Contact the provider
Contact the provider of the affected account and use only its official recovery process. If you can use a second email address or another recovery option, check first that it is still correct.
Windows guide · Account security
Unknown sign-ins, messages you did not send or a suddenly changed password? This guide gives you a clear order for checking your account and taking the first steps, without panic or exaggerated security promises.
A data-breach finding is not automatically proof that someone currently controls your account.
The short answer
First check whether you still have access and which activities or settings are unfamiliar. If you can access the account, change its password as soon as possible, end active sessions and then secure any other affected accounts.
The order follows the guidance from the German Federal Office for Information Security (BSI).
Step 1 · Check
One unusual signal is not conclusive proof. You should nevertheless take several unfamiliar changes or activities seriously.
Your login details may have been changed.
For example, new devices, sign-ins or changed recovery options.
Contacts report emails that you did not send yourself.
Also check automatic forwarding rules and active sessions.
Step 2 · Immediate steps
Work through the steps in this order where possible. If you no longer have access, start with your provider’s official recovery process.
If you still have access, change the password as soon as possible. Use a unique, strong password that you do not use for other accounts.
End unfamiliar or all active sessions if your provider offers this option. Devices will then have to sign in again.
Change reused passwords and secure accounts where the affected email address is used as a login or recovery address.
Check forwarding rules, recovery options and unfamiliar changes. Tell your contacts if messages were sent from your account by someone else.
No access? Contact the provider of the affected account and follow its official recovery process. Do not use links in suspicious messages for recovery.
Step 2b · If you have no access
You can still limit the impact without access. Work on the affected account and on the services connected to it.
Contact the provider of the affected account and use only its official recovery process. If you can use a second email address or another recovery option, check first that it is still correct.
Give other accounts their own passwords if you reused the affected password or if the affected address is used for password resets. Also check applications where you sign in with this email account through single sign-on.
Tell your contacts that messages from the affected address may not have come from you. This helps them assess suspicious links or attachments more carefully.
Step 3 · Check for a data breach
For a one-time check, you can use an independent service such as the HPI Identity Leak Checker. It also explains why specific passwords are not displayed publicly. A finding is a reason to act, not proof that an account is currently compromised.
Step 4 · Follow-up check
The first changes are done once you regain access. Continue checking whether unfamiliar activity appears or settings change again.
Sign-ins and sessionsContinue checking unfamiliar devices, active sessions and new sign-in alerts.
Forwarding and recovery optionsLook for unfamiliar forwarding rules and changes to phone numbers or recovery addresses.
Messages from contactsTake reports of further unfamiliar messages seriously and check the account again.
Optional product bridgeIf you want to stay informed in future
The official Abelssoft product page describes HackCheck as Windows software that monitors online accounts and mobile phone numbers for hacks and alerts you when security risks are found.
This is a product bridge, not a promise that HackCheck will automatically restore an account that has already been taken over. The official product page is authoritative for the current version, trial scope and terms.
Learn about and try HackCheck (add the full version to the cart)FAQ
The answers distinguish one-time checks, account security and ongoing monitoring.
Warning signs can include a denied login, unfamiliar sign-ins or account settings, messages you did not send and password changes you did not make.
If you still have access, first change the email account password, end active sessions, check settings and then secure other accounts with unique passwords. If you have no access, contact the provider.
Yes. Independent services such as the HPI Identity Leak Checker can help. A data-breach finding does not automatically prove that an account is currently compromised.
A check answers a specific question at one point in time. Monitoring repeatedly watches stored data and can notify you when a security risk is found.
The official HackCheck page describes monitoring online accounts and mobile phone numbers. Check the current feature set directly on the official product page.
Check accounts where you reused the same password or where the affected email address is used for password resets. This also includes applications where you sign in through single sign-on with the email account.
Check active sessions, unfamiliar devices, forwarding rules and recovery options. Also watch for further unfamiliar messages and reports from contacts.
No. This guide summarizes general, cautious steps and does not replace individual advice from your email provider, the BSI or a responsible authority.
Further sources
For account security and interpreting data-breach findings, follow the official guidance from the relevant authorities.