Email Account Takeover UK: Recover and Lock It Down
Follow your provider’s recovery process, remove unknown forwarding rules, secure linked accounts, and use a passkey where the service offers one.
What email account takeover means
An attacker has gained access to an email account, often through phishing, a reused password, credential theft or malware. Email is particularly important because many other services use it for password resets and security alerts.
Warning signs
- Password-reset or sign-in alerts you did not trigger.
- Messages in Sent, Deleted or Drafts that you did not create.
- Contacts receiving unexpected messages from your address.
- Recovery details, delegates, filters or forwarding rules you do not recognise.
- New devices or active sessions you cannot account for.
Recover the account through the provider
Use the email provider’s official account-recovery page, reached independently rather than through a message. Once access is restored:
1. Review and remove unknown forwarding rules, filters, delegates and recovery addresses. 2. Change the account password if the service still uses one, and change it anywhere it was reused. 3. Sign out other sessions and remove unfamiliar devices or app passwords. 4. Review sent mail, deleted mail, security events and linked accounts. 5. Warn contacts if the attacker sent messages from the account.
NCSC specifically warns that attackers can add forwarding rules so they continue receiving copies of messages and password resets.
Passkeys and two-step verification
NCSC recommends choosing a passkey over a password wherever one is available. Passkeys are phishing-resistant because they are bound to the legitimate service rather than being reusable secrets typed into a page. They still depend on a secure device, credential manager and recovery method.
If the service does not offer passkeys, use a strong unique password generated or stored by a password manager and enable two-step verification. “Three random words” remains an NCSC option for passwords you need to create yourself.
Check breach exposure carefully
haveibeenpwned.com can tell you whether an email address appears in data from a known breach. It does not prove that the email account itself is currently compromised, and a clean result does not prove safety. Never reuse a password exposed in a breach.
If money or other accounts may be at risk
Check shopping, social-media and financial accounts linked to the mailbox. Contact the bank immediately through a trusted number if payment details, banking access or money may be affected. Preserve security alerts and relevant messages.
Reporting in the UK
Forward a suspicious email to report@phishing.gov.uk. If fraud or cybercrime caused a loss, report it at reportfraud.police.uk or on 0300 123 2040 in England, Wales or Northern Ireland. In Scotland, report to Police Scotland on 101. Also report the compromise to the email provider.
Frequently asked questions
What should I check first after recovering an email account?
Check recovery details, forwarding rules, filters, delegates, app passwords and active sessions, then secure every account that reused the same password.
Does a passkey make an account impossible to compromise?
No. It greatly reduces phishing and credential-reuse risk, but device security and account-recovery controls still matter.
Does a breach result on Have I Been Pwned mean my email is hacked now?
No. It means the address appeared in a known breach dataset. Treat exposed or reused passwords as compromised, but use the provider’s security records to assess the account itself.