Someone is in your email. This is the order to fix it.
Change the password, then use your provider's "sign out of all sessions" option. The password alone does not throw out someone who is already signed in.
Your email is the account that can reset all the others. Getting it back is only half the job: the other half is undoing what they set up while they were inside.
Most advice about a hacked email account stops at "change your password", and that is the part that fails people. A password change does not always end a session that is already open, and it does nothing at all to the forwarding rule, filter or connected app someone may have added while they were inside. Those keep working afterwards, quietly, which is why people get compromised a second time a week later and assume they were simply unlucky.
Work through this in order. The order matters more than the speed.
Why email comes before your bank
When your money is involved the instinct is to go straight to the bank, and that instinct costs people their accounts twice. Every one of those accounts has a "forgot my password" link, and that link sends a reset to your email address. If someone still holds the mailbox, they can request a reset on anything tied to it, receive the link, and lock you out again minutes after you finish.
Email is the master key. Secure it first, even though it feels less urgent, and then the rest of the work stays done.
The one exception: if you can see money actively moving, call the bank's fraud line while you work through the rest. Reporting a fraudulent transfer is time-sensitive in a way that account cleanup is not.
Step 1: get back in, and throw everyone out
Change the password from a device you trust, and make the new one unique to this account. Reusing the password from another site is how a lot of these start, because a breach somewhere else becomes a working key here. If you keep passwords in your head, this is the account to make the exception for: a password manager means the email password can be long and impossible to guess without you having to remember it.
Then find the option that ends every other session. Providers name it differently: Sign out of all sessions, Sign out of all devices, or a device list where you revoke them one by one. Do this after the password change, so the person is not signed straight back in.
If you cannot get in at all, stop and use the provider's account recovery form rather than the login page. Fill it in from a device and network you have used with that account before, because that consistency is one of the signals a provider weighs. Answer from memory even when the answers are approximate: a roughly right creation date helps more than a blank field.
Step 2: the settings nobody checks
This is the part that separates a clean recovery from a repeat. Someone with a few minutes in your mailbox will often leave a way back in, and none of it is undone by a password change. Go through all of it:
| Setting | What to look for |
|---|---|
| Forwarding | Any address that is not yours. A copy of everything keeps arriving to them, and you never see a trace of it in your inbox. |
| Filters and rules | Rules that delete or archive on a keyword like "bank", "invoice" or "password". These hide the alerts that would have warned you. |
| Recovery address and phone | If either was changed, the recovery route now points at them. Change it back before anything else, because it undoes your work otherwise. |
| App passwords | Long generated strings that bypass two-factor entirely. Revoke every one you do not recognise, and expect to re-add a mail client afterwards. |
| Connected apps | Third-party services with mailbox access granted through a consent screen. Access survives a password change by design. |
| Aliases and send-as | An added address lets someone keep writing as you even after losing access to the account itself. |
Check the sent folder and the trash while you are there. What was sent from your address tells you what your contacts received, and the trash often holds the alerts that were deleted to keep you unaware.
Step 3: turn on two-factor properly
With the mailbox yours again, add a second factor so a stolen password is not enough next time. If you have the choice, prefer an authenticator app or a security key over SMS codes. SMS is far better than nothing, and it is also the weakest of the options, because a SIM swap moves your number to someone else's phone and the codes follow it.
Save the recovery codes somewhere that is not the mailbox they protect. Printed and in a drawer is perfectly reasonable.
Step 4: work outward
Now the accounts that reset through that address, most exposed first:
- Banking and payment apps, plus anything holding a saved card.
- The other big account you sign into things with, usually a Google or Apple ID.
- Shopping accounts with an address and a card on file.
- Social and messaging, where impersonation does the damage rather than theft.
For each one: new unique password, sign out all sessions, check that the email and phone on file are still yours. That last check catches the quiet version of this attack, where nothing was stolen yet and the account was simply pointed somewhere else for later.
Step 5: tell your contacts, briefly
Send a short message from a different channel: anything unusual from your address in the last few days was not you, and they should not act on it. Whoever had access may have written to the people who trust you most, which is precisely why it works. There is no need for detail or apology, only the warning.
If a contact already paid someone or clicked something, point them at where to report it and tell them to move quickly. The window for stopping a transfer is short.
How they got in, so it does not repeat
Almost always one of four:
- A reused password exposed in someone else's breach. The single most common route, and the one a password manager closes.
- A phishing page that looked like the login screen. If a "security alert" led you there, compare it against what a real one looks like.
- An approved prompt. Two-factor pushes that arrive repeatedly until someone taps accept to make them stop. If you did not start it, deny it.
- An old device or app still signed in and no longer under your control.
Knowing which one it was decides what you fix. If the answer is a reused password, changing this one and leaving the others is a temporary repair.
Frequently asked questions
I changed my password. Is my email safe now?
Why does the guide say to fix email before my bank?
I cannot get back in at all. What now?
Should I tell my contacts?
Daniel A. and Óscar S. run Breachfolio, a small independent site about security and AI. This article was drafted with AI assistance and reviewed by a person before it went live. We write from documentation, vendor sources and published research rather than from original lab benchmarks, and we link a source in the sentence that relies on it. How we work · About us
