If you think you have an email account compromised, act quickly but avoid rushing into random changes. The priority is to regain control, stop unauthorized access, and preserve useful evidence.

An attacker may read messages, send mail, create hidden forwarding rules, or change recovery details. A password reset helps, but it does not always end active sessions or remove every backdoor. If you suspect an email account compromised, use the sequence below for a careful first response.
Confirm the warning without clicking risky links
Start by deciding what triggered your concern. Common signs include unfamiliar sent messages, unexpected password alerts, missing mail, new login notifications, or contacts receiving suspicious requests.
Do not use a reset link from an unexpected email or text. Instead, open the provider’s known website or its official application. Type the address yourself, use a saved bookmark, or contact the provider through a trusted channel.
Phishing is a fake message designed to steal credentials or payment details. Review CISA guidance on recognizing and reporting phishing before responding to a suspicious message.
- Do not reply to the suspicious message.
- Avoid opening unknown attachments.
- Never approve an unexpected MFA prompt.
- Record the alert, sender, time, and visible login details.
If the account controls business email, tell a responsible manager or service provider. Keep the notification factual. Avoid deleting evidence before someone reviews it.
Reset the password after an email account compromise
Use a device you trust and update the password through the provider’s account security page. Choose a long, unique password that you have not used for another service. A password manager can help create and store it.
Changing the password is the first major containment step. However, it may not remove a thief who already authenticated. Therefore, continue through the remaining steps even after the reset succeeds. If the account remains an email account compromised risk, continue checking every control below.
Check for password reuse
If the same password protected other accounts, change those accounts too. Start with administrator accounts, banking access, cloud storage, domain registration, payroll, and password-manager access.
Change reused passwords from trusted devices. Never send new passwords through ordinary email or place them in a shared document.
For a broader baseline, compare your process with this small business cybersecurity checklist. It covers practical safeguards beyond one mailbox.
Revoke active sessions and connected access
Look for controls named “sign out everywhere,” “active sessions,” “recent activity,” or “connected applications.” Sign out devices and browser sessions you do not recognize. If the provider offers a global sign-out option, use it when appropriate.
Also review third-party applications. An attacker may use an approved connection instead of the main password. Remove unknown applications and old integrations. Check email clients, mobile devices, desktop applications, and automation tools.
Session revocation can force old browser tokens to expire. A token is a temporary credential that lets an application stay signed in. Provider behavior differs, so verify the result in the account activity page.
Avoid removing a known business integration without checking its purpose. Some tools send invoices, process support tickets, or archive messages. Record the application name before disconnecting it.
Enable MFA and review the authentication methods
Multifactor authentication, or MFA, requires an additional proof beyond the password. That proof might come from an authenticator app, security key, or text message.
Enable MFA after securing the password, then review every registered method. Remove unknown phone numbers, authenticator devices, security keys, and backup codes. Generate new backup codes if the provider supports them.
An attacker who added their own MFA method may keep control after a password change. Look for recent security changes and unfamiliar device names. Business administrators should review whether the account belongs to a larger identity system.
Prefer an authenticator app or security key when the provider and business process support it. Text messages can still help, but they depend on phone-account security. Never approve a login prompt you did not initiate.
Inspect forwarding rules, filters, and mailbox access
Attackers often hide their activity with mail settings. Review forwarding addresses, inbox rules, filters, delegated access, automatic replies, signatures, and blocked senders.
- Remove forwarding to addresses no one recognizes.
- Disable rules that delete, archive, or mark messages as read.
- Check rules that move invoices, password alerts, or security notices.
- Review delegate and shared-mailbox permissions.
- Inspect automatic replies and signatures for changed content.
Search the mailbox for terms such as “forward,” “password,” “invoice,” “wire,” and “security.” The exact search syntax depends on the provider. Check sent, deleted, archived, and trash folders.
Do not assume that a missing message was deleted. A rule may have moved it, or another connected application may have downloaded it. Export or document suspicious settings before removing them when an investigation may follow.
Review email account recovery settings and ownership
Open the recovery section and confirm the phone number, alternate email address, identity details, and trusted contacts. Remove information that an attacker added. Then confirm that your own recovery methods still work.
Review security questions if the provider still uses them. Replace weak answers where possible, and do not use answers that anyone can find on public profiles.
Business accounts need an extra check. Confirm the account’s administrator, license owner, recovery administrator, and organization domain. A personal recovery address may create confusion during a workplace incident.
Keep a dated record of changes. Include who made each change and which account or mailbox it affected. This simple record helps with follow-up, reporting, and recovery planning.
Check the devices that accessed the mailbox
Secure the account and the devices together. Review recent sign-ins for unfamiliar locations, browsers, operating systems, and times. Location data can be approximate, so treat it as a clue rather than proof.
Run current security checks on computers and phones that used the account. Install pending operating-system and browser updates from their normal update tools. Remove unknown browser extensions and applications.
If the device shows signs of malware, do not use it for another password reset. Disconnect it from networks when practical, then use a known-clean device or ask a qualified technician for guidance.
Pay attention to password-stealing malware, remote-control software, and fake browser prompts. Do not install a “security tool” offered through a pop-up or unsolicited phone call. A suspected email account compromised situation may involve the device as well as the mailbox.
Review business impact and notify the right people
After access is under control, determine what the mailbox could expose. Check messages involving payroll, vendors, customer data, contracts, tax records, passwords, and payment instructions.
Contact vendors or customers who may have received fraudulent instructions. Use a known phone number, not the contact details in a suspicious message. Warn staff not to trust recent payment or password requests from the affected account.
If the incident involves personal information, regulated data, financial loss, or a high-value business account, involve legal counsel, an insurer, or an incident-response provider. Notification duties depend on the facts and your location.
Use the NIST Cybersecurity Framework as a useful structure for identifying, protecting, detecting, responding to, and recovering from the wider risk.
For account or device issues that affect other business systems, review the remote support service options available to your organization.
What not to do after a suspected takeover
- Avoid using a suspicious device for sensitive changes.
- Preserve relevant evidence before deleting messages.
- Remember that a password reset alone may not be enough.
- Warn coworkers before forwarding suspicious mail.
- Treat a familiar login location as a clue, not proof of legitimacy.
When possible, preserve alert emails, sign-in records, rule details, and timestamps. Avoid changing unrelated systems until you understand the scope.
Build a recovery plan for next time
A good response becomes easier when account ownership and escalation paths are documented. List administrators, recovery contacts, critical mailboxes, connected applications, and approved MFA methods.
Separate administrator accounts from everyday accounts. Limit mailbox delegation and review it periodically. Make sure more than one authorized person can recover a business account without sharing passwords.
Train staff to report suspicious messages quickly. The goal is not perfect recognition. The goal is fast reporting before someone clicks, pays, or shares credentials.
An email account compromised response should protect both the mailbox and the business relationships connected to it. Treat email as a gateway to other systems, not as an isolated application.
When to ask for professional help
If you cannot revoke sessions, identify unauthorized rules, verify administrator access, or determine which data was exposed, pause further changes. Tech Rescue Ops LLC can help review the account, connected systems, devices, and recovery steps remotely. Professional assistance is especially appropriate when several mailboxes, administrators, or business-critical integrations may be involved.
