PanicStation.org
us Technology & digital loss

What to do if…
your email password or recovery details are changed without your permission

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Treat this as a possible account takeover. On a trusted device, open the email provider’s official app or website directly; secure the account if you are still signed in, or start the provider’s official recovery process if you are locked out.

Do not do these things

  • Do not use a link, search advertisement, or phone number from an unexpected security message.
  • Do not share your password, verification codes, backup codes, or recovery answers with anyone who contacts you.
  • Do not pay an unsolicited person or service claiming it can recover the account.
  • Do not close your only working session before using it to secure the account, unless the provider requires you to sign in again.
  • Do not delete security alerts or suspicious messages before recording their dates and taking screenshots.
  • Do not enter a new password on a device you reasonably suspect contains malicious software when another trusted device is available.

What to do now

  1. Use a trusted device. Open the provider’s official app, use a saved bookmark, or manually enter the website address you normally use. Check whether you still have access through an existing signed-in session.

  2. If you are signed in, change the email password immediately. Use a strong, unique password that you have not used for another account.

  3. Check the listed recovery email addresses and phone numbers. Restore details you control and remove any you do not recognize.

  4. Turn on two-factor authentication if it is available. An authenticator app or security key may be offered as a stronger option than a code sent by text or email.

  5. Review recent security activity, devices, and active sessions if the provider offers these controls. Remove unfamiliar devices and sign out other sessions after confirming that your new password and recovery details work.

  6. If you cannot sign in, follow only the provider’s official account-recovery instructions. Give accurate information and monitor any recovery email address or phone number that you still control.

  7. Check for forwarding rules or filters you did not create. Review the sent and deleted folders for messages you did not send or changes you did not make, and remove unfamiliar settings.

  8. Change the password on any other account where you reused the same or a similar password. Start with recovery email, financial, cloud-storage, shopping, social-media, and mobile-carrier accounts.

  9. Look for password-reset or security-change notices involving other accounts. Open each service independently rather than following links in suspicious messages.

  10. If your phone unexpectedly lost service or your mobile account was changed, contact your carrier through its official app, website, store, or customer-service number.

  11. If messages were sent from your account, warn affected contacts through another trusted channel. Tell them to ignore unexpected links, attachments, requests for codes, or requests for money from your address.

  12. For a work or school account, contact the organization’s official IT or security team promptly. If money was transferred or a financial account was changed, contact the financial institution immediately. Use IdentityTheft.gov if someone has used your personal information.

What can wait

You do not need to identify who made the changes, read every message, replace every device, change every unrelated password, or decide whether to abandon the email address right now. First regain control, remove unfamiliar access, and secure the most important connected accounts.

Important reassurance

Unauthorized changes are a serious warning, but they do not prove that every message or linked account was accessed. Securing the email account and its recovery routes can limit further access.

Scope note

This guide covers immediate first steps only. Continuing access problems, identity theft, financial loss, or a workplace incident may require help from the provider, your organization, a financial institution, or a cybersecurity professional.

Important note

This is general digital-safety information, not legal, financial, or professional cybersecurity advice. Features and recovery procedures vary by provider, so follow the instructions on the provider’s official website.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us