Your Email Has Been Hacked — the Correct Order to Fix It
Changing the password first is not enough, and most people miss the step that actually matters. Here is the order a UK engineer works through, and why the hidden rule comes before everything else.
Symptoms
- Contacts report messages from you that you never sent
- Sign-in alerts from countries you have never visited
- Replies arriving to conversations you cannot find in your sent items
- Password reset emails for other services that you did not request
Likely causes
- The password was reused on a site that suffered a breach
- A convincing fake sign-in page captured the password and the one-time code
- Malware on a computer or phone captured the session
- An old app password or connected app still holds access after the main password changed
Step-by-step fix
- 1
Use a device you trust
If a computer might be infected, do none of this on it. Use a phone on mobile data, or another machine. Working from the compromised device hands the attacker every new password as you type it.
- 2
Change the password, then check active sessions
Set a new, unique password — long rather than complicated. Then find the security page for your provider and sign out all other sessions. Microsoft, Google and Apple all offer this. A password change alone does not always kick out an attacker who is already signed in.
Unlock the remaining 5 steps + engineer follow-up
Detailed instructions, screenshots where it matters, and a real UK engineer on standby if a step doesn't behave.
Payments aren't wired up in this build — the button takes you to the expert form and an engineer follows up.
Watch out for
- Do not simply delete the suspicious emails and assume it is over. Without removing the forwarding rule, the attacker keeps receiving your mail regardless of the new password.
- Be careful with invoice fraud. If the compromised mailbox belongs to a business, attackers often wait quietly and then send a genuine-looking invoice with altered bank details. Warn your customers and suppliers.
Frequently asked
How do I know if my details were in a breach?▾
Have I Been Pwned (haveibeenpwned.com) lets you check an address against known breaches. It is run by a respected security researcher and does not need your password. If your address appears, assume any password you reused on other sites is also compromised.
Is a password manager safe if everything is in one place?▾
Far safer than the alternative. The realistic risk is not someone breaking a well-designed manager — it is you reusing one password across forty sites, one of which gets breached. Use a manager with a strong master password and multi-factor authentication on it.
They had my one-time code too. How?▾
Usually a real-time phishing page: you enter the code on a fake site and the attacker relays it to the genuine one within seconds. This is why the sign-out-all-sessions step matters, and why app-based or hardware authentication is stronger than codes you type in.
Still stuck? A UK engineer can jump on remotely.
Fixed fee, secure one-time session, usually within the hour.