Why mailbox compromise spreads outward
What Happens If Your Email Account Gets Hacked?
A hacked mailbox can expose messages, reset links, contacts and recovery flows for other accounts. Recovery should include password changes, session review, forwarding-rule checks, MFA and recovery-setting cleanup.
An email account is more than a place where messages arrive. For many services it is also a recovery channel. If an attacker controls the mailbox, the damage can therefore extend beyond reading email: they may reset other accounts, impersonate you to contacts, hide alerts or create forwarding rules that preserve access after you change the password.
What an attacker may gain from a compromised mailbox
| Capability | Why it matters | What to inspect |
|---|---|---|
| Read messages | Receipts, personal details and account notices can reveal valuable context | Inbox, archive and deleted folders |
| Request password resets | Other accounts may send recovery links into the compromised inbox | Security emails and downstream account activity |
| Send as you | Contacts may trust messages coming from your real account | Sent mail and reports from friends or coworkers |
| Create forwarding rules | New mail can continue flowing to the attacker after the visible incident | Forwarding, filters, delegates and connected apps |
| Change recovery settings | The attacker can try to make future recovery harder | Recovery email, phone, MFA methods and trusted devices |
Recover the account in the right order
- 1
Use the provider's official recovery process
If you cannot log in, start with the mail provider's known recovery page rather than links sent by an unknown third party.
- 2
Secure the device you are using
The FTC recommends updating security software and scanning for suspicious software so a compromised device does not immediately expose the new credentials again.
- 3
Change the password to a unique one
Do not reuse a password that protects another service. If the old password was reused elsewhere, change those accounts too.
- 4
Sign out other sessions
End unfamiliar sessions and, where supported, sign out all devices before signing back in on trusted devices.
- 5
Enable stronger authentication
Turn on 2FA or another stronger method supported by the provider so a stolen password alone is less useful.
- 6
Repair recovery and routing settings
Check recovery addresses, phone numbers, forwarding rules, filters, delegates and connected apps for changes you did not make.
Why changing the password is necessary but not sufficient
A password change blocks one credential, but an attacker may already have an authenticated session, a malicious forwarding rule or a changed recovery method. The FTC specifically recommends signing out devices, checking recovery information and inspecting forwarding rules after regaining control.
This is also why a hacked mailbox should trigger review of downstream accounts. If the attacker had time to request resets or read security alerts, the incident may no longer be limited to email.
After you regain control
- Review sent, deleted and security-notification folders for actions you did not take.
- Tell contacts if messages were sent from your account so they do not trust malicious follow-ups.
- Review important accounts that use this mailbox for password recovery.
- Replace any reused password exposed by the incident.
- Watch for new recovery changes or login alerts over the following days.
Mailbox recovery is complete only when you remove the attacker's ways back in and check the accounts that depended on that mailbox. Treat the incident as an identity-and-recovery problem, not just a password problem.
Put this threat in context
Sources and further reading
Need a separate inbox for a short-lived interaction?
Temporary email can reduce exposure of your durable address when future recovery is not important. It is one privacy layer, not a replacement for account security.
Create temporary email