What to do if…
your email password or recovery details are changed without your permission
Short answer
Open your email provider’s official website or app on a device you trust and follow its account-recovery or security process. If you are still signed in, keep that session open while you remove unfamiliar changes, secure the account, and check for forwarding rules.
Do not do these things
- Do not use links or phone numbers in an unexpected security message; open the provider’s official website or app yourself.
- Do not approve an unfamiliar sign-in, password-reset, recovery, or two-step verification request.
- Do not sign out of the only device that still has access until you have followed the provider’s recovery steps.
- Do not reuse the old password or one used for another account.
- Do not delete suspicious security alerts or sent messages before noting the relevant details.
- Do not pay anyone who claims they can recover the account outside the provider’s official support process.
- Do not contact a suspected person through the affected email account.
What to do now
- Open the email provider’s official website or app on a device you trust. Go to its security or account-recovery page. For a work, school, or university account, contact the organisation’s IT administrator.
- If you are locked out, use the provider’s official recovery process. Give the information it asks for and use a recovery address, phone number, device, or method that you still control.
- If you still have access, check the recovery email address, recovery phone number, and other sign-in methods. Remove unfamiliar details and restore your own details where the provider allows this.
- Check email forwarding rules and filters before changing the password. Remove any rule or filter you did not create.
- Change the password to a strong password that is different from every other password you use.
- Use the account’s security settings to sign out other devices and apps. Review recent activity and remove unfamiliar connected apps, delegated access, app passwords, passkeys, or security keys where those options are available.
- Set up a passkey if the provider supports one. Otherwise, turn on two-step verification using a method controlled only by you, and store any recovery codes separately from the email account.
- Secure any separate recovery email account. Change passwords on other accounts that used the same password, starting with accounts that can be reset through this email address.
- Check sent mail, deleted mail, recent sign-ins, password-reset messages, and changes to important linked accounts. Warn contacts through another trusted route if messages were sent from your address without permission.
- Contact your bank or payment provider through trusted contact details immediately if you find an unfamiliar payment or financial-account change.
- Keep screenshots or notes of security alerts, unfamiliar activity, and changes if this does not delay securing the account. Report cyber crime or fraud to Report Fraud in England, Wales, or Northern Ireland, or to Police Scotland if you live in Scotland or the crime happened there.
What can wait
You do not need to identify who changed the details, close the email account, choose a new provider, delete every suspicious message, or review every old online account before regaining control. Detailed clean-up can wait unless money is moving, threats are being made, or the account details keep changing.
Important reassurance
Changed security details are a sign that someone may have accessed the account, but they do not prove that every linked account has been accessed. Recovering the email account, removing unfamiliar access, and securing accounts that depend on it can limit further harm.
Scope note
This guide covers immediate account-recovery and damage-limitation steps only. Later decisions may require help from the email provider, an IT administrator, your bank, the police, or a cyber-security specialist.
Important note
This is general information, not legal, financial, cyber-security, or other professional advice. Recovery options and security-setting names vary between email providers.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.