What do I do if my email account is hacked?
Short answer
Change the password from a device you trust, then check the account's forwarding rules and filters — attackers leave those behind and they survive a password reset. Turn on two-step verification, sign out every other session, and reset the password on anything that used this email to log in. If money has gone, GOV.UK gives 0300 123 2040 for reporting fraud in England and Wales, and Police Scotland in Scotland.
Verified · 8 cited sources
Treat this as the first emergency rather than a nuisance, because email is the master key to everything else. The National Cyber Security Centre puts it plainly — a hacked email account can lead to hacks elsewhere. Whoever holds your inbox can trigger a password reset on your bank, your GOV.UK One Login, your HMRC account and your NHS login, and read the code that arrives to complete it. The order below is the NCSC's, and the order matters more than the speed.
If you are locked out entirely, the route back in is the provider's own account recovery process, not a general helpline. The NCSC's guidance is that each cloud service will have a different process to recover your account, either by yourself or with their support, and it points to the providers' own step-by-step guides — Google Workspace and Microsoft 365 are the two worked examples it links. Its list of warning signs is worth reading alongside that: activity on the account you do not recognise, such as changes to security settings, or password reset messages you did not ask for. Expect recovery to be slow and awkward where the attacker has already changed the recovery phone number and the backup address, and find the provider's support route from its official site rather than trusting the recovery options inside an account that has been tampered with.
The step almost everyone skips is the settings audit, and it is the one that decides whether the attacker stays. The NCSC warns that a common tactic is to set up a forwarding rule so a copy of every incoming message goes to the criminal — which quietly lets them keep resetting your passwords long after you have changed yours. Check forwarding, check filters that auto-delete or auto-archive messages from your bank, check app passwords and connected third-party apps, and reset the recovery phone and address to ones you control.
Then clean up outward. Change the password on every account that shared the old one, because attackers test stolen credentials across services — the NCSC's data breach guidance for individuals points people at haveibeenpwned.com to check where their address has already turned up, and back to its own advice on using a strong and separate password for email. Sign out all other devices and apps that may still be logged in, which is step four of the NCSC's recovery guide, so an old session cannot walk straight back in. Turn on two-step verification, install the latest software and app updates, and notify your contacts so they distrust anything sent from you during the compromise. Cyber Aware's standing advice underneath all of this is short: protect your email with a strong and separate password, use three random words to build it, and turn on 2SV.
Reporting has separate doors and people knock on the wrong one. Forward the phishing message that started it to [email protected] and any scam text to 7726, which GOV.UK says is free. If money has been taken, GOV.UK gives the number 0300 123 2040 for reporting fraud in England and Wales, and says that if you are in Scotland and have lost money because of an online scam or fraud you report the crime to Police Scotland. In Northern Ireland, nidirect's route for reporting a crime is 999 in an emergency, 101 for non-urgent matters, or the PSNI's online reporting form.
If it was a work account, or a personal account holding other people's data, tell your employer straight away and do not attempt a quiet fix. GOV.UK's cyber incident reporting service states plainly that information you give will not be shared with the Information Commissioner's Office, and that you may need to report the incident to the ICO separately if there has been a breach of personal data — it points to the ICO's own self-assessment tool for deciding. Treat those as two different obligations landing on two different desks. And if the account cannot be recovered at all, the NCSC's advice is to create a new account if you want to keep using the service, give your contacts the new details and tell them you have abandoned the old one, then update your banking, utility and shopping accounts with the new address.
- Check forwarding rules and filters — changing the password does not remove them
- Sign out all other sessions, then turn on two-step verification before anything else
- Reset every account that shared the password, and every account that emails reset links here
- Forward the phishing email to [email protected] and scam texts to 7726
- Report losses on 0300 123 2040 in England and Wales; Police Scotland in Scotland; PSNI on 101 in Northern Ireland
- Work account? Tell your employer — the ICO reporting duty sits with the organisation
Go deeper
People also ask
Sources & provenance
Facts verified
- 1.Recovering a hacked account OfficialNational Cyber Security CentreUsed for: The nine recovery steps, the forwarding-rule tactic, signing out devices, and what to do when an account cannot be recovered
- 2.Hacked accounts OfficialNational Cyber Security CentreUsed for: That a hacked email account can lead to hacks elsewhere, and the sequencing of provider contact, settings audit and password changes
- 3.Recovering a hacked account or service OfficialNational Cyber Security CentreUsed for: That unrecognised activity such as changed security settings or unrequested password reset messages are signs of compromise, that each cloud service has a different recovery process, and that Google Workspace and Microsoft 365 are its worked examples
- 4.Cyber Aware OfficialNational Cyber Security CentreUsed for: The strong and separate email password, three random words, 2-step verification and software updates
- 5.Report a scam or phishing email, website or text OfficialUK GovernmentUsed for: [email protected], the free 7726 text service, the number 0300 123 2040 for reporting fraud in England and Wales, and reporting to Police Scotland if you are in Scotland
- 6.Report a cyber incident OfficialUK GovernmentUsed for: That information given through this service will not be shared with the Information Commissioner's Office, and that a personal data breach may need reporting to the ICO separately using its self-assessment tool
- 7.Reporting a crime OfficialnidirectUsed for: The Northern Ireland reporting routes — 999 in an emergency, 101 for non-urgent matters and PSNI online reporting — used here because GOV.UK's fraud number is given for England and Wales
- 8.Data breach guidance for individuals OfficialNational Cyber Security CentreUsed for: That it points readers to haveibeenpwned.com to check exposure and back to the NCSC's strong-and-separate-password-for-email guidance after a breach
The nine-step recovery sequence, the forwarding-rule warning, the instruction to log out other devices and apps, the signs of compromise and the advice on abandoning an unrecoverable account are lifted from the NCSC pages cited, as is the Cyber Aware wording on a strong and separate password, three random words and 2SV. The phishing and 7726 routes and the 0300 123 2040 number for England and Wales come from GOV.UK, the Scottish route from the same page, the Northern Ireland route from nidirect, and the ICO point from GOV.UK's cyber incident service. Our own contribution is the ordering — the settings audit before the outward password sweep — and the framing of email as the master key to One Login, HMRC and NHS accounts, which the cited sources do not put that way. Reporting numbers, web addresses and provider recovery flows change; confirm on GOV.UK and with your email provider before acting.
Facts on this page are taken from the sources listed above — UK government departments, devolved administrations, regulators, statutory bodies and official statistical releases. Comparisons, judgements and "which option suits whom" conclusions are AI-assisted analysis written over those sources; they are marked in the text and listed as an AI-analysis entry in the sources, not attributed to any authority. Rates, thresholds, fees and processing times change, usually at the start of a tax year in April; figures are current as at the review date shown and should be confirmed with the responsible body before you rely on them. Much of what follows differs between England, Scotland, Wales and Northern Ireland — where it does, this site says so.