All guides

Practical breach-response guide

Secure your email after a breach

A calm, ordered response that starts with a trusted device and protects the accounts your inbox can reset.

First, establish a safe place to work

Treat an unexpected reset email, unfamiliar login, or breach notice as a reason to verify—not as a reason to click quickly. Open the provider’s app or type its known address yourself. If you suspect malware or a stolen browser session, use a different, updated device.

Before changing anything, save the provider’s security-alert details and note unfamiliar devices, forwarding rules, recovery methods, and recent account changes. This record can help support teams and makes it easier to distinguish your actions from an attacker’s.

Recovery workflow, in order

  1. Change the email password to a newly generated, unique password. Do not make a variation of the old one.
  2. Use the provider’s “sign out everywhere” or session-management screen. A password change does not always invalidate every existing session.
  3. Review recovery email addresses, phone numbers, app passwords, passkeys, connected apps, delegates, filters, and automatic forwarding. Remove anything you do not recognize.
  4. Turn on phishing-resistant MFA, such as a passkey or hardware security key, when offered. Otherwise use an authenticator app and store the recovery codes offline.
  5. Secure the recovery email account and your mobile-carrier account too. They may be alternate routes back into the inbox.
  6. Change passwords on high-impact accounts that reused the breached password, starting with your password manager, banking, cloud storage, social accounts, and work systems.
Never use a sample password printed in a guide, screenshot, tutorial, or support conversation. Generate a fresh value and save it directly to your password manager.

Watch for the second wave

After a public breach, convincing phishing messages often imitate the affected company. A message knowing your name or old password is not proof that it is genuine. Return to the service through a bookmark or known app, and do not share one-time codes with anyone.

CISA’s account-security guidance recommends strong unique passwords, a password manager, MFA, and recognizing phishing. The exact recovery screens vary by provider, so use the provider’s official help center for account-specific steps.