Skip to content
All guides

Account security

How to Recover a Hacked Email Account

A hijacked inbox is an emergency because it resets other accounts. This guide follows official recovery steps without asking you to share the password.

By the 4safer teamUpdated August 29, 20268 minutes read

Signs the inbox is no longer only yours

The Federal Trade Commission lists practical clues: friends get mail you did not send, you cannot sign in, or you see a login alert that was not you. Also look for:

Do not confirm those clues by clicking a “restore access now” button inside a stranger’s message. Type the real webmail domain.

  • Password-reset messages for banks you did not request
  • Filters that hide security mail
  • A recovery phone or address you never added
  • Drafts or sent items that ask relatives for money

Get back in through the provider, not a helper in chat

The FTC’s recovery page is direct: update security software, run a scan if you suspect malware, then follow the provider’s own instructions. Popular services publish those flows on their official sites. If you can still sign in:

If you cannot sign in, use “Forgot password” or “Help signing in” on the typed official domain. You may need a backup code, an old device, or a passkey. A person who emailed you first is not the recovery team. How to recover a hacked email account is a provider process. Paying a “specialist” who wants remote access is a second incident.

  • Change the password to a long unique one.
  • Sign out of all devices.
  • Turn on two-factor authentication or a passkey.
  • Check recovery email and phone.

What to inspect the minute you are inside

The FTC tells people who regain control to look for forwarding rules and delete any they did not create. Also open:

If mail was used to reset a bank, call the bank on the number on the card. Do not wait for the next statement.

  • Connected apps and app passwords
  • Recent security activity
  • Filters and auto-forward
  • Display name and signature changes
  • Vacation responders that ask contacts to send codes

After you take the mailbox back

Secure the account, then the accounts it owns.

Then walk the reset list: banking, payroll, tax, Apple or Google, shopping, social. Reused passwords go first. If the takeover included new credit or tax activity, that is identity theft. Report it at IdentityTheft.gov.

  • Unique password in a password manager
  • Passkey or authenticator app, not SMS only if you have a better option
  • Login alerts turned on
  • A second recovery method you actually control
  • A note to close contacts if the attacker sent mail in your name, as the FTC suggests after a social or email hack

If the provider will not give the account back

Stay on official support. Keep case numbers. Use another email you control to talk to banks so you are not waiting in silence. You may need to:

No article can promise the provider will restore every account. Official recovery is still the only safe path.

  • Open a new mailbox and move recovery addresses on other sites
  • Tell contacts the old address is unsafe
  • Watch credit if identity data may also have been used

Reduce the chance of a second lockout

CISA’s household list still applies: unique passwords, multifactor authentication, updates, and caution with links. Email is the account that deserves the strongest method the service offers. Store backup codes offline or in a manager. Do not keep them in the same inbox. Learning how to recover a hacked email account is useful. Building a mailbox that needs more than a leaked password is what keeps you from repeating the week.

Practical checklist

  • Type the official webmail domain.
  • Use the provider’s recovery flow if you are locked out.
  • Change the password and sign out all sessions.
  • Enable MFA or a passkey.
  • Delete unknown forwarding and recovery methods.
  • Reset reused passwords on money accounts.
  • Notify contacts if fake mail went out.
  • Report identity misuse at IdentityTheft.gov.

Frequently asked questions

Should I delete the email address after a hack?

Usually no. Recover it, lock it, and keep it so other sites can still find you. Create a new address only if recovery fails.

Can I trust a pop-up that says the provider is on the line?

No. Hang up or close the chat. Sign in through a typed URL.

Does a successful recovery mean the leak is gone?

No. Recovery ends the current session. Old exposure files can still exist. Unique passwords and MFA limit what those files can do.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.