.png)
Email Account Security
What to Do When Your Email Has Been Hacked
By Steve Harper | 8 min read | Last updated:
6 August 2026 at 10:39:42
In this guide:
- What it means when your email has been hacked
- Common signs your email account has been compromised
- Immediate actions to take in the first 15 minutes
- How to check for suspicious forwarding rules and account changes
- How to secure your device and reset passwords safely
- Who to notify after an email account compromise
- How to prevent future email account compromise
- How IT Desk can help with email security and Microsoft 365 protection
TL;DR
If your email has been hacked, act quickly to regain control, change your password, enable multi-factor authentication and check for suspicious forwarding rules, mailbox rules, connected apps and active sessions. A compromised email account can be used to steal data, reset other passwords, impersonate your business or send phishing emails to contacts.
Key Takeaways
Change your email password immediately using a strong, unique password.
Enable multi-factor authentication to reduce the risk of further unauthorised access.
Sign out of all active sessions and remove suspicious connected apps or app passwords.
Check forwarding rules, mailbox rules and auto-replies that attackers may have created.
Warn colleagues, customers or suppliers if suspicious emails may have been sent from your account.
Review whether any personal data or sensitive business information may have been exposed.
IT Desk can help businesses secure email accounts, review Microsoft 365 settings and reduce the risk of future compromise.
What NOT to do
Don’t assume it’s fixed after changing the password.
Don’t ignore forwarding rules or app permissions.
Don’t delay internal communication. Silence increases risk to others.
Containment and remediation
Once immediate access is removed:
Reset passwords for any linked or reused credentials
Remove unauthorised rules, forwarding, and app access
Review MFA and conditional access policies
Monitor login activity closely for several days
Scan endpoints used by the affected user
Do you need to tell anyone?
You may need to notify:
Internal teams if phishing was sent
Clients or suppliers if they may receive fraudulent messages
Compliance/legal teams if sensitive or personal data was accessed
Whether external reporting is required depends on the data involved and confirmed exposure.
Preventing future email compromises
Most email hacks exploit:
Weak or reused passwords
Missing MFA
Poor visibility into account activity
Key preventative measures include:
MFA for all email accounts
Regular mailbox and sign-in reviews
User awareness around phishing
Monitoring for suspicious rules and app access
Signs the attacker may still have access
After remediation, watch for:
Rules or forwarding reappearing
Repeated MFA prompts
Unexpected password resets
Login attempts from unfamiliar locations
Continued reports of suspicious emails
Any of these should be treated as an active incident.
People Also Ask
How do I know if my email has been hacked?
Common signs of a hacked email account include password reset emails you did not request, messages sent from your account that you do not recognise, login alerts from unknown locations, missing emails, changed settings, unusual forwarding rules or contacts receiving suspicious messages from you.
What should I do first if my email has been hacked?
The first step is to regain control of the account and change the password using a strong, unique password. You should then enable multi-factor authentication, sign out of all devices, check account recovery details, review forwarding rules and look for suspicious connected apps or active sessions.
Should I tell my contacts if my email has been hacked?
Yes, if suspicious emails may have been sent from your account. Warn contacts not to click links, open attachments, reply to unusual requests or send money or information based on messages that appear to come from you. This is especially important for business email accounts.
Can a hacked email account lead to a data breach?
Yes. A hacked email account can lead to a data breach if personal data, customer information, employee records, financial information or sensitive business data has been accessed, disclosed or stolen. Businesses should assess what information may have been exposed and whether reporting obligations apply.
Can IT Desk help secure a hacked business email account?
Yes. IT Desk can help businesses secure hacked email accounts by reviewing Microsoft 365 sign-ins, resetting access, checking forwarding rules, improving MFA, reviewing security settings and helping reduce the risk of future phishing or account compromise.
How can I prevent my email from being hacked again?
You can reduce the risk by using strong unique passwords, enabling multi-factor authentication, keeping devices updated, avoiding suspicious links and attachments, reviewing account recovery details, using phishing protection and regularly checking account activity and forwarding rules.
Need help securing a hacked email account?
IT Desk helps businesses secure Microsoft 365 email accounts, review sign-in activity, check suspicious forwarding rules, improve multi-factor authentication and reduce the risk of future compromise. We can help you regain confidence in your email security and protect users from phishing and account takeover.
What does it mean if your email has been hacked?
An email account is considered “hacked” when an unauthorised party gains access and can read, send, delete, or manipulate messages. This often happens after a phishing attack, password reuse, or compromised credentials.
Because email is the gateway to many other systems, a hacked inbox can quickly lead to:
Data theft
Invoice and payment fraud
Internal phishing
Wider account compromise across cloud services
Common signs your email has been compromised
You may notice:
Emails sent that you didn’t write
Password reset notifications you didn’t request
Missing or deleted emails
New mailbox rules or auto-forwarding
Login alerts from unfamiliar locations
Contacts reporting suspicious messages from you
Even subtle signs should be taken seriously.
Immediate actions (first 15 minutes)
Change the email password immediately Use a strong, unique password that isn’t used anywhere else.
Revoke active sessions Force sign-out across all devices to remove attacker access.
Enable or confirm MFA Check that MFA is active and review registered methods (apps, phone numbers).
Preserve evidence Save examples of suspicious emails, login alerts, and rule changes.Note the time the issue was first noticed.
Check forwarding rules, mailbox rules and active sessions
After changing your password, check whether the attacker has changed any settings that could let them keep access or continue receiving information.
Review:
- Email forwarding rules that send messages to an unknown external address.
- Mailbox rules that move, delete or hide messages.
- Auto-replies or signatures that have been changed.
- Connected apps or third-party services you do not recognise.
- App passwords or legacy authentication settings.
- Active sessions or signed-in devices you do not recognise.
- Password reset emails or security alerts from other services.
If this is a business Microsoft 365 account, an administrator should also review sign-in logs, risky sign-ins, mailbox rules, MFA settings and any unusual changes to user permissions.
Check for silent persistence (critical step)
Attackers often try to maintain access even after a password reset.
Check for:
Mailbox rules that auto-delete or forward emails
Email forwarding to external addresses
OAuth / third-party app access you don’t recognise
Recovery email or phone number changes
Admin role changes (for business accounts)
This step is frequently missed — and it’s how attackers regain access later.
Assess what else may be affected
A hacked email account is often used to pivot into other systems.
Review:
Cloud storage (OneDrive, SharePoint)
CRM and finance platforms
Password reset activity for other services
Internal systems that rely on email for authentication
Recent invoices, payment details, or supplier communications
If email was used for password resets elsewhere, those accounts should be treated as compromised too.
Why it matters
A hacked email account can quickly create serious problems for a business. Attackers may use the account to read sensitive information, reset passwords, impersonate employees, send phishing emails, change forwarding rules or access other connected services.
This guide explains what to do when your email has been hacked, how to secure the account, what to check after regaining access, and how businesses can reduce the risk of future email compromise.

Related Insights
So, why IT Desk?

Proactive & Reactive Support
In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.
Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

Award Winning
Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!
Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

Experienced & Certified
Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.
From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent
Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.
With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.

Innovative Solutions for Businesses
20+
Years of Experience
A legacy of excellence in digital solutions.
100%
Zero Carbon
Doing our part for the environment.
Certified by British Gas.
99.9%
Client Satisfaction Rate
Trusted by businesses across all sectors for superior service.
1200+
Projects Completed
Delivering cutting-edge solutions for a seamless digital future.











