When a Mailbox Has Been Broken Into

Time: the first hour decides most of it, the repairs take an evening. Repeat: hopefully never, but the order is the same every time.

Work out whether somebody is actually inside

Before you touch anything, decide which of two situations you are in: somebody has access to the mailbox, or somebody is sending mail that pretends to come from it.

Signs of real access: sign-in notices from places you have not been, messages disappearing or turning up already read, replies in your sent folder that you did not write, a contact asking why you sent them a strange link that they received from your actual address, or password reset mails for accounts you did not try to reset.

Signs of the other thing: friends receive mail with your name on it but the sender address is subtly different, nothing in the account itself looks touched, and no sign-in notices arrived. That is a forged sender, which is unpleasant and public but leaves your account alone. It needs a warning to your contacts, not the procedure below.

If it is real access, keep reading and follow the order exactly. The order is what makes the difference between an hour and a month.

End every other session before you change anything

Sign in, find the list of active sessions or devices, and end all of them except the one you are on right now.

Do this first, not after the password. On a number of providers a session that is already open survives a password change, so an intruder holding one keeps reading while you congratulate yourself. Worse, changing the password sends a confirmation to the mailbox, and someone still inside sees it, learns you are awake and has minutes to entrench before you get to the rest of the list.

If you have lost access entirely and cannot sign in, stop here and start the provider's recovery process instead. What happens next depends entirely on what you registered in advance, which is the argument for setting the routes up while nothing is wrong.

Hunt the forwarding rule before you relax

With the sessions closed, go looking for the quiet copy. This is the step people skip, and it is the one that keeps a break-in alive for months.

A forwarding rule costs the intruder ten seconds and survives your password change, your new second factor and your sense of relief. Everything that arrives from then on reaches them without another login, including reset links for accounts you have not thought about yet.

Six places hide it. Automatic forwarding to another address. Filters or rules, especially ones that mark as read, archive or delete on a keyword like the name of a bank. The vacation autoresponder, which can quietly mail your contacts. Alternate or alias addresses added to the account. Delegation, where a second person is granted access to the mailbox as themselves. And connected applications, which are covered below and hold access without needing a rule at all.

Read every rule you find, including the ones that look like yours, because a rule written to hide is written to look ordinary. If you have never opened this part of the settings before, the mechanics are the same as the rules you build deliberately, and knowing what a normal rule looks like is what lets you spot the one that is not.

Change the password and rebuild the second factor now

Only now, with the sessions closed and the rules cleaned out, set a new password that exists nowhere else, from a password manager.

In the same sitting: turn the second factor back on, or replace it if the intruder had time to swap it for one of theirs. Generate a fresh set of backup codes, which invalidates any set they may have copied. Check the address that receives security notices, because pointing it at their own mailbox is a standard move and it silences every warning you would otherwise get.

Then check the recovery settings themselves. A recovery phone number or address belonging to someone else is a permanent way back in, and it is the single most common thing left behind after a rushed cleanup. The rest of the settings worth hardening while you are in there are listed in the five that decide who can reach the account.

Cut off the apps that never needed the password

Open the list of applications with access to the account and revoke everything you do not recognise, along with everything you no longer use.

An authorised application holds a token, not a password. It keeps reading after you change the password, after you enable the second factor, and after you sign out of every device, because none of those touch it. App passwords are the same story with a different name and they bypass the second factor by design, so kill those first. The full list of what to look for, and what will break when you revoke it, is in the apps that can read your mail.

Sign out of all sessions a second time once the password, the second factor and the app list are done. It takes ten seconds and it closes anything that reconnected while you worked.

Repair the accounts underneath, most expensive first

Now leave the mailbox and go down the list of what it can unlock, in order of what losing it costs.

Money first: banking, payment services, anything holding a card or a balance, plus the shopping accounts with a saved card. Then your domain registrar if you own one, because a stolen domain takes the mail with it. Then work and documents. Then the password manager, if its recovery ever pointed at this mailbox. Everything else, including the shops and the newsletters, can wait until the weekend.

For each: new password, second factor on, and check its recovery address. If you have no idea how long that list is, build it properly rather than from memory, because guessing is how the one account that mattered gets missed. Four sources between them will find nearly everything.

Tell the people who need to know, and nobody else

Warn the specific people affected, in one short message each, without a public announcement.

Your contacts, if anything was sent from the account, so they do not open it. Your bank, if confirmations or reset mails for it passed through the mailbox while somebody else was reading. Your employer's IT team, immediately and without delay, if this is a work mailbox or if work mail was forwarded to it, because that stops being only your problem.

Do not do these four things

Do not delete the mailbox. It is the address your other accounts recover through, and deleting it turns a fixable incident into a permanent loss.

Do not reply to an extortion message claiming to hold your password or your webcam footage, and do not pay. These are sent in bulk, they usually quote an old reused password to sound credible, and answering only confirms that a person reads this address.

Do not reuse the old password anywhere, including on the accounts you are now repairing.

Do not use a disposable address as the replacement while you sort this out. The inbox we hand out deletes itself on schedule, which is right for a one-off signup and wrong for the account everything else recovers through.

The checklist

  • End every active session before touching the password.
  • Check all six hiding places for forwarding, filters, autoresponders, aliases, delegation and app access.
  • Set a new unique password, restore the second factor, generate fresh backup codes, and verify the security notice address.
  • Revoke app passwords and connected applications, then sign out everywhere again.
  • Repair the accounts underneath in order: money, domain, work, everything else.
  • Warn your contacts, your bank and your employer only as far as each is actually affected.

Read next

All guides