a mailbox created in cPanel, see how to change an e-mail account password; if you can no longer get in, how to recover an e-mail account password.
3 End the other sessions and remove unknown devices, if your mail service has that option. Switch on two-step verification where available.
4 Look for what the intruder left behind. In “Forwarders” and “Email Filters” in cPanel, or in the Roundcube filters, delete any rule you did not create: they usually copy everything that arrives to an address of theirs, or delete your contacts’ replies so you do not notice. See filters in Roundcube.
5 Check the signature, the reply-to address and the folders for drafts and trash, where they may have deleted or hidden messages.
6 Change the passwords of accounts that depend on this e-mail: Meu Interweb, the bank, social networks, the shop. Whoever has your e-mail can request a password reset for all of them. Start with the most important.
7 Warn your contacts. A short message through another channel: “do not open links sent from my e-mail between such and such a time”.
If it was your company e-mail, the greater damage may be to those who trusted the messages. Check whether invoices or payment requests were sent with different accounts. See whether your server ended up on a blocklist: your server IP on a blocklist.
When all is calm, put in place what would have saved you: a long, unique password, two-step verification and a recovery e-mail outside your domain. It is all explained in locked out: password, two-step authentication and the recovery e-mail.

Is the mailbox on your account with us and you cannot get in, or are messages going out that you did not send? Write to us now.

Open a support ticket

SEE ALSO

A strong password and a password manager

How to change an e-mail account password

How to recover an e-mail account password

Your server IP on a blocklist: how to tell and how to get off

RECOMMENDED PRODUCT

Professional e-mail on your domain

Mailboxes in your company name, no adverts, with spam filtering. from 5.940,00 Kz/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?