TL;DR: Use your email provider's account recovery flow right away — most providers (Gmail, Outlook, Yahoo, etc.) have a dedicated 'my account has been hacked' recovery path that's faster than general support.

👉 Check my digital footprint — free 30-second check →

How to Recover a Hacked Email Account — a clear, step-by-step guide to what to do and how long it takes.

Step 1: Try to regain access immediately

Use your email provider's account recovery flow right away — most providers (Gmail, Outlook, Yahoo, etc.) have a dedicated 'my account has been hacked' recovery path that's faster than general support.

Step 2: Change your password once you're back in

As soon as you regain access, set a new, unique password you haven't used anywhere else, and check that the recovery email/phone number hasn't been changed by the attacker.

Step 3: Check account activity and connected apps

Review your account's recent activity log and revoke access for any unfamiliar devices, sessions, or third-party apps connected to the account.

Step 4: Enable two-factor authentication

Turn on two-factor authentication if it isn't already active, ideally using an authenticator app rather than SMS where the option exists.

Step 5: Notify your contacts and check linked accounts

Let your contacts know if the attacker may have sent messages from your account, and check any other accounts that use this email for password recovery, since those may now be at risk too.

If this looks similar to something else you've seen, it's worth reading How to Recover a Hijacked Domain or Website.

This pattern shows up elsewhere too — see How to Recover a Stolen Social Security Number.

Frequently Asked Questions

Step 1: Try to regain access immediately

Use your email provider's account recovery flow right away — most providers (Gmail, Outlook, Yahoo, etc.) have a dedicated 'my account has been hacked' recovery path that's faster than general support.

Step 2: Change your password once you're back in

As soon as you regain access, set a new, unique password you haven't used anywhere else, and check that the recovery email/phone number hasn't been changed by the attacker.

Step 3: Check account activity and connected apps

Review your account's recent activity log and revoke access for any unfamiliar devices, sessions, or third-party apps connected to the account.

Step 4: Enable two-factor authentication

Turn on two-factor authentication if it isn't already active, ideally using an authenticator app rather than SMS where the option exists.

Step 5: Notify your contacts and check linked accounts

Let your contacts know if the attacker may have sent messages from your account, and check any other accounts that use this email for password recovery, since those may now be at risk too.

Sources

Related Reading