Security8 min readModerateUpdated August 2026

Your Email Has Been Hacked — the Correct Order to Fix It

Changing the password first is not enough, and most people miss the step that actually matters. Here is the order a UK engineer works through, and why the hidden rule comes before everything else.

Symptoms

  • Contacts report messages from you that you never sent
  • Sign-in alerts from countries you have never visited
  • Replies arriving to conversations you cannot find in your sent items
  • Password reset emails for other services that you did not request

Likely causes

  • The password was reused on a site that suffered a breach
  • A convincing fake sign-in page captured the password and the one-time code
  • Malware on a computer or phone captured the session
  • An old app password or connected app still holds access after the main password changed

Step-by-step fix

  1. 1

    Use a device you trust

    If a computer might be infected, do none of this on it. Use a phone on mobile data, or another machine. Working from the compromised device hands the attacker every new password as you type it.

  2. 2

    Change the password, then check active sessions

    Set a new, unique password — long rather than complicated. Then find the security page for your provider and sign out all other sessions. Microsoft, Google and Apple all offer this. A password change alone does not always kick out an attacker who is already signed in.

Full guided fix

Unlock the remaining 5 steps + engineer follow-up

Detailed instructions, screenshots where it matters, and a real UK engineer on standby if a step doesn't behave.

Payments aren't wired up in this build — the button takes you to the expert form and an engineer follows up.

Free unlock

Prefer not to pay? Get the full fix free with your email.

We'll send occasional plain-English fixes and warnings. No spam, one-click unsubscribe.

Watch out for

  • Do not simply delete the suspicious emails and assume it is over. Without removing the forwarding rule, the attacker keeps receiving your mail regardless of the new password.
  • Be careful with invoice fraud. If the compromised mailbox belongs to a business, attackers often wait quietly and then send a genuine-looking invoice with altered bank details. Warn your customers and suppliers.

Frequently asked

How do I know if my details were in a breach?

Have I Been Pwned (haveibeenpwned.com) lets you check an address against known breaches. It is run by a respected security researcher and does not need your password. If your address appears, assume any password you reused on other sites is also compromised.

Is a password manager safe if everything is in one place?

Far safer than the alternative. The realistic risk is not someone breaking a well-designed manager — it is you reusing one password across forty sites, one of which gets breached. Use a manager with a strong master password and multi-factor authentication on it.

They had my one-time code too. How?

Usually a real-time phishing page: you enter the code on a fake site and the attacker relays it to the genuine one within seconds. This is why the sign-out-all-sessions step matters, and why app-based or hardware authentication is stronger than codes you type in.

Still stuck? A UK engineer can jump on remotely.

Fixed fee, secure one-time session, usually within the hour.