How to Remove a Hacker From Your Email Account for Good

You logged in and something is off. Maybe your password no longer works, your contacts say they got spam from you, or you received a sign-in alert or a two-factor code you never requested.

T

Technobezz

Editorial Team

May 30, 2026
•
9 min read

Contents

Don't Miss the Good Stuff

Get tech news that matters delivered to your inbox.

You logged in and something is off. Maybe your password no longer works, your contacts say they got spam from you, or you received a sign-in alert or a two-factor code you never requested. Maybe mail has simply stopped arriving.

Someone else has access to your email, and that is serious because your inbox is the reset point for nearly every other account you own. The goal here is not just to change your password. It is to lock the intruder out for good so they cannot quietly walk back in.

Work through the steps below in order. The sequence matters: a few common mistakes (like changing your password before clearing malware) let the attacker keep their grip. We cover the universal recovery order first, then the exact paths for Gmail, Outlook.com, Yahoo Mail, and Apple Account.

Remove Malware Before You Touch the Password

Run a full antivirus scan on the device first. If a keylogger is recording what you type, changing your password just hands the attacker the new one. Microsoft makes this its explicit first step.

On Windows with Microsoft Defender, open Windows Security > Virus & threat protection > Scan options > Full scan > Scan now. Let it finish and remove anything it flags before continuing.

This single ordering choice is what separates a fix that holds from one that fails within hours.

Use the Provider's Own Recovery Process

Always start from the service's official help and recovery pages, never a third party. Google states plainly that it does not work with any outside service claiming to provide password support, and you cannot call to sign in.

Be careful here: tech-support scams thrive on this moment of panic. Google, Yahoo, and Apple never ask for your password or your verification codes in an email or phone call. If someone asks you to read out an SMS code, that is the attack, not the rescue. Do not share passwords or codes with anyone.

Change the Password to Something New and Unique

Once the device is clean, set a strong password you have never used anywhere before. Reused passwords are the single most common way intruders get in, since a password leaked in one breach gets tried everywhere.

If the attacker already changed your password, use the reset or recovery option instead of the normal change flow.

Sign Out of All Devices and Revoke Active Sessions

Changing the password does not, on its own, kick out someone who already has an active signed-in session. You must end every session to cut their live access.

In Gmail, go to myaccount.google.com, select Your devices, then Manage devices; for anything unfamiliar, choose "Don't recognize a device?" and follow the steps to sign it out. In Apple Account, go to account.apple.com, select Devices, and remove any device you do not recognize.

Delete Forwarding Rules, Filters, and Altered Mail Settings

This is the classic persistence trick. A hidden forwarding rule sends the attacker copies of your mail (including password-reset links) long after you regain control. Hunt these down and delete anything you did not create.

In Gmail, review and remove: automatic forwarding, filters, the vacation/auto-reply responder, scheduled emails, mail delegation, the "Send mail as" outgoing address, blocked addresses, and IMAP/POP remote access. Also check your Sent folder for messages you did not write.

In Outlook.com, Microsoft flags three areas to re-check by hand: Connected accounts, Forwarding, and Automatic replies. In Yahoo Mail, revert any changed email filters, sending name, signature, reply-to address, send-only address, vacation response, default From address, blocked list, and auto-forwarding address.

Review Recent Activity to Confirm the Intruder

Seeing the unauthorized session helps you confirm the breach and force a re-secure.

For a Microsoft account, go to the Recent activity page at account.live.com/Activity (it shows the last 30 days). Expand a suspicious entry to see its IP, location, device, and app; under Unusual activity, expand it and choose "This wasn't me." You will then be prompted to change your password and update your security info, so complete both.

For Gmail, at myaccount.google.com select Security, then on Recent security events choose "Review security events"; for anything suspicious select "No, it wasn't me" and follow the steps. One caution: mobile-carrier traffic can make a legitimate sign-in look like it came from a far-off city, so an unfamiliar location alone is not proof.

Fix Your Recovery Email and Phone Number

Attackers often add their own recovery phone or email so they can re-take the account later. Remove anything you do not recognize, and confirm a current recovery email and phone you control.

For an Apple Account, go to account.apple.com and correct any personal or security info you do not recognize; confirm you control every email and phone number listed, and check for unauthorized SMS forwarding with your carrier.

Revoke Third-Party App Connections and App Passwords

An app or app-specific password that was authorized earlier can keep reading your mailbox even after a password change. Revoke what you do not recognize.

In Google, go to myaccount.google.com/connections. For an app under "Access to your Google Account," select it, choose See details, then Remove access, then Confirm. For a Linked account, choose See details under "Google has some access," then Delete link, then Confirm. In Yahoo Mail, delete any app passwords you do not recognize. Apple users should review app-specific passwords likewise.

Turn On Two-Step or Two-Factor Verification

This is what makes a stolen password worthless on its own. Set it up after you have re-secured everything else.

For Gmail, go to myaccount.google.com/signinoptions/two-step-verification. For Apple, set up two-factor authentication and consider Security Keys, a device passcode, and Stolen Device Protection on iPhone. Microsoft and Yahoo both offer two-step verification in their security settings.

Change That Password on Every Other Account

If you reused the compromised password anywhere else, the email fix is incomplete. The attacker simply pivots to those accounts through password reuse.

Change it everywhere it was used. For Gmail users, you can check for compromised saved passwords at passwords.google.com/checkup/start.

Notify Contacts and Check for Fraud

Tell your contacts the account was compromised and to treat any recent messages from you as suspicious, especially links or money requests sent in your name.

Then review your bank and shopping accounts for unauthorized activity, since a compromised inbox is often used to reset those next.

Exact Apple Account Password Paths

Apple's password lives in different spots per device, so here are the verified routes.

  1. 1.iPhone or iPad: Settings > [your name] > Sign-In & Security > Change Password, then follow the prompts.
  2. 2.Mac: Apple menu > System Settings > [your name] > Sign-In & Security > Change Password (enter your Mac unlock password first).
  3. 3.Web: go to account.apple.com, sign in, select Sign-In and Security > Password (it may redirect you to a trusted device).

Gotcha: if Stolen Device Protection is on, you may have to wait one hour before changing the password or other critical security settings.

When You Cannot Sign In at All

If you are fully locked out, use each provider's recovery flow. For Gmail, go to accounts.google.com/signin/recovery (also reachable via g.co/recover) and answer the recovery questions as accurately as you can; wrong guesses do not lock you out, but changes to your recovery info can take up to 7 days to take effect.

For a Microsoft account, complete the recovery form, which requires a separate working email address Microsoft can reply to. For Apple, start account recovery at iforgot.apple.com and wait out the required waiting period. Yahoo users who still cannot get in can contact Yahoo Customer Care.

Frequently Asked Questions

Why isn't changing my password enough to remove the hacker?
Because three things survive a password change: an active signed-in session, an authorized third-party app or app-specific password, and any forwarding rule or filter they added. You have to sign out all devices, revoke connections and app passwords, and delete hidden mail rules for the lockout to be permanent.

Should I really scan for malware before changing my password?
Yes, and Microsoft makes it the explicit first step. If a keylogger is on the device, it captures the new password the moment you type it, so the breach simply repeats. Run a full antivirus scan and clean the device first.

The sign-in activity shows a login from another country. Was I definitely hacked?
Not necessarily. Mobile-carrier traffic can route through a distant city and make a legitimate sign-in look foreign. Judge by the device, app, and whether you actually signed in, not by location alone, and confirm before assuming the worst.

A "support" service offered to recover my account for me. Is that safe?
No. Google states it does not work with any service claiming to offer account or password support, and you cannot call to sign in. Apple and Yahoo never ask for your password or 2FA codes. Treat any such request as an attack and only use the provider's official recovery pages.

How long does account recovery take?
It varies. Google notes that changes to your recovery info may take up to 7 days to take effect for security reasons, and there is no penalty for wrong recovery guesses. Apple enforces a waiting period during account recovery, and Stolen Device Protection can add a one-hour delay before you can change critical settings.

What forwarding and address settings should I check specifically?
Look for auto-forwarding rules, filters, the vacation or auto-reply responder, and any "Send mail as," reply-to, send-only, or connected/linked account the intruder added. These let them keep copies of your mail or impersonate you, so delete anything you did not set up yourself.