How to Recover a Hacked Email Account in 2026: Easy Steps

You get a hacked email account back the same way everyone does: open your provider’s official account recovery page from a device and location you normally use, prove you own the mailbox, and change the password before anything else. Knowing how to recover a hacked email account is mostly about doing the right steps in the right order, because the intruder may have left forwarding rules, a connected app or a live session behind them. If you still control the recovery phone number or the backup email address, the first part usually takes under 30 minutes.

If the attacker changed the password, the recovery email and the phone number, expect a longer process involving a support request and waiting. That happens more often than providers admit, and it changes nothing about what you do first. Start immediately, from a device you trust, and never from a link in a message that alerted you to the problem.

Here is the order that works, whether you are locked out or still sitting in a mailbox somebody else has been reading.

Table of Contents

What You Need Before You Start

Recovering access is much faster when you can answer these before you open the recovery form. Nothing here is optional except the last item, and having them ready turns a two-week support thread into a ten-minute reset.

  • Access to the account. If you can still sign in, you do not need a recovery flow. Go straight to the password change screen and change it, even if nothing looks obviously wrong.
  • Your recovery email address. This is the second mailbox linked to the account. Check that inbox too, because the attacker may have changed it before you noticed.
  • A phone number you control. Providers lean on a code sent to the last verified number. If the account lists a number you do not recognise, stop and read step 2 closely, because that is where recovery gets hard.
  • Your current password. If you have it, put it in the password manager on your trusted device. Knowing an older password you used previously also helps during verification.
  • A trusted device and your normal network. Use the laptop or phone you usually sign in from, on your home or work connection. Providers weight the device and location you normally use as proof of ownership, so a public Wi-Fi hotspot at short notice is a bad place to start.
  • Contact details for a backup address and phone. You will replace whatever is currently listed once you are back in, so have a working alternative ready.
  • The “Your email address has been changed” notification. Search your other inbox for that exact subject line. Reddit users recovering hijacked accounts point to it again and again: the link inside it can reverse a change the attacker made.

Take two minutes now to write down which other accounts use this email as their login or password-reset address. Banking, payment apps, cloud storage and your Apple ID or Google account come first, and you will want that list later rather than guessing.

How to Recover a Hacked Email Account: Step-by-Step

1. Record What Happened and Check for Warning Signs

Record What Happened and Check for Warning Signs

Before you change anything, note down what you have found. If this is a work account, tell your IT team now and do not delete messages yourself, because the record of the compromise matters later.

The warning signs people actually see:

  • A password that stopped working, or security notices about a password you did not change.
  • Messages in your Sent folder you never wrote, often thank-you notes or wire requests with a reply-all.
  • Missing emails that may have been deleted or filtered out of view.
  • A recovery email address or phone number in settings that you did not enter.
  • A signature or automatic vacation reply you did not set up.
  • Password reset emails arriving for accounts you never touched, because your inbox is the recovery address for them.
  • Contacts telling you they got spam or a phishing link from your address.

One odd detail worth writing down: some people never get a security alert at all, because the attacker had already changed the address the alerts go to. That absence of notifications is not evidence that nothing happened.

2. Reset the Password From a Trusted Device

Run a full malware or spyware scan before you reset, not after. If a keylogger is still sitting on your machine, a brand-new password typed into that machine gets recorded the moment you type it. Update your operating system first, run the built-in Windows Defender or macOS scan, then add a second opinion with a dedicated tool, and only then reset.

Type the provider’s address yourself rather than following a link in an alert email. Generic phrases like “mail account recovery” are search ads, not support.

  • Gmail: accounts.google.com/signin/recovery. Verification routes include a last used password, a linked phone, the backup email, or the “Try another way” option.
  • Outlook / Hotmail: account.live.com/password/reset. Routes are security info, phone, alternative email, or a support request.
  • iCloud Mail: account.apple.com/sign-in/recovery. The strongest proof is an Apple device still signed in, then a trusted phone number, then Apple support.
  • Yahoo Mail: account.yahoo.com/has-recover-my-password. Routes are recovery phone, secondary email, or a support request.

If you are still signed in, open security settings and change the password there instead. When you do use the recovery form, choose Try another way whenever it appears, and complete as many prompts as it offers. Every route you clear makes the account look more thoroughly owned by you.

If the form keeps returning you to a phone number or email you do not control, the attacker changed it. Go to the provider’s support channel, and while you are waiting use the “Your email address has been changed” notification link to reverse what you can. People in the r/help and JustAnswer threads describe this taking weeks, sometimes more than a month, so open the request early and keep the ticket reference.

3. Check Recent Sessions and Sign Out Other Devices

A password reset does not always end live sessions. An attacker signed in on a phone or laptop can stay authenticated until you explicitly kill it.

In Gmail, open Google Account, then Security, then “Your devices”, and choose Manage all devices. In Outlook, go to Account, then Security, then Sign me out of all devices. iCloud has “Manage Devices” under account.apple.com. Yahoo keeps its sessions under recent account activity.

Read the recent activity list before you sign anything out, and look at location, device and time. Anything you cannot explain is a live breach, not an old artifact. Note it down, then sign out everywhere and change the password once more, since signing out alone does not always invalidate a stored credential.

If you see an unfamiliar device that reappears after signing out, remove that device’s authorisation as well and check connected apps in the next step.

4. Remove Unauthorized Forwarding Rules, Filters and Apps

This is the step people skip, and it is the one that lets an attacker keep reading everything you receive even after you change the password. Auto-forwarding rules and filters are settings, not credentials, so many of them survive a reset.

  • Gmail: Settings, then “See all settings”, then Forwarding and POP/IMAP, and then Filters and Blocked Addresses. Delete every rule and address you did not create.
  • Outlook: Settings, then Mail, then Rules, and check Junk Email settings for an allow list you never set. Connected apps sit under Account, then Privacy and Security.
  • iCloud Mail: iCloud.com, then Mail, then Rules, then edit and delete anything unfamiliar.
  • Yahoo: Settings, then Mailboxes, then Filters and Forwarding.

Next, review third-party access. In Gmail, open Security, then “Third-party connections” and remove anything unfamiliar. In Outlook, it is under the apps and services list. Any app you do not recognise can read your mail without ever seeing your password.

Check delegated access too. Someone with full mailbox permission reads and deletes mail without leaving a forwarding rule behind, and this is where a shared family or small business account gets compromised silently.

5. Restore Your Recovery Email, Phone and Mailbox Contents

Put your own details back before an attacker gets a second window: reset the recovery email, the backup phone number, any security questions, and the account signature or auto-reply. Old security questions are barely worth having because the answers are often discoverable from your own public posts, so prefer an authenticator app over questions.

Then work out what happened to your mail. Check Sent and Deleted for anything that should not be there, look in Spam and Trash, and confirm that mail you can see is actually arriving rather than being filtered away. Search for rules again after the reset, because a rule the attacker re-adds through a still-connected app looks exactly like a rule you already removed.

If messages were deleted rather than just hidden, most providers can restore them from Trash for a short window. Beyond that, ask support about recovery, and it helps to name the senders and dates you remember.

6. Enable Two-Factor Authentication

Enable Two-Factor Authentication

Turn on two-factor authentication, and choose the strongest method the provider will give you. In rough order of strength: a passkey or hardware security key, then an authenticator app, then SMS codes, and email codes last. SMS is beaten by “sneaky 2FA” attacks, where a fake sign-in page relays your code to the attacker in real time, and the code in your inbox is no better since an attacker sitting in your inbox can read it.

When you switch two-factor on, the provider shows recovery codes. Store them in your password manager or print them and keep them somewhere physically safe, because those codes are often the only way back in when a phone is lost or replaced.

Then open the two-step verification settings and check that only methods you added are listed. Attackers frequently register their own second factor so they return after a reset. Remove every entry that is not yours, and remove devices under “Devices you don’t recognize” at the same time.

7. Warn Contacts and Prevent a Repeat Attack

Contacts who trust you are the ones most likely to click. Send a short notice to the addresses that mattered, and tell them exactly what to look for. Here is a message people can copy and fill in:

Subject: Important: my email account was briefly compromised

Hi [name], my [Gmail/Outlook/etc.] account was taken over on [date] and I have now secured it. If you received any email from me between [start date] and [today] that asked you to click a link, open an attachment, send money, or buy gift cards, please ignore it and delete it. I will never ask you for passwords, codes or payments by email. If you already clicked something, tell me right away so I can help you sort it out. Sorry for the trouble.

For a work account, IT should handle the notification so the message goes out consistently and covers your company domain, and your team may need to warn clients directly if attacker mail went out under a signature your customers recognise.

Now work outward in priority order. Banking and payment accounts first, because they can send real money. Then your other email accounts, then cloud storage and the Apple ID or Google account tied to this address. Then shopping and social media. Change each password on the site’s own page, use a different password everywhere, and switch on two-factor as you go.

Once access is secure, report it. Start with the email provider, then use the national reporting body for where you live: identity.ftc.gov in the United States, Action Fraud in the United Kingdom, or your local cybercrime unit. File a report even if nothing was lost. Patterns from small incidents are how larger ones get caught.

Common Mistakes That Keep People Locked Out

  • Resetting from an untrusted device. A public library computer or a borrowed phone may still have a keylogger. Scan first, then reset from a machine you own. If that is not possible, use your phone on mobile data instead.
  • Clicking links inside the compromise notification. Attackers send fake “your account was hacked, click here” messages to your other inbox. Type the provider address yourself.
  • Ignoring recovery details until the end. If the recovery email and phone still point at the attacker, every later reset attempt loops you back to them. Change those two settings first, then verify by signing in from a second device.
  • Deleting evidence too early. Forwarding rules, filters, connected apps and unfamiliar devices are evidence as well as damage. Screenshot them before deleting, especially on a work account where IT may need them.
  • Assuming the reset fixed everything. Live sessions, forwarding rules, filters and delegated access all survive it. Walk steps 3 and 4 after every reset, not just the first.
  • Leaving two-factor on SMS. SIM swaps and fake sign-in pages defeat text codes. Move to an authenticator app or a passkey while you still have account access.
  • Creating a new account instead of recovering the old one. Every service tied to that address still points at a mailbox someone else controls.

One habit covers most of the list: keep passwords in a password manager, generated unique for each site. Credential stuffing reuses passwords stolen from one breach across thousands of accounts, so one reused password is how a single site compromise turns into your inbox being taken.

Frequently Asked Questions

Is it possible to recover a hacked email account?

Usually yes, and most people get back in on the first attempt through their provider’s recovery page. You need to prove ownership with things only you know: a password you previously used, a linked phone number, your recovery email, or signing in from a familiar device and location. If the attacker changed all of those, recovery still works but it goes through a support request, and users report waiting days to several weeks. Nothing you send from the account is beyond repair once you are back in.

Who do I contact if my email is hacked?

Contact the email provider first, through the sign-in page rather than a link in an alert email, and open a support request if the automatic recovery options are exhausted. After that, report to the national body for your country: identity.ftc.gov in the US, Action Fraud in the UK, or your local cybercrime unit. If a work account was taken, notify your IT team the same day. Report even if no money moved.

What happens if your email address is hacked?

Expect your contacts to receive your password, your inbox to receive password reset links for everything else you own, and your bank and payment apps to be next. An attacker can reset those accounts because your email is their recovery address, and they can read two-factor codes sent to it. They may also delete your mail to hide the intrusion. That blast radius is why banking and payment accounts get changed before anything else.

How do I get a hacker out of my email account?

You have to close four doors, not one. Sign out all devices and sessions, delete forwarding rules and filters, remove connected apps and delegated access, and delete any two-step verification method you did not add. Changing the password alone leaves forwarding rules, live sessions and third-party app access in place, which is why people think they are locked out again a week later.

Can I recover my email without the old password or a phone number?

Yes, often. A familiar device, your usual location, an older password you still remember, and a backup email address all count as proof, and the recovery form offers Try another way repeatedly until you run out of routes. Search your other inbox for a notification saying your email address was changed, because its link can reverse the change. With no verified route at all, support requests are the remaining path.

Should I delete my email account if it was hacked?

No. Your address is the login and recovery key for banking, cloud storage, your phone and your Apple or Google account. A new mailbox leaves every one of those pointing at the old address, and the attacker keeps it. Recover the account, clean the settings, rotate passwords elsewhere, and delete only if the provider tells you it cannot secure it.

Conclusion

The first priority is getting access back from a device and connection you trust, through the provider’s official recovery page, typed by hand rather than clicked from an alert. Scan for malware before you reset anything, then change the password and immediately close the other doors: sessions, forwarding rules, filters, connected apps and any second factor you did not add yourself.

After that, put your own recovery email and phone number back, switch two-factor authentication to an authenticator app or passkey, and change passwords on banking and payment accounts first. Warn your contacts with something short and specific, report the incident to your provider and your national reporting body, and this account stays yours.

Leave a Comment