Email account hacked: how to recover it and lock it down
Your email is the reset route for every other account you own, so getting back in is only half the job. Provider recovery when your recovery details are gone, the forwarding rules a password change leaves behind, and when to report it.
Short answer
Regain control of the email account first, because it is the password reset route for everything else. Use the provider's own account recovery process, then check for forwarding rules and filters the attacker left behind — a new password does not remove them. Sign out all devices, turn on 2-step verification, then work through every account that uses that address.
Part of How to report a scam in the UK — and try to get your money back
An email account is not one account among many. It is the account that controls all the others, because almost every service you use will send a password reset link to it and ask no further questions. The National Cyber Security Centre puts this plainly: someone with access to your email can read private information including your banking details, send messages that appear to come from you, and reset the passwords on all your other online accounts. That is why the NCSC's standing advice is to give your email address a strong password used nowhere else, and it is why a hacked inbox is an emergency rather than an inconvenience.
There is a second reason this problem is worse than it looks. Getting back in is the part everyone concentrates on, and it is the part that generates the most anxious searching, but it is not where most of the lasting damage sits. An attacker who has had even an hour inside a mailbox will normally have left something behind that survives a password change — a forwarding rule copying every incoming message to an address you have never seen, a filter that silently deletes anything mentioning your bank, a linked account, an app password, or a second recovery address quietly added to the profile. Change the password, breathe out, and the attacker is still reading your post.
This page is written in the order that limits harm rather than the order that feels natural. It covers what to do in the first hour if you still have access, the provider recovery routes when you do not — including the awkward case where the attacker has already changed the registered phone number and recovery address — the specific settings to strip out afterwards, the sweep of connected accounts that follows, and the point at which this stops being a self-help matter and becomes a crime you should report to Report Fraud in England, Wales and Northern Ireland or to Police Scotland on 101.
It also covers the case people get wrong most often: a work or study email account. If the mailbox held other people's personal data, your employer or institution has statutory obligations to the Information Commissioner's Office that run on a 72-hour clock, and telling your IT team promptly is not an admission of fault — it is what starts that clock in time. Throughout, this guide links to the existing pages on reporting a scam and on identity theft rather than repeating them, because a hacked inbox often turns into one or both of those problems next.
Why email is the account that decides how bad this gets
Start by understanding what an attacker actually gains, because it determines the order of everything that follows. The NCSC's guidance on email passwords sets out three things a criminal with your inbox can do: access private information about you, including your banking details; post emails and messages pretending to be from you, and use that to trick other people; and reset all your other account passwords, which gives them access to all your other online accounts. The third of those is the one that matters. Your email address is not a communication channel to a criminal — it is a master key.
Work outwards from that and the scope becomes clear. Your bank, your energy supplier, your mobile network, your online shopping accounts, your social media, your cloud storage and the government services you use are all reachable through a password reset sent to that address. GOV.UK One Login, which the government says will over time replace every other way of signing in to services on GOV.UK including Government Gateway, is managed by signing in and changing your sign-in details — your email address, your password, or how you get security codes. HMRC's own guidance on unauthorised access describes the same pattern from the other end: access codes arriving on your phone when you have not tried to sign in, a password that no longer works, changes to tax records you did not make.
This is why an email compromise is so often the first step in something larger rather than the whole of the incident. A criminal rarely wants your emails. They want the accounts those emails unlock, and the credibility of messaging your contacts from an address they already trust — both time-limited advantages, which is why speed matters more here than in most consumer problems.
The other side of that is reassuring, and worth saying because people in the middle of this tend to catastrophise. Almost all consumer email compromise is opportunistic. The usual cause is a password reused on a site that suffered a data breach and then tried automatically against thousands of email providers — the NCSC's data breach guidance describes criminals doing exactly this. Nobody chose you, and the fix is mechanical rather than mysterious.
One practical implication follows immediately. If the password on your email account was one you had used anywhere else, every account sharing that password is compromised too, whether or not anything has happened on it yet. The NCSC and the government's Stop! Think Fraud service both say the same thing: change the password on the hacked account, and change it on every other account where you used the same one. Treat that as part of the incident, not as a later tidying-up job.
One last thing about how you use the mailbox from here on. Until you have completed the clean-up below, assume anything you send or receive may be visible to someone else — so do not email yourself passwords, document scans or recovery codes, and use a phone number or authenticator app rather than the inbox for the confirmations on accounts you are about to secure.
The first hour, if you can still get in
If you can still sign in, you are in a far stronger position than you feel, and you should use it before that changes. The single most useful thing you have is the ability to act without going through an identity check, so do the irreversible things first and the tidying afterwards.
Run a full antivirus scan before you change the password. This ordering is not fussiness — Microsoft's guidance on recovering a compromised account puts it as step one and explains why: if the device you are typing on is running credential-stealing software, a new password is captured the moment you set it. Open whatever antivirus you have, update it, and run a full scan rather than a quick one, letting it clean up what it finds. On Windows, Microsoft Defender is built in and does this without any additional purchase.
Then change the password, and change it to something you have never used anywhere. The NCSC recommends three random words as a way of producing something long enough to resist guessing and memorable enough to actually use, or a password manager to generate and store a genuinely random one. Do not recycle a variation of the old password — an attacker who had the old one will try the obvious variations first.
Next, sign out everywhere. Every major provider has a control that terminates all active sessions on every device and app, usually in the security or privacy settings. This matters because a password change does not always invalidate an existing logged-in session, and an attacker sitting in a browser session on their own machine can carry on regardless. Stop! Think Fraud lists this as a distinct step for exactly that reason: once you have changed the password and signed out everywhere, you and anyone else attempting to use the account will be prompted for the new password, and only you have it.
Turn on 2-step verification while you are in the settings, if it is not already on. The NCSC describes 2-step verification — also called two-factor authentication or multi-factor authentication — as one of the most effective ways to protect an account, because it keeps a criminal out even when they know the password. If your provider offers a choice, an authenticator app or a security key is stronger than a code sent by text message, because SIM-swap fraud defeats text codes. Whatever you choose, make sure the second factor is something the attacker does not already control.
Only now check the damage: your sent items, your deleted items, your recent security activity, and your account recovery settings. Google's guidance on securing a compromised account tells you to review recent security events and the list of devices signed in to the account, and to correct immediately any unfamiliar change to your recovery phone number, recovery email address, alternate or contact email address, or the name on the account. Attackers change those first, because it is what stops you taking the account back later.
Finally, warn your contacts. Both the NCSC and Stop! Think Fraud list this as a formal step rather than a courtesy. Messages sent from your address in the past few days may have carried malicious links, and the people most likely to click them are the ones who know you. A short, unembarrassed message saying the account was compromised and that anything unusual from it should be ignored does more good than any amount of individual apology later.
When you are locked out: the provider recovery routes
If the password has already been changed, you are into account recovery, and there is one hard truth to absorb before you start. There is no UK regulator, ombudsman or government body that can compel a private email provider to give you your account back. The NCSC's guidance is explicit that recovery runs through the provider: go to the account provider's website, find their help or support pages, and follow the recovery process they publish. Report Fraud, Police Scotland, the ICO and your bank all have roles in this incident, but none of them is the route back into the mailbox.
The recovery process is an identity test dressed up as a form, and it is scored rather than passed. Google's own advice on completing account recovery is unusually candid about this: answer every question rather than skipping ones you are unsure about, because wrong guesses do not end the process; use a device, browser and location you normally sign in from, because familiarity is itself evidence; and if you are asked for the last password you remember, give the most recent one you can recall, or your best guess if you cannot. Each of those is a signal the provider weighs. Attempting recovery from a borrowed laptop in an unfamiliar country is the single most common reason a genuine owner fails.
Microsoft runs the equivalent process through a sign-in helper that asks for the email address or phone number and then either offers self-help or routes you to an agent, with a separate account recovery form where the usual verification is not possible. Apple, Yahoo and the smaller UK providers each run their own version. The mechanics differ; the logic does not.
The hardest case is the one this page exists for: the attacker has already changed the recovery phone number and the recovery email address, so every code the provider offers to send goes to them. Do not treat that as the end of the road. Providers keep a history of the settings on an account and can see that a recovery address was added days ago rather than years ago. Work through the recovery flow anyway, use the option to try another way when a challenge routes to an address you no longer control, and supply everything you can evidence — the approximate creation date of the account, the recovery details as they used to be, the names of frequent correspondents, the labels and folders you created, and the subscriptions or purchases tied to the address.
Expect delay, and do not read it as refusal. Providers deliberately slow down requests that look risky, because an instant recovery process is itself an attack route — the same form that gets you back in would get a criminal in. If a request is refused, submit again from a device and location you use routinely, with more supporting detail.
If recovery genuinely fails, both the NCSC and Google say the same thing: open a new account. It feels like defeat and it is not. Choose a new address, tell your contacts it has changed, and then work methodically through the accounts in the next two sections, changing the registered email address on each one. The old inbox stays in the attacker's hands, which is precisely why the sweep matters — every account still pointing at it remains reachable by them indefinitely.
One thing to avoid entirely: paid account recovery services. There is no privileged channel into a provider's recovery process, and approaching people who claim otherwise usually produces a second fraud on top of the first.
Strip out what a password change does not remove
This is the section most guidance skips and the one that decides whether the compromise is over. A password change closes the front door. It does nothing to the arrangements an attacker made while they were inside, and several of those keep working indefinitely.
Start with forwarding. The NCSC names this as the specific tactic to look for, describing how criminals set up a forwarding rule so that they will automatically be sent a copy of all emails sent to your account, which lets them go on resetting passwords long after you have locked them out. Stop! Think Fraud gives the same instruction and puts it before the password change: check and switch off any unwanted forwarding rules in your email account settings, then change your passwords. Look in the settings under forwarding, and check for forwarding configured at the level of an individual filter as well as the account-wide setting.
Then the filters and rules. A rule that files anything containing the word 'bank', 'invoice' or 'security alert' straight into the archive or the deleted items folder is invisible in normal use and is what allows fraud to run in your name without you seeing a single warning email. Google's guidance tells you to remove any labels, filters or forwarding rules you did not set up; Microsoft's tells you to check connected accounts, forwarding and automatic replies, and notes that it resets some account settings itself after a compromise. Go through the list line by line and delete anything you do not positively recognise.
Automatic replies deserve their own look. An out-of-office message telling every correspondent to send future mail to a different address is a slow redirection of your entire correspondence, and most people never open that settings page from one year to the next.
Now the permissions layer, which is where the longest-lived access hides. Look for third-party apps and services you have granted access to the mailbox, application-specific passwords issued to mail clients, connected or linked accounts, and any delegated access or shared mailbox permissions. Each of these authenticates without your password and therefore ignores the fact you have changed it. Revoke everything you cannot identify, and re-authorise the handful you actually use afterwards.
Finally, put the recovery details back the way they should be. Check the recovery phone number, the recovery email address, any alternate or contact address, the account name and the security questions, and remove anything you did not add. Google flags exactly these as the settings to correct immediately after a compromise. An attacker who leaves a recovery address in place has left themselves a door they can use whenever they choose.
Do all of this before you consider the incident closed, and do it in a session where you are logged in on a device you trust. If the account has a security or activity log, read it afterwards: a second unfamiliar sign-in appearing days later is the signal that something in this list was missed.
- Check and clear forwarding rules and filters before you change the password, not after.
- Revoke app passwords and third-party app access — these ignore a password change entirely.
- Use 'sign out of all devices' explicitly; changing the password does not always kill live sessions.
- Restore the recovery phone, recovery email and account name to your own details.
- Re-read the account's security log a week later to confirm nothing was missed.
| What the attacker leaves behind | Survives a password change? | Where to look |
|---|---|---|
| Forwarding rule sending a copy of every message | Yes | Settings — forwarding, and inside individual filters |
| Filter that archives or deletes bank and security emails | Yes | Settings — filters, rules or 'inbox rules' |
| Automatic reply pointing correspondents elsewhere | Yes | Settings — automatic replies or vacation responder |
| Third-party app or service granted mailbox access | Yes | Security — connected apps, app permissions, linked accounts |
| App password issued to a mail client | Yes | Security — app passwords |
| Added recovery email address or phone number | Yes | Security — recovery and sign-in options |
| An active browser session on the attacker's device | Not always | Security — devices, active sessions, 'sign out everywhere' |
Compiled from NCSC guidance on recovering a hacked account, Stop! Think Fraud, Google's compromised-account checklist and Microsoft's account recovery guidance.
Sweep every account the address could unlock
With the mailbox itself clean, the question becomes what was done with it, and the honest answer is that you will not know until you look. Work in order of how much damage each account can do rather than alphabetically, and check the account itself rather than relying on the email confirmations — an attacker who set up a deletion filter has already made sure you never saw them.
Money first. Check bank and card statements line by line, including very small transactions, because a test payment of a pound or two commonly precedes a large one. Both the NCSC and Stop! Think Fraud list watching bank statements and shopping accounts as a formal recovery step. If you find anything you did not authorise, call your bank — dialling 159 connects you securely to your own bank's fraud team and cannot be spoofed. The existing guide on reporting a scam covers what happens next, including the reimbursement rules for bank transfer fraud, and there is no point repeating that here.
Then the shopping and delivery accounts, which are where email compromise most often turns into loss. Look for changed delivery addresses, new saved cards, gift card purchases and stored balances spent down. These accounts rarely have 2-step verification turned on by default, and they are the easiest to monetise quickly.
Then tax and government. HMRC publishes a dedicated route for exactly this: if you still have access, you can sign in to HMRC online services and report suspicious activity from the security console; if you cannot, there is an online reporting form that asks for an email address, a contact number with preferred times, and details of the suspicious activity. HMRC says it aims to phone or email you within 10 working days of a report. The signs it tells you to look for are access codes arriving when you have not tried to sign in, a password that no longer works, changes to tax records you did not make, and letters or payments from HMRC you were not expecting.
Then GOV.UK One Login, which is now the sign-in for a growing list of services and which the government says will in time replace Government Gateway. It is managed by signing in and changing your sign-in details — the email address, the password, or how you get security codes — so if your email was compromised, treat the One Login as compromised too and change all three. Note that it does not yet cover every government service; Universal Credit, for instance, still has its own sign-in.
Then everything that holds documents or identity data: cloud storage, photo libraries, and any account where you have ever emailed yourself a passport scan or a payslip. Google specifically flags this, telling people to contact their bank or the authorities if personal information such as tax or passport details was stored in the account. If identity documents were exposed, the separate guide on identity theft covers protective registration and the credit reference agencies, which is the right next move and is not repeated here.
Finally, the social and messaging accounts registered to the address, and any account belonging to someone else that you administer — a club, a business page, a shared subscription. Compromise spreads sideways through shared admin rights more often than people expect.
| Account | What to look for | Who to contact |
|---|---|---|
| Bank and cards | Small test payments, new payees, changed contact details | Your bank — dial 159 |
| Shopping and delivery | New delivery addresses, saved cards, gift card purchases | The retailer's account security team |
| HMRC online services | Unrequested access codes, changed records, unexpected letters | HMRC — security console or the online reporting form |
| GOV.UK One Login | Changed email address, password or security code method | GOV.UK One Login team |
| Cloud storage and photos | Unfamiliar sharing, downloads, identity documents held there | The provider; then the identity theft steps |
| Social and messaging | Messages sent to contacts, changed recovery details | The platform, and your contacts directly |
Built from HMRC's guidance on reporting suspicious activity in an online account, GOV.UK's One Login pages, NCSC and Stop! Think Fraud recovery steps, and Stop Scams UK on the 159 service.
Reporting it: crime, self-help, or both
Unauthorised access to your email account is a criminal offence, and it is worth knowing that before you decide whether reporting is proportionate. Section 1 of the Computer Misuse Act 1990 makes it an offence to cause a computer to perform any function with intent to secure unauthorised access to any program or data, knowing that the access is unauthorised. It carries up to two years' imprisonment on conviction on indictment. No financial loss is required for the offence to have been committed.
Where you report depends on where you live, and this is the point most pages get wrong. In England, Wales and Northern Ireland, fraud and cybercrime go to Report Fraud — the national reporting centre run by City of London Police and formerly branded Action Fraud — online or on 0300 123 2040. In Scotland the position is different: Report Fraud's own site directs Scottish residents to report via 101, and Police Scotland publishes its own hacked accounts advice with an online reporting form alongside the phone and in-person routes. Reporting a Scottish incident to Report Fraud does not put it in front of Police Scotland.
Be realistic about what a report achieves. Report Fraud collates reports for intelligence purposes and does not investigate every case; its most immediate practical value to you is the reference number, which banks, insurers and credit reference agencies routinely ask for before they will act on a claim. If money has been taken, or if identity documents were held in the mailbox, get the reference early rather than at the point someone demands it.
Separately from any crime report, forward the message that started it. If the compromise followed a phishing email, forward that email to [email protected], the NCSC's free reporting address; suspicious texts go to 7726, and to report a scam call you text 7726 with the word 'Call' followed by the caller's number. Stop! Think Fraud sets out all three routes. These feed takedown work rather than an investigation into your case, but they are free, take a minute, and reduce the number of people who receive the same message next week.
If the account belongs to a business, charity or other organisation and the attack is live, the escalation differs again: Report Fraud asks organisations under cyber attack to call 0300 123 2040 immediately rather than wait on an online form.
Finally, get support if you need it. The Cyber Helpline is a free UK service staffed by volunteer cybersecurity professionals that handles hacked email accounts specifically, and Police Scotland links to it alongside Get Safe Online, the National Crime Agency and the Cyber and Fraud Centre Scotland. Being hacked is a crime committed against you, and treating it as a personal failing is both wrong and a reliable way of delaying the steps that limit the damage.
If it was a work, study or business account
A hacked work mailbox is not the same problem as a hacked personal one, and the difference is that other people's personal data is usually sitting in it. That converts a security incident into a data protection incident with statutory timescales attached, and those timescales run from the moment the organisation becomes aware.
Tell your IT team or data protection lead immediately, and do it by a channel other than the compromised mailbox. The NCSC's phishing guidance says the same in one line: if you received the message on a work laptop or phone, contact your IT department and let them know. Delay is the thing that turns a manageable incident into a reportable failure, and organisations know that the person who reports quickly is the one who limited the damage.
What happens next is the organisation's obligation, not yours, but it helps to know the shape of it. Where a personal data breach is likely to result in a risk to people's rights and freedoms, the organisation must notify the Information Commissioner's Office as soon as possible and, where feasible, within 72 hours. The ICO is explicit that the 72-hour requirement is a legal one even when the picture is still incomplete, and that the correct response is to report what you have and supply further detail afterwards without undue delay. Where the risk to people is high, the organisation must also tell those people directly, without undue delay.
The ICO's report is made through an online form which it says takes around 30 minutes and cannot be saved partway through, and which asks what happened, when and how it was discovered, who has been or may be affected, what is being done, and who else has been told. If your organisation is small enough not to have a data protection team, the ICO publishes a short guide aimed at small companies and sole traders on responding in the first 72 hours.
The position is different if you are on the other side of it — if an organisation's breach is the reason your details were exposed in the first place. The ICO's advice to individuals is to contact the organisation first and give it the chance to explain, and it publishes a template complaint letter for the purpose. The organisation should reply within one month. If you are unhappy with the response or receive none, you can complain to the ICO, and its helpline for members of the public is 0303 123 1113.
One caution specific to breaches. The NCSC warns that criminals exploit high-profile breaches while they are fresh, sending messages that appear to come from the breached organisation and ask you to log in and verify your account because fraudulent activity has taken place. They arrive some time after the breach becomes public, and are convincing precisely because you are already worried. Contact the organisation through its official website, never a link you were sent.
Making the next attempt fail
Once the account is yours again, the useful question is not how to be more careful but which structural change removes the failure mode entirely. There are four, and they are worth doing in this order.
Give the email account a password used nowhere else. The NCSC's position is unambiguous: always use a strong and separate password for your email — one you do not use for any other account, at home or at work — because if a criminal gets one shared password they get everything. If you have reused your email password elsewhere, the NCSC says to change it as soon as possible. This single change breaks credential stuffing, which is the mechanism behind most consumer email compromise.
Turn on 2-step verification and choose the strongest second factor the provider supports. An authenticator app or a hardware security key beats a code sent by text, because text codes fall to SIM-swap fraud, which defeats every service relying on them at once. Where your provider supports passkeys, they remove the password from the sign-in altogether and are worth adopting on the email account before anywhere else.
Use a password manager. The NCSC actively encourages them, on the grounds that they create strong passwords and remember them, which is the only realistic way to hold a unique password for every account. The alternative most people reach for — a memorable pattern varied slightly per site — is exactly what an attacker with one of your passwords will try next.
Keep devices updated and turn on automatic updates. Stop! Think Fraud calls applying updates one of the most important and quickest things you can do to prevent an account being hacked, and the NCSC lists it among its core actions. It is unglamorous and it closes the route that no amount of password hygiene protects against.
Two smaller habits shorten the next incident. Set the recovery address to a second mailbox you control and use for nothing else, rather than a partner's address or an old work account you may lose access to. And read the new sign-in alerts your provider sends instead of dismissing them — for most people that message is the earliest warning they will get, and acting on it within the hour is the difference between an annoyance and the whole of this page.
Key takeaways
- Email is the password reset route for your bank, HMRC, GOV.UK One Login and everything else, so the NCSC's advice is to give it a strong password used on no other account.
- Changing the password does not remove forwarding rules, filters, app passwords or third-party app access — check and clear those, or the attacker keeps reading your mail.
- Only the email provider can return the account; no UK regulator can compel it, so use the provider's recovery process from a device and location you normally sign in from.
- Report to Report Fraud on 0300 123 2040 in England, Wales and Northern Ireland, and to Police Scotland on 101 in Scotland — unauthorised access is an offence under section 1 of the Computer Misuse Act 1990 whether or not money was lost.
- If it was a work or study account holding other people's data, tell your IT team at once: the organisation must notify the ICO within 72 hours where a risk to people is likely.
Who to contact
Report Fraud (formerly Action Fraud)
National reporting centre for fraud and cybercrime in England, Wales and Northern Ireland. Produces the reference number banks and insurers ask for. Organisations under live attack should call rather than use the form.
Hacked accounts and all fraud in Scotland are reported here, not to Report Fraud. Online form, phone or in person.
National Cyber Security Centre
Step-by-step recovery guidance, and the free reporting address [email protected] for the phishing email that started it. Suspicious texts go to 7726.
Report unauthorised access to an HMRC online account through the security console or the online form. HMRC aims to respond within 10 working days.
Information Commissioner's Office
For breaches of your personal data by an organisation. Contact the organisation first and give it a month to respond, then complain to the ICO.
Connects you securely to your own bank's fraud team if money has moved. Cannot be spoofed, so it is also the safe way to check a call claiming to be your bank.
At a glance
- Secure this first
- The email accountIt is the password reset route for every other account you hold
- What a new password does not fix
- Forwarding rules and filtersNCSC names these as a known attacker tactic — check them before anything else
- Reporting: England, Wales, NI
- Report Fraud0300 123 2040 — the service formerly branded Action Fraud
- Reporting: Scotland
- Police Scotland on 101Fraud and financial crime in Scotland go to 101, not to Report Fraud
- Suspicious emails
- [email protected]Free NCSC service; suspicious texts and calls go to 7726
- The offence
- Computer Misuse Act 1990, s.1Unauthorised access to computer material — up to two years on indictment
- Work or study accounts
- 72 hoursThe organisation must tell the ICO within that window where a risk to people is likely
- If money has moved
- 159Connects you securely to your own bank's fraud team and cannot be spoofed
Email account hacked — FAQ
My email has been hacked — what do I do first?
Run a full antivirus scan on the device, then check for forwarding rules and filters the attacker may have added, then change the password to one used nowhere else. Sign out of all devices, turn on 2-step verification, restore your recovery phone and email, and tell your contacts. Only then start checking your other accounts.
Someone changed my email password and I cannot get in — can I still recover it?
Usually yes, through the provider's own account recovery process. Attempt it from a device, browser and location you normally sign in from, answer every question rather than skipping ones you are unsure of, and give the most recent password you can recall. Expect delay — providers deliberately slow requests that look risky. If recovery fails, open a new account and move every service across.
Do I report a hacked email account to the police in the UK?
In England, Wales and Northern Ireland report it to Report Fraud, the national reporting centre formerly branded Action Fraud, online or on 0300 123 2040. In Scotland report to Police Scotland on 101 or through its online form. Unauthorised access is an offence under section 1 of the Computer Misuse Act 1990, so no financial loss is needed before you can report.
Why did the hacker still have access after I changed my password?
Because a password change does not touch what they left behind. Forwarding rules, filters, automatic replies, app passwords, connected accounts and third-party app permissions all keep working independently of the password, and an active browser session is not always killed by a reset. Clear all of those and use the provider's sign out of all devices control.
What should I check on HMRC if my email was hacked?
Look for access codes arriving when you have not tried to sign in, a password that no longer works, changes to tax records you did not make, or unexpected letters or payments. If you still have access, report suspicious activity from the security console in HMRC online services; if not, use HMRC's online reporting form. HMRC aims to contact you within 10 working days.
My work email was hacked — who has to tell the ICO?
Your employer, not you. Where a personal data breach is likely to result in a risk to people's rights and freedoms, the organisation must notify the Information Commissioner's Office as soon as possible and, where feasible, within 72 hours, and must tell affected individuals directly where the risk is high. Your job is to tell IT immediately, through a channel other than the hacked mailbox.
Should I use a paid service to recover a hacked email account?
No. There is no privileged route into an email provider's recovery process, so anyone advertising guaranteed recovery is either selling you the same free form or setting up a second fraud. Use the provider's own recovery pages, and if you want free expert help, the Cyber Helpline is a UK service staffed by volunteer cybersecurity professionals that handles hacked accounts.
How do I stop this happening again?
Give the email account a strong password used on no other account, turn on 2-step verification using an authenticator app or security key rather than text codes, use a password manager so every account has its own password, and turn on automatic updates. Set the recovery address to a second mailbox you control and read the new sign-in alerts your provider sends.
Read next
Sources & provenance
Facts verified
- 1.Recovering a hacked account OfficialNational Cyber Security CentreUsed for: The nine recovery steps, the signs of compromise, the instruction to check email filters and forwarding rules, signing out of all devices, telling contacts, and creating a new account if recovery fails
- 2.Use a strong and separate password for your email OfficialNational Cyber Security CentreUsed for: That a criminal with your email can access private information, send messages as you and reset every other account password; and the advice to use a unique password plus a password manager
- 3.Data breaches: guidance for individuals and families OfficialNational Cyber Security CentreUsed for: How stolen credentials are reused across accounts, and the wave of convincing phishing that follows a publicised breach — including the advice to contact the organisation via its official website rather than any link sent to you
- 4.What to do if you've been hacked OfficialStop! Think Fraud (UK Government)Used for: The eight-step recovery sequence, including checking forwarding rules before changing passwords, logging out of all apps and devices, setting up 2-step verification and applying updates
- 5.Reporting fraud OfficialStop! Think Fraud (UK Government)Used for: Police Scotland on 101 for Scotland, 159 for banks, [email protected] for suspicious emails, and 7726 for texts and calls including the 'Call' plus number format
- 6.Report Fraud — the UK's home for reporting cyber crime and fraud OfficialCity of London PoliceUsed for: Coverage of England, Wales and Northern Ireland, the 0300 123 2040 number, the direction of Scottish residents to 101, and the instruction for organisations under live attack to phone immediately
- 7.Hacked accounts OfficialPolice ScotlandUsed for: The Scottish reporting routes — online form, phone or in person — and the support organisations Police Scotland points victims to, including the Cyber and Fraud Centre Scotland and Get Safe Online
- 8.UK GDPR data breach reporting (DPA 2018) RegulatorInformation Commissioner's OfficeUsed for: The 72-hour notification requirement where a risk to people's rights and freedoms is likely, the duty to tell affected individuals where the risk is high, and the online form's scope and 30-minute length
- 9.I'm worried about how an organisation has handled my information RegulatorInformation Commissioner's OfficeUsed for: The individual's route — contact the organisation first, expect a reply within one month, then complain to the ICO — and the public helpline number 0303 123 1113
- 10.Report suspicious activity happening in an HMRC online account OfficialHM Revenue & CustomsUsed for: The signs of unauthorised access to a tax account, the security console route for those who still have access, the online reporting form for those who do not, and HMRC's 10 working day response aim
- 11.Using your GOV.UK One Login OfficialUK GovernmentUsed for: That signing in lets you change your email address, password or how you get security codes; that One Login will over time replace Government Gateway; and that it does not yet cover every service, Universal Credit included
- 12.Computer Misuse Act 1990, section 1 Legislationlegislation.gov.ukUsed for: The offence of unauthorised access to computer material, its elements, and the maximum of two years' imprisonment on conviction on indictment
- 13.How to recover a hacked or compromised Microsoft account IndustryMicrosoftUsed for: Running a full antivirus scan before changing the password, the sign-in helper and account recovery form, and the instruction to check connected accounts, forwarding and automatic replies afterwards
- 14.Secure a hacked or compromised Google Account IndustryGoogleUsed for: Reviewing recent security events and signed-in devices, removing labels, filters and forwarding rules you did not set up, correcting recovery phone, recovery email, alternate address and account name, and the tips for completing account recovery from a familiar device
Not a source — AI-assisted analysis on this page
- AI-assisted analysis — persistence mechanisms and the order to clear them — The framing of forwarding rules, filters, app passwords and third-party app grants as persistence mechanisms that authenticate independently of the password, and the specific ordering we recommend — scan, clear forwarding and filters, change password, revoke sessions and app permissions, restore recovery details — is our synthesis. The NCSC, Stop! Think Fraud, Google and Microsoft each list these settings as items to check; none of them describes them as persistence mechanisms or publishes this sequence, and the observation that apparent repeat compromises are usually unbroken original access is our reasoning, not theirs.
- AI-assisted analysis — when a hacked inbox should be reported as a crime — The suggested threshold for reporting — identity documents held in the mailbox, a work or shared account, changed recovery details, or a foreseeable later need for a reference number — is our judgement. The Computer Misuse Act 1990 establishes that no financial loss is required for the offence, and the NCSC, Report Fraud and Police Scotland set out where to report; none of them publishes a test for when reporting is worthwhile, and the argument that a reference number is far harder to obtain retrospectively is ours.
The recovery steps, the forwarding-rule tactic, the password and 2-step verification advice and the post-breach phishing warning are taken from NCSC guidance and the government's Stop! Think Fraud service as cited. Provider mechanics come from Microsoft's and Google's own compromised-account pages; the reporting routes from Report Fraud and Police Scotland; the tax steps from HMRC; the 72-hour duty and the individual complaint route from the ICO; and the offence from section 1 of the Computer Misuse Act 1990. Two passages are marked as AI-assisted analysis: the ordering of the clean-up and the threshold for reporting. Provider recovery flows, HMRC response times and ICO processes change without notice — confirm each with the body concerned before relying on it. This is general information, not legal advice.
Facts on this page are taken from the sources listed above — UK government departments, devolved administrations, regulators, statutory bodies and official statistical releases. Comparisons, judgements and "which option suits whom" conclusions are AI-assisted analysis written over those sources; they are marked in the text and listed as an AI-analysis entry in the sources, not attributed to any authority. Rates, thresholds, fees and processing times change, usually at the start of a tax year in April; figures are current as at the review date shown and should be confirmed with the responsible body before you rely on them. Much of what follows differs between England, Scotland, Wales and Northern Ireland — where it does, this site says so.