Windows guide · Account security

Email hacked? How to check your account and respond

Unknown sign-ins, messages you did not send or a suddenly changed password? This guide gives you a clear order for checking your account and taking the first steps, without panic or exaggerated security promises.

A data-breach finding is not automatically proof that someone currently controls your account.

Check warning signs
HackCheck product image for Windows
Stay informed about risks
01Understand warning signs
02Secure the account first
03Understand monitoring

The short answer

What should you do if your email was hacked?

First check whether you still have access and which activities or settings are unfamiliar. If you can access the account, change its password as soon as possible, end active sessions and then secure any other affected accounts.

The order follows the guidance from the German Federal Office for Information Security (BSI).

In four steps

  1. 01Check accessCan you still sign in?
  2. 02Change the passwordUse a unique password for this account.
  3. 03Secure other accountsCheck reused passwords and recovery options.
  4. 04Check settingsCheck sessions, forwarding rules and devices.

Step 1 · Check

How can you tell if your email was hacked?

One unusual signal is not conclusive proof. You should nevertheless take several unfamiliar changes or activities seriously.

  • You can no longer sign in

    Your login details may have been changed.

  • Unfamiliar account changes

    For example, new devices, sign-ins or changed recovery options.

  • Messages you did not send

    Contacts report emails that you did not send yourself.

  • Your password or settings changed

    Also check automatic forwarding rules and active sessions.

Step 2 · Immediate steps

Email hacked: follow this order

Work through the steps in this order where possible. If you no longer have access, start with your provider’s official recovery process.

  1. 01

    Change your email account password

    If you still have access, change the password as soon as possible. Use a unique, strong password that you do not use for other accounts.

  2. 02

    End active sessions

    End unfamiliar or all active sessions if your provider offers this option. Devices will then have to sign in again.

  3. 03

    Check other accounts

    Change reused passwords and secure accounts where the affected email address is used as a login or recovery address.

  4. 04

    Check settings and contacts

    Check forwarding rules, recovery options and unfamiliar changes. Tell your contacts if messages were sent from your account by someone else.

No access? Contact the provider of the affected account and follow its official recovery process. Do not use links in suspicious messages for recovery.

Step 2b · If you have no access

What should you do if you can no longer sign in?

You can still limit the impact without access. Work on the affected account and on the services connected to it.

Contact the provider

Contact the provider of the affected account and use only its official recovery process. If you can use a second email address or another recovery option, check first that it is still correct.

Secure connected accounts

Give other accounts their own passwords if you reused the affected password or if the affected address is used for password resets. Also check applications where you sign in with this email account through single sign-on.

Tell your contacts

Tell your contacts that messages from the affected address may not have come from you. This helps them assess suspicious links or attachments more carefully.

Step 3 · Check for a data breach

Where can you check whether your email address appeared in a data breach?

For a one-time check, you can use an independent service such as the HPI Identity Leak Checker. It also explains why specific passwords are not displayed publicly. A finding is a reason to act, not proof that an account is currently compromised.

Data-breach check
Enter an email address
Interpret the resultA finding means: change the password and check other accounts.

Step 4 · Follow-up check

What should you watch after securing the account?

The first changes are done once you regain access. Continue checking whether unfamiliar activity appears or settings change again.

HackCheck product image for WindowsOptional product bridge

If you want to stay informed in future

HackCheck: Monitor online accounts and mobile phone numbers

The official Abelssoft product page describes HackCheck as Windows software that monitors online accounts and mobile phone numbers for hacks and alerts you when security risks are found.

Alert systemDark-web monitoringFor WindowsPassword generator

This is a product bridge, not a promise that HackCheck will automatically restore an account that has already been taken over. The official product page is authoritative for the current version, trial scope and terms.

Learn about and try HackCheck (add the full version to the cart)

FAQ

Frequently asked questions about hacked email accounts

The answers distinguish one-time checks, account security and ongoing monitoring.

How can you tell if your email was hacked?

Warning signs can include a denied login, unfamiliar sign-ins or account settings, messages you did not send and password changes you did not make.

What should you do if your email was hacked?

If you still have access, first change the email account password, end active sessions, check settings and then secure other accounts with unique passwords. If you have no access, contact the provider.

Can I check whether my email address appeared in a data breach?

Yes. Independent services such as the HPI Identity Leak Checker can help. A data-breach finding does not automatically prove that an account is currently compromised.

What is the difference between a check and monitoring?

A check answers a specific question at one point in time. Monitoring repeatedly watches stored data and can notify you when a security risk is found.

Can HackCheck monitor my email address?

The official HackCheck page describes monitoring online accounts and mobile phone numbers. Check the current feature set directly on the official product page.

What should I consider for connected accounts?

Check accounts where you reused the same password or where the affected email address is used for password resets. This also includes applications where you sign in through single sign-on with the email account.

What should I check after recovery?

Check active sessions, unfamiliar devices, forwarding rules and recovery options. Also watch for further unfamiliar messages and reports from contacts.

Is this guide security advice?

No. This guide summarizes general, cautious steps and does not replace individual advice from your email provider, the BSI or a responsible authority.

Further sources

Reliable next steps

For account security and interpreting data-breach findings, follow the official guidance from the relevant authorities.