The first sign is usually a text from a friend: "Did you just email me a link?" Or an inbox full of bounced messages you never sent. Someone has your email password, and they are using your account to reach everyone who trusts you. It is fixable — but the order you do things in matters, and there is one step almost everybody misses.
Why this is more serious than spam
Your email is the key to almost everything else. Every "forgot password" link for your bank, your shopping accounts and your social media goes to your inbox. Someone with access to your email can reset those too. So treat this as urgent, even if all they have done so far is send some junk.
1. Change the password — from a different device
If your computer has malware that captured the password, typing a new one on the same computer can hand it straight over. Use your phone or another computer you trust.
- Make it new and unique. Not a variation of the old one, and not one you use anywhere else.
- If you cannot log in because they changed the password, use the provider's account recovery page (Microsoft, Google, Apple, or your internet provider's email service) and follow the steps to prove it is yours.
2. Sign out every other session
Changing the password does not always kick out someone who is already logged in. In your account security settings, look for "Sign out of all sessions", "Sign out everywhere" or a list of devices, and remove everything you don't recognise.
3. Check for forwarding rules — the step everyone misses
This is the hidden one. Hackers often set up a rule that silently forwards a copy of every email you receive to their own address, or automatically deletes replies from people asking "is this really you?". Changing your password does not remove it. The rule keeps working after they are locked out.
Look in your email settings for Forwarding, Rules, Filters or Inbox rules and delete anything you did not create. In Outlook, check both the web version and the desktop app.
4. Check your recovery details
Look at the recovery phone number and backup email address on the account. If the hacker added their own, they can take the account back whenever they like. Remove anything that isn't yours.
5. Turn on two-step verification
With two-step verification (sometimes called 2FA or multi-factor), logging in needs your password and a code from your phone. A stolen password on its own stops being enough. It is the single most effective thing you can do, and every major email provider offers it free.
6. Change passwords anywhere you reused that one
If you used the same password for other accounts, assume they are exposed too — banking and shopping first. Then tell your contacts that emails sent in the last few days may not have been from you, and not to click links in them.
7. Find out how they got in
Most hacked email comes from one of three places: a password reused on a website that was breached, a convincing fake login page, or malware on the computer. The first two are fixed by the steps above. The third is not — if there is malware, it will simply capture your new password.
Signs your computer itself may be involved: new toolbars or browser extensions, popups, programs you don't remember installing, or the account getting hacked again straight after you changed the password. In that case, a virus and malware clean-up comes before anything else.
If money or identity is involved
- Money lost or bank details shared: call your bank straight away.
- Report it at cyber.gov.au (ReportCyber), the Australian Government's reporting service.
- Worried about identity theft: IDCARE, Australia's national identity and cyber support service, offers free help working out what to do next.
Want someone to do it with you?
We lock down hacked accounts every week — for home users and small businesses where one hacked mailbox can lead to fake invoices being sent to your customers. On an email help job we secure the account, remove hidden rules and forwarding, set up two-step verification in a way you can actually live with, and check the computer is clean. Onsite or remote, same flat rate.
Related guides
- That "Microsoft" popup is lying to you — another common way strangers get into your computer.
- Keep our one-page scam checklist by the computer.
Rather someone just fixed it?
Call us and describe what is happening. We will tell you what it is likely to be and what it would involve — before you commit to anything.
1800 851 816 Our servicesWritten by the technicians at Afford IT, Indooroopilly. We service homes and small businesses across Greater Brisbane.