Inbox
Email security

Why mailbox compromise spreads outward

What Happens If Your Email Account Gets Hacked?

A hacked mailbox can expose messages, reset links, contacts and recovery flows for other accounts. Recovery should include password changes, session review, forwarding-rule checks, MFA and recovery-setting cleanup.

9 min read

An email account is more than a place where messages arrive. For many services it is also a recovery channel. If an attacker controls the mailbox, the damage can therefore extend beyond reading email: they may reset other accounts, impersonate you to contacts, hide alerts or create forwarding rules that preserve access after you change the password.

What an attacker may gain from a compromised mailbox

CapabilityWhy it mattersWhat to inspect
Read messagesReceipts, personal details and account notices can reveal valuable contextInbox, archive and deleted folders
Request password resetsOther accounts may send recovery links into the compromised inboxSecurity emails and downstream account activity
Send as youContacts may trust messages coming from your real accountSent mail and reports from friends or coworkers
Create forwarding rulesNew mail can continue flowing to the attacker after the visible incidentForwarding, filters, delegates and connected apps
Change recovery settingsThe attacker can try to make future recovery harderRecovery email, phone, MFA methods and trusted devices

Recover the account in the right order

  1. 1

    Use the provider's official recovery process

    If you cannot log in, start with the mail provider's known recovery page rather than links sent by an unknown third party.

  2. 2

    Secure the device you are using

    The FTC recommends updating security software and scanning for suspicious software so a compromised device does not immediately expose the new credentials again.

  3. 3

    Change the password to a unique one

    Do not reuse a password that protects another service. If the old password was reused elsewhere, change those accounts too.

  4. 4

    Sign out other sessions

    End unfamiliar sessions and, where supported, sign out all devices before signing back in on trusted devices.

  5. 5

    Enable stronger authentication

    Turn on 2FA or another stronger method supported by the provider so a stolen password alone is less useful.

  6. 6

    Repair recovery and routing settings

    Check recovery addresses, phone numbers, forwarding rules, filters, delegates and connected apps for changes you did not make.

Why changing the password is necessary but not sufficient

A password change blocks one credential, but an attacker may already have an authenticated session, a malicious forwarding rule or a changed recovery method. The FTC specifically recommends signing out devices, checking recovery information and inspecting forwarding rules after regaining control.

This is also why a hacked mailbox should trigger review of downstream accounts. If the attacker had time to request resets or read security alerts, the incident may no longer be limited to email.

After you regain control

  • Review sent, deleted and security-notification folders for actions you did not take.
  • Tell contacts if messages were sent from your account so they do not trust malicious follow-ups.
  • Review important accounts that use this mailbox for password recovery.
  • Replace any reused password exposed by the incident.
  • Watch for new recovery changes or login alerts over the following days.

Mailbox recovery is complete only when you remove the attacker's ways back in and check the accounts that depended on that mailbox. Treat the incident as an identity-and-recovery problem, not just a password problem.

Put this threat in context

Sources and further reading

Need a separate inbox for a short-lived interaction?

Temporary email can reduce exposure of your durable address when future recovery is not important. It is one privacy layer, not a replacement for account security.

Create temporary email

Related security guides