How people find out

Rarely by noticing a break-in. Usually one of these:

Friends reply to a message you never sent, often a short one with a link. Your own address starts receiving bounce messages for mail you did not send. You cannot sign in with a password you are certain of. Or password reset emails arrive for accounts you did not ask to reset, which means someone already has the email and is working through what it unlocks.

Treat that last one as urgent, even if nothing else looks wrong.

Do this in order

Change the password, from a different device. If there is any chance the computer itself is compromised, changing the password on it simply hands over the new one. Use your phone, a tablet, a work machine — anything else.

Use a password you’ve never used anywhere else. If the old one was shared with other accounts, change those too.

Turn on two-factor authentication. Do it straight away, while you’re already in the settings. Whoever got the password once may be able to get it again, and two-factor authentication stops them signing in even if they do. For a personal email account, it’s the most useful security setting there is.

Sign out every other session. A password change does not evict someone already signed in. Gmail has “Sign out of all other sessions” at the bottom of the inbox; Outlook.com has it under security settings. Until you do this, they may still be reading along.

Now check what they changed

People often skip this part, and it’s the reason some accounts get taken over again a few weeks later.

Someone who gets into an email account will often change settings so they keep getting in, or keep getting copies of your mail, after you’ve changed the password. Check these four things.

Forwarding rules. A rule copying every message to an address you don’t recognise. Your mail arrives normally, you notice nothing, and they keep receiving it indefinitely.

Filters and rules that delete. These are harder to spot. A rule might file anything mentioning your bank, or containing the word “password”, straight into Archive or Trash, so you never see the security alerts.

The recovery email and phone number. If these have been changed to theirs, they can reset your password whenever they like and you cannot. Check both read what you expect.

App passwords and connected apps. Long-lived tokens that keep working after a password change. Revoke anything you do not recognise.

Checking all four takes about ten minutes, and it’s how you make sure they’re really locked out.

Tell people

Send a short message to your contacts saying your email was compromised and to ignore anything odd from you. Scammers often use a hacked account to send messages to the owner’s contacts, because people trust mail from someone they know. A one-line message is enough.

If money or identity documents were involved

Ring your bank on the number on your card, not one from an email or a search result. Say the email account tied to your banking was compromised, and ask them to note it.

If the mailbox contained scanned identity documents — passport, licence, Medicare card, tax file number — take it seriously. IDCARE is Australia’s free identity support service and a good first call. They’ll tell you which steps are needed for your situation.

The reuse problem

Almost every compromised personal account comes down to the same thing: the password was used somewhere else, and that somewhere else was breached.

The usual advice is to change the password everywhere you used it, but few people remember where they used a password from ten years ago.

A more realistic approach is to change the important ones now (email, banking, anything holding a card number) and use a password manager from here on. It gives every account a different password without you having to remember them, which makes it much easier to keep up.

Have a look at haveibeenpwned.com while you are at it. Type in the address and it lists the breaches it has appeared in. It’s free and run by an Australian security researcher, and most people are surprised by how many breaches their address has been caught up in.