top of page
it support sheffield

Email Account Security

What to Do When Your Email Has Been Hacked

By Steve Harper  |  8 min read  | Last updated:

6 August 2026 at 10:39:42

In this guide:

- What it means when your email has been hacked


- Common signs your email account has been compromised


- Immediate actions to take in the first 15 minutes


- How to check for suspicious forwarding rules and account changes


- How to secure your device and reset passwords safely


- Who to notify after an email account compromise


- How to prevent future email account compromise


- How IT Desk can help with email security and Microsoft 365 protection

TL;DR

If your email has been hacked, act quickly to regain control, change your password, enable multi-factor authentication and check for suspicious forwarding rules, mailbox rules, connected apps and active sessions. A compromised email account can be used to steal data, reset other passwords, impersonate your business or send phishing emails to contacts.


Key Takeaways

  • Change your email password immediately using a strong, unique password.

  • Enable multi-factor authentication to reduce the risk of further unauthorised access.

  • Sign out of all active sessions and remove suspicious connected apps or app passwords.

  • Check forwarding rules, mailbox rules and auto-replies that attackers may have created.

  • Warn colleagues, customers or suppliers if suspicious emails may have been sent from your account.

  • Review whether any personal data or sensitive business information may have been exposed.

  • IT Desk can help businesses secure email accounts, review Microsoft 365 settings and reduce the risk of future compromise.

What NOT to do

  • Don’t assume it’s fixed after changing the password.

  • Don’t ignore forwarding rules or app permissions.

  • Don’t delay internal communication. Silence increases risk to others.


Containment and remediation

Once immediate access is removed:

  • Reset passwords for any linked or reused credentials

  • Remove unauthorised rules, forwarding, and app access

  • Review MFA and conditional access policies

  • Monitor login activity closely for several days

  • Scan endpoints used by the affected user


Do you need to tell anyone?

You may need to notify:

Internal teams if phishing was sent

Clients or suppliers if they may receive fraudulent messages

Compliance/legal teams if sensitive or personal data was accessed


Whether external reporting is required depends on the data involved and confirmed exposure.


Preventing future email compromises

Most email hacks exploit:

  • Weak or reused passwords

  • Missing MFA

  • Poor visibility into account activity


Key preventative measures include:

  • MFA for all email accounts

  • Conditional access policies

  • Regular mailbox and sign-in reviews

  • User awareness around phishing

  • Monitoring for suspicious rules and app access


Signs the attacker may still have access

After remediation, watch for:

  • Rules or forwarding reappearing

  • Repeated MFA prompts

  • Unexpected password resets

  • Login attempts from unfamiliar locations

  • Continued reports of suspicious emails


Any of these should be treated as an active incident.


People Also Ask

How do I know if my email has been hacked?

Common signs of a hacked email account include password reset emails you did not request, messages sent from your account that you do not recognise, login alerts from unknown locations, missing emails, changed settings, unusual forwarding rules or contacts receiving suspicious messages from you.


What should I do first if my email has been hacked?

The first step is to regain control of the account and change the password using a strong, unique password. You should then enable multi-factor authentication, sign out of all devices, check account recovery details, review forwarding rules and look for suspicious connected apps or active sessions.


Should I tell my contacts if my email has been hacked?

Yes, if suspicious emails may have been sent from your account. Warn contacts not to click links, open attachments, reply to unusual requests or send money or information based on messages that appear to come from you. This is especially important for business email accounts.


Can a hacked email account lead to a data breach?

Yes. A hacked email account can lead to a data breach if personal data, customer information, employee records, financial information or sensitive business data has been accessed, disclosed or stolen. Businesses should assess what information may have been exposed and whether reporting obligations apply.


Can IT Desk help secure a hacked business email account?

Yes. IT Desk can help businesses secure hacked email accounts by reviewing Microsoft 365 sign-ins, resetting access, checking forwarding rules, improving MFA, reviewing security settings and helping reduce the risk of future phishing or account compromise.


How can I prevent my email from being hacked again?

You can reduce the risk by using strong unique passwords, enabling multi-factor authentication, keeping devices updated, avoiding suspicious links and attachments, reviewing account recovery details, using phishing protection and regularly checking account activity and forwarding rules.

Need help securing a hacked email account?


IT Desk helps businesses secure Microsoft 365 email accounts, review sign-in activity, check suspicious forwarding rules, improve multi-factor authentication and reduce the risk of future compromise. We can help you regain confidence in your email security and protect users from phishing and account takeover.



What does it mean if your email has been hacked?

An email account is considered “hacked” when an unauthorised party gains access and can read, send, delete, or manipulate messages. This often happens after a phishing attack, password reuse, or compromised credentials.


Because email is the gateway to many other systems, a hacked inbox can quickly lead to:

  • Data theft

  • Invoice and payment fraud

  • Internal phishing

  • Wider account compromise across cloud services


Common signs your email has been compromised

You may notice:

  • Emails sent that you didn’t write

  • Password reset notifications you didn’t request

  • Missing or deleted emails

  • New mailbox rules or auto-forwarding

  • Login alerts from unfamiliar locations

  • Contacts reporting suspicious messages from you


Even subtle signs should be taken seriously.


Immediate actions (first 15 minutes)

  1. Change the email password immediately Use a strong, unique password that isn’t used anywhere else.

  2. Revoke active sessions Force sign-out across all devices to remove attacker access.

  3. Enable or confirm MFA Check that MFA is active and review registered methods (apps, phone numbers).

  4. Preserve evidence Save examples of suspicious emails, login alerts, and rule changes.Note the time the issue was first noticed.


Check forwarding rules, mailbox rules and active sessions

After changing your password, check whether the attacker has changed any settings that could let them keep access or continue receiving information.


Review:


- Email forwarding rules that send messages to an unknown external address.

- Mailbox rules that move, delete or hide messages.

- Auto-replies or signatures that have been changed.

- Connected apps or third-party services you do not recognise.

- App passwords or legacy authentication settings.

- Active sessions or signed-in devices you do not recognise.

- Password reset emails or security alerts from other services.


If this is a business Microsoft 365 account, an administrator should also review sign-in logs, risky sign-ins, mailbox rules, MFA settings and any unusual changes to user permissions.


Check for silent persistence (critical step)

Attackers often try to maintain access even after a password reset.


Check for:

  • Mailbox rules that auto-delete or forward emails

  • Email forwarding to external addresses

  • OAuth / third-party app access you don’t recognise

  • Recovery email or phone number changes

  • Admin role changes (for business accounts)


This step is frequently missed — and it’s how attackers regain access later.


Assess what else may be affected

A hacked email account is often used to pivot into other systems.


Review:

  • Cloud storage (OneDrive, SharePoint)

  • CRM and finance platforms

  • Password reset activity for other services

  • Internal systems that rely on email for authentication

  • Recent invoices, payment details, or supplier communications


If email was used for password resets elsewhere, those accounts should be treated as compromised too.

Why it matters

A hacked email account can quickly create serious problems for a business. Attackers may use the account to read sensitive information, reset passwords, impersonate employees, send phishing emails, change forwarding rules or access other connected services.


This guide explains what to do when your email has been hacked, how to secure the account, what to check after regaining access, and how businesses can reduce the risk of future email compromise.

Email Hack Response

Related Insights

So, why IT Desk?

deceleration.png

Proactive & Reactive Support

In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.

Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

trophy.png

Award Winning

Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!

Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

certified.png

Experienced & Certified

Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.

 

From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent

Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.

With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.

Chris W.png
Steve Harper.png
BG---Name---Chloe-Day.png
BG---Name---Morgan-C.png

Experts in the field. Driven by success.

Speak to our team today.

IT Desk are a leader in business growth through consultancy. Contact us today for a no-obligation chat. Your Success, We’re Part of IT.

Book a meeting with our team.

Click below to see our live calendar and book a meeting with our team of experts.

Innovative Solutions for Businesses

20+

Years of Experience

A legacy of excellence in digital solutions.

100%

Zero Carbon

Doing our part for the environment.

Certified by British Gas.

99.9%

Client Satisfaction Rate

Trusted by businesses across all sectors for superior service.

1200+

Projects Completed

Delivering cutting-edge solutions for a seamless digital future.

bottom of page