Personal Security
Email Hacked? (2026): 14 Signs Your Email Was Compromised and How to Take It Back
Your email account is the master key to your entire digital life. Here are the 14 signs that it has been compromised, the free tools that confirm it in under five minutes, and the exact 12-step lockdown sequence Miami incident responders use to take an account back and keep it.

Almost every serious incident we investigate in Miami starts in the same place: somebody's email account. Not a firewall, not a server — an inbox. That is because email is the recovery mechanism for everything else you own. Your bank, your brokerage, your crypto exchange, your title company, your cloud drive and your children's school portal all reset passwords by sending a link to that one address.
So when clients ask us how to tell whether their email has been hacked, we treat it as the highest-priority question in personal security. This guide gives you the fourteen signs, the free checks that confirm it in minutes, the full lockdown sequence, and what to do if the account was tied to a business.
14 signs your email has been hacked
Some of these are obvious. The dangerous ones are the quiet ones near the bottom of this list — the signals that indicate an attacker is still inside and intends to stay.
- 1You receive a sign-in alert from an unfamiliar device, browser or location. Providers send these for a reason. Do not dismiss one because you were traveling — verify it inside the account's security activity page.
- 2Your password suddenly stops working. If you did not change it, someone else may have. This is the single most urgent sign, because it means the attacker has already locked you out.
- 3Messages appear in your Sent folder that you never wrote — often short, link-heavy notes to your own contacts.
- 4Friends, colleagues or clients tell you they got a strange email from you. Believe them. Ask them to forward it with full headers.
- 5Password reset emails arrive for accounts you did not try to reset. Someone is walking your inbox looking for what else they can take.
- 6Emails you expected never arrive, or messages vanish from the inbox. A rule that auto-deletes bank and security notifications is a classic persistence trick.
- 7A forwarding address you do not recognize appears in settings. This is the most common and most damaging finding — it silently copies every future email to the attacker even after you change your password.
- 8New filters or rules exist that you did not create, especially ones that mark messages read, archive them, or route anything containing 'security', 'invoice', 'wire' or 'bank' to trash.
- 9Your recovery phone number or backup email has been changed to something unfamiliar. This is how the attacker plans to lock you out permanently.
- 10Your display name, signature or auto-reply has been edited — often to add a fake phone number for a callback scam.
- 11Unfamiliar third-party apps or OAuth grants are connected to your account with read access to mail.
- 12Contacts, calendar entries or files disappear, or new calendar invites you did not accept appear on your schedule.
- 13Have I Been Pwned shows your address in a recent breach, particularly one that exposed passwords rather than just email addresses.
- 14Your bank, credit or e-commerce accounts show activity you did not authorize. By the time this appears, email compromise is usually the root cause, not a coincidence.
"Nine times out of ten, the client already had the evidence in front of them — a forwarding rule they never opened settings to see. The password change felt like the fix. It wasn't."— Cybrvault incident response team
Confirm it in five minutes: three free checks
1. Check breach databases
Enter your address at Have I Been Pwned, the breach index maintained by security researcher Troy Hunt. It tells you which known breaches included your address and what data was exposed. An email-only exposure means expect phishing; an exposure that included passwords means change that password everywhere it was reused, immediately.
A hit does not prove your account is currently compromised — it proves your credentials are in circulation. Combine it with the next two checks. If you want to know how criminals actually use that data afterward, see our guide on whether your email is on the dark web.
2. Read your provider's security activity log
- Gmail / Google: open your Google Account, then Security, then 'Your devices' and 'Recent security activity'. Also scroll to the bottom right of Gmail on desktop and click 'Details' for the last account activity list with IP addresses.
- Outlook / Microsoft: go to account.microsoft.com, then Security, then 'Sign-in activity'. It shows successful and failed attempts with approximate location and app used.
- Apple / iCloud: check appleid.apple.com under Devices, and review which devices are signed in and trusted.
- Yahoo: use Account Info, then 'Recent activity' to view sign-ins and app access.
Approximate locations are geolocated from IP and are frequently off by a city or two — a Miami sign-in showing as Doral or Hialeah is normal, one showing as another country is not.
3. Audit the four persistence points
This is the check almost everyone skips. Open your mail settings and inspect, in this order:
- 1Forwarding — is mail being copied anywhere? Remove any address you did not add yourself.
- 2Filters and rules — read every one. Delete anything that deletes, archives, marks-read or forwards based on keywords.
- 3Recovery phone and recovery email — confirm both belong to you and are current.
- 4Connected apps, app passwords and third-party access — revoke everything you do not actively use and recognize.
How email accounts actually get taken over
Understanding the entry point tells you which defense actually matters.
- Credential stuffing. A password you reused was exposed in an unrelated breach, and automated tools tried it against your email provider. This is the number one cause and it is entirely preventable with unique passwords.
- Phishing. A convincing message about a suspended account, a shared document or a package delivery sends you to a fake sign-in page. Modern phishing kits also capture the six-digit code you type, in real time, and use it before it expires.
- Malware and infostealers. A cracked download, a malicious browser extension or a fake installer harvests saved passwords and, worse, session cookies — which log the attacker in without needing a password or a code at all.
- SIM swapping. An attacker convinces or bribes a carrier representative to move your number to their SIM, then receives your SMS reset codes. South Florida has been a persistent hotspot for this.
- Public Wi-Fi and rogue hotspots. Less common than it used to be thanks to HTTPS, but still a real risk on hotel, airport and café networks — see our home and public Wi-Fi security guidance.
- Recovery-path abuse. If your recovery email is an old, abandoned account with a weak password, that account is now the weakest link in your chain.
- Consent phishing. You are asked to 'sign in with Google' to a legitimate-looking app, and you grant it permanent read access to your mailbox. No password is ever stolen — you handed over a key.
The 12-step lockdown: how to take your account back
Do these in order. Order matters — changing the password before you remove persistence just tells the attacker you noticed.
- 1Get on a clean device. If you suspect malware, do not use the infected computer. A phone that has never had sideloaded apps is usually the safest option available immediately.
- 2Change the password to something long, unique and generated by a password manager. Aim for 16+ characters. Never reuse it anywhere.
- 3If you are locked out, start the provider's account recovery immediately — Google, Microsoft, Apple and Yahoo all run identity-verification recovery flows. Answer from a device and location you normally use; both improve your odds.
- 4Sign out all other sessions. Every provider has a 'sign out of all devices' control. This kills stolen session cookies, which passwords alone do not.
- 5Remove unauthorized forwarding addresses.
- 6Delete every filter or rule you did not create.
- 7Restore your recovery phone and recovery email to addresses and numbers you control, and delete the attacker's.
- 8Revoke all app passwords and disconnect third-party apps with mailbox access. Reconnect only the ones you genuinely use.
- 9Turn on phishing-resistant two-factor: a passkey or a hardware security key such as a YubiKey. If neither is available, use an authenticator app. Use SMS only as a last resort — see passkeys vs passwords.
- 10Generate and safely store new backup codes. Print them or put them in your password manager's secure notes — not in the email account itself.
- 11Change the password on every account that uses this email for recovery, starting with banking, brokerage, crypto, cloud storage and your phone carrier. Anywhere you reused the old password is a live risk.
- 12Scan the device you normally read mail on for malware, and check your browser extensions. If the account keeps getting retaken after a clean password change, an infostealer is still resident.
Then watch the account for two weeks. Re-check forwarding and rules every few days. Re-compromise almost always happens through a persistence mechanism nobody removed, not a second break-in.
Also do these, within 48 hours
- Warn your contacts. A short, plain note: 'My email was compromised. If you got anything odd from me, delete it and don't click. Verify any money request with me by phone.' This prevents the second wave of victims.
- Freeze your credit at Equifax, Experian and TransUnion. It is free, takes minutes, and blocks the most profitable use of stolen identity data.
- Add a port-out PIN or number-lock with your mobile carrier to blunt SIM-swap attempts.
- Review your sent mail and trash for what the attacker saw and sent — that inventory determines who else needs to be notified.
- Check for financial exposure: unauthorized logins, changed payout details, new payees on bank and payment accounts.
- Report it. Individuals should file with the FTC at identitytheft.gov; losses or business impact also go to the FBI at ic3.gov.
If it was a business email account, the stakes change
A compromised business inbox in Miami is rarely the end goal. It is a staging area for invoice fraud and wire redirection — the attacker sits quietly, reads how your company talks about money, then sends a payment-detail change from your real address to a real client. We break down exactly how this is staged in our business email compromise guide.
For a business account, add these steps:
- Preserve evidence before you clean up. Export the mailbox audit log and message trace. Deleting the attacker's rules without capturing them destroys the record of what happened and when.
- Determine the exposure window — first unauthorized sign-in to last — and identify every client, employee or patient record accessible in that window.
- Check whether any outbound payment instructions were altered. Call every affected client by phone.
- Assess reporting obligations. Florida's breach notification statute requires notice to affected individuals within 30 days, and to the Department of Legal Affairs when 500 or more Floridians are involved. Our Florida data breach law explainer covers the specifics.
- Notify your cyber insurance carrier promptly — most policies require early notice and many provide a breach coach at no additional cost.
- Enforce phishing-resistant MFA tenant-wide, disable legacy authentication protocols, and turn on alerting for new mailbox forwarding rules across every account, not just the one that was hit.
How to make sure it does not happen again
- 1One unique password per account, generated and stored in a password manager. This alone eliminates credential stuffing.
- 2Passkeys everywhere they are offered, and a hardware key on your primary email as the ultimate backstop.
- 3Separate your identities: one email for banking and government, one for shopping and newsletters, one public-facing address for business. A breach of the throwaway address then costs you nothing.
- 4Keep your recovery email a real, secured, actively monitored account — not an abandoned address from 2011.
- 5Slow down on urgency. Every phishing message engineers a deadline. Treat 'act now or your account will be suspended' as the tell that it is fake.
- 6Verify money by voice. Any change to wiring or payment details gets confirmed on a phone number you looked up yourself, never one in the email.
- 7Patch your devices and browser, and remove extensions you do not need. Infostealers arrive through both.
- 8Set a quarterly reminder to re-check forwarding rules, connected apps and Have I Been Pwned. Ten minutes, four times a year.
The bottom line
Email compromise is not exotic and it is not rare. It is the ordinary, repeatable front door into someone's finances — and it usually opens because a password was reused and a second factor was never enabled. The signs are visible if you know where to look, and the fix is a defined sequence rather than a guess.
If you have found evidence of a compromise and the account touched your business, your clients or a real estate transaction, do not clean it up alone — the cleanup destroys the evidence you may need. Cybrvault runs confidential email compromise investigations for individuals and businesses across Miami-Dade, Broward and Palm Beach. Book a free consultation and we will scope it in 30 minutes.
// frequently asked
Questions teams ask us
How can I tell if my email has been hacked or just spoofed?+
Spoofing means someone forged your address as the sender without ever accessing your account — your Sent folder will be empty of those messages and your sign-in activity will look normal. A real compromise shows unfamiliar sign-ins, messages in your Sent folder, or settings changes such as new forwarding rules. Check the security activity log first; that distinction determines whether you need a full lockdown or just a warning to your contacts.
Does changing my password fix a hacked email account?+
Not by itself. Attackers commonly leave behind forwarding rules, filters, app passwords, altered recovery addresses and active sessions, all of which survive a password change. You must also sign out all devices and remove every persistence mechanism, then enable phishing-resistant two-factor. Skipping that is the main reason accounts get retaken within days.
What does it mean if Have I Been Pwned shows my email?+
It means your address appeared in a known data breach. If only your email was exposed, expect more phishing and spam. If passwords were exposed, change that password immediately everywhere you reused it — credential stuffing against reused passwords is the most common cause of email takeover.
Is SMS two-factor enough to protect my email?+
It is far better than nothing but it is the weakest common option. SIM swapping lets an attacker move your phone number to their device and receive your codes, and real-time phishing kits capture typed codes before they expire. Passkeys or a hardware security key resist both attacks and are the standard we recommend for any primary email account.
My business email in Miami was compromised — do I have to notify anyone?+
Possibly. Florida's data breach notification law requires notifying affected individuals within 30 days when personal information is compromised, and notifying the Department of Legal Affairs when 500 or more Floridians are affected. Industry rules such as HIPAA or bar association obligations may add requirements. Preserve the mailbox logs before cleanup and consult counsel or an incident response firm to determine scope.
How long does it take to recover a hacked email account?+
If you still have access, the full lockdown takes about 30 to 60 minutes. If the attacker changed your recovery details and locked you out, provider account recovery typically takes anywhere from a few hours to a couple of weeks depending on how much identity evidence you can supply. Attempting recovery from a device and location you normally use materially improves your chances.
// miami, fl services
Cybersecurity built for South Florida
// need help applying this?
Book a free, confidential consultation.
Our engineers can map this to your environment in 30 minutes.
Get secured// keep reading
Related articles

Personal Security
The Safest Neighborhoods in Miami (2026): A Security Pro's Ranked Guide
A 2026 security-professional's ranked guide to the safest neighborhoods in Miami — real crime data, home-invasion and burglary trends, HOA and patrol coverage, hurricane-season looting risk, and the exact hardening steps we recommend to clients block by block, from Key Biscayne and Pinecrest to Coral Gables, Aventura, Doral, and Bay Harbor Islands.

Personal Security
Snap Hack: Understanding the Risks and How to Protect Your Snapchat Account in 2026
Snapchat accounts are hijacked every day through phishing 'login' pages, fake third-party 'snap score booster' apps, and SIM-swap attacks. Here's how Snap accounts actually get hacked in 2026, the red flags to watch for, and the 7-step lockdown that stops 95% of takeovers.

Personal Security
TikTok Hacked? What to Do and How to Protect Your Account in 2026
TikTok accounts are hijacked through fake follower-boost apps, phishing DMs, and SIM-swap attacks. Here's the exact recovery path if your TikTok is compromised, plus the 6-step lockdown that prevents most takeovers.
