You get a text from a cousin asking why you sent her a weird link. Then a friend forwards you a message from your own address asking for gift cards. Your stomach drops. Somebody is in your email.
Here is the thing worth understanding before it happens: your email account is not just where messages live. It is the master key. Nearly every other account you own resets its password by sending a link to that inbox. Whoever controls it can walk into your bank, your shopping accounts, your phone carrier, your photo library, one at a time, at their leisure. Which means the order you do things in actually matters. This is the plan we would follow, in the order we would follow it.
Why Email Is the Master Key
Think about the last time you forgot a password. You clicked the reset link, a message arrived in your inbox, and thirty seconds later you were back in. That convenience is the entire problem. It works exactly as well for a stranger.
So an email compromise is not one door. It is the hallway. That is why the first hour matters more than the next week, and why we tell people to fix the inbox completely before chasing anything else.
The First Hour, In Order
The Federal Trade Commission publishes consumer guidance on recovering a hacked email or social media account, and the sequence below follows it closely. Do these in order. Skipping ahead is how people end up locked out twice.
- Use a device you trust. The FTC advises updating your security software and running a scan first, because if the break in started with malicious software on your computer, a new password just gets stolen too. If you are unsure about the machine, do the recovery from a different device you know is clean.
- Get back in and change the password. If you can still sign in, change it immediately. If you are locked out, use the provider’s account recovery process. Every major email provider has one, and it is the only route that works. Make the new password long and used nowhere else.
- Sign out everywhere else. The FTC puts it plainly: sign out of all devices, so “anyone who’s logged in to your account on another device will get kicked out.” A password change alone does not always end an existing session. This step does. Look for a security section listing devices or active sessions.
- Turn on a stronger sign in. The FTC recommends enabling two factor authentication, also called two step verification, if it is available. Do it before cleaning anything else, so the attacker cannot walk back in behind you. If your provider offers a passkey or hardware key, pick that: the Cybersecurity and Infrastructure Security Agency describes FIDO based authentication as the only widely available phishing resistant form of multifactor authentication, and calls text message codes a last resort.
- Check your recovery email and phone number. The FTC specifically says to confirm the recovery addresses and phone numbers listed are ones you entered. Attackers change these so they can take the account back later. If something unfamiliar is there, remove it.
The Part Almost Everyone Skips
You changed the password, you feel better, you move on. Two months later the same thing happens again and nobody understands why. It is usually because of the quiet settings the attacker left behind. The FTC advises checking your email settings for forwarding rules you did not create and deleting them. Microsoft’s guidance for a compromised Outlook.com account tells users to review connected accounts, forwarding settings, and automatic replies for the same reason.
These are the hiding places. Look at every one:
- Forwarding. A rule that quietly copies every incoming message to an address you have never seen. This is the most common one, and it survives a password change untouched.
- Filters and rules. Instructions that automatically delete or archive messages containing words like “password,” “security alert,” or your bank’s name, so you never see the warnings.
- Automatic replies. An out of office message can be used to answer your contacts on your behalf.
- Connected accounts and app access. Third party apps and linked accounts that were authorized to read your mail. Revoke anything you do not recognize.
- Sent and deleted folders. The FTC recommends checking both, since the sent folder shows what went out in your name and the deleted folder shows what the attacker read and discarded.
Most of these settings live in the same general area of your email settings, usually a section named something like forwarding, rules, or filters. The exact wording varies by provider and changes over time, so browse the settings rather than hunting for a specific menu path.
Then Work Outward Through Everything That Resets Through That Inbox
Now the inbox is genuinely yours again. The next job is figuring out where else the key opened a door. Search your own mailbox for the words “welcome,” “verify,” and “receipt” and you will get a surprisingly complete inventory of your online life.
- Money first. Banking, credit cards, payment apps, investment accounts. New password, check recent activity, turn on alerts for transactions.
- Then identity. Your phone carrier and your domain or web host if you have one. Control of a phone number can defeat text message verification codes elsewhere.
- Then shopping and travel. Anywhere a saved card or stored address lives.
- Then social and everything else. Lower stakes, but worth doing because these accounts get used to scam the people who trust you.
- Stop reusing passwords while you are in there. The reason one break in becomes six is a shared password. A password manager solves this permanently and is the single highest value habit change available to a normal person.
Tell Your People Before the Scam Does
This part feels embarrassing and it is the most valuable thing you will do all day. Whoever got in has your contact list, and the standard next move is to message everyone in it while wearing your name. Those messages work, because they arrive from a real address with real history behind them. If you want to understand why these attacks keep succeeding against sensible people, our piece on why phishing remains so hard to block gets into the mechanics.
The FTC’s advice here is refreshingly simple: send your friends a quick email or text, or post something, to let them know about the hack. Keep it short and unglamorous. Something like: “My email was compromised earlier today. If you got anything odd from me, please delete it and do not click anything. It is handled now.” No apology necessary. You did not do anything wrong.
The Bottom Line
Email compromise is common, recoverable, and much less painful when you already know the running order: get back in from a clean device, sign out everyone else, turn on stronger sign in, hunt down the forwarding rules and filters, verify your recovery contacts, then work outward through the accounts that reset through that inbox, and tell your people.
Better still, spend twenty minutes this week making the whole scenario unlikely. Put a unique password on your email, turn on the strongest second step your provider offers, and glance at your forwarding settings while you are there. Our comparison of hardware keys, passkeys, and ordinary multifactor authentication explains which one is worth having.
If you are in the middle of one of these right now and the order is not obvious, or you cleaned up and still feel unsure that it is over, we are happy to talk it through. We do this work for businesses across Denton County, and the personal version follows the same map. Contact us today
Sources:

Comments are closed