MYTHOSAI

Security basics / PRACTICAL GUIDE

Recover a compromised email account

Remove attacker access, check hidden mailbox changes and protect password-reset channels.

Before you start

Access to your provider recovery process and a trustworthy device.

Treat email as a recovery hub

An email account often controls password resets for other services. Unexpected sent mail, altered recovery details or a provider alert deserve prompt investigation. Ask contacts to preserve suspicious messages rather than simply deleting every trace of what happened.

Regain access through the provider

Use the real provider's account-recovery page, opened directly. If you still have access, start the security review before signing out of your only working session. If you are locked out, use the provider's documented recovery route. Do not pay a stranger on social media who promises a special recovery tool.

Remove the ways an attacker can return

  1. Change the password from a trustworthy device and replace reused credentials on other services.
  2. Review recent activity and signed-in devices. Use the provider's available session-revocation controls for unfamiliar access.
  3. Check recovery email addresses, telephone numbers, passkeys, authenticator registrations and app passwords. Remove unauthorised entries carefully; do not delete your only valid factor.
  4. Inspect third-party applications and revoke permissions you do not recognise or no longer need.

MFA improves the next sign-in but does not automatically remove every existing session or application permission.

Inspect mailbox settings

Review automatic forwarding, inbox rules, filters, delegates and connected accounts. Attackers may forward invoices or hide security notifications. Check Sent, Deleted and archive folders for clues. A rule that deletes messages containing security alerts is a different problem from an unfamiliar browser session; both need attention.

For a business mailbox, involve the administrator. Preserve relevant logs, investigate whether other users received malicious messages and assess potential information exposure. Avoid deleting evidence solely to make the mailbox look tidy.

Protect accounts depending on this mailbox

Prioritise financial, work and password-manager accounts whose reset emails go here. Review their activity separately. Warn affected contacts using a verified communication route and explain that recent requests for money or sign-in codes may be fraudulent.

Verify and monitor

Test a genuine sign-in, confirm a usable recovery method and send a harmless message to yourself to check unexpected forwarding behaviour. Review activity again after recovery. Record which settings changed and when, without exposing codes in screenshots.

Common mistakes

Changing only the password overlooks delegates and app access. Deleting the whole mailbox can destroy evidence and business records. Assuming a successful sign-in means the original device is clean can lead to another compromise. Address account access and device trust as separate tasks.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.