Recover hacked email: lock it in the first hour, then report to ACSC

Email recovery checklist and cyber reporting steps for a hacked inbox

Article by

PC Scientist

PC Scientist is a professional IT support provider helping homeowners and small businesses across New South Wales. We specialise in computer repair, business IT support, networking, Wi-Fi optimisation, cybersecurity, email support, device setup and security camera solutions.

Our articles are written using practical, real-world experience to help Australians solve technology problems with clear, accurate and easy-to-follow advice. When an issue requires professional assistance, we're here to help with onsite and remote support.

You opened the inbox and something felt off. A password prompt you did not expect. A sent item you did not write. That sick drop in the stomach is the right signal. Do not sit there refreshing. The first hour decides how much damage they get to do.

  • Ask if you can still sign in. If yes, change the password now and turn on multi-factor authentication. Then sign every other session out.
  • Ask if the sign-in is gone. Open the official Google or Microsoft recovery page yourself. Never tap a "reset your account" link that just landed.
  • Ask if this device is clean. If the computer may have malware, use a phone or another machine you trust before you type a new password.
  • Ask who else is at risk. Contacts, banks, and any account that uses this address for resets. Warn people. Report it.

If the mailbox still does not feel safe, Cybersecurity Scientist can take the lock-down from here. Sydney inboxes can start with cybersecurity help across Sydney. Central Coast homes and offices can use cybersecurity help on the Central Coast.

If the first click was a fake invoice or a fake login page, read phishing email examples so the next one is easier to spot.

Key takeaways

If you can still get in, change the password and turn on MFA in the first hour. If you cannot, use the official recovery page and wait. Then strip out recovery phones, forwarding rules, and apps they may have added. Report it in Australia. Call if malware or a business admin account is involved.

Point Details
Still signed in New unique password, MFA on, sign out all other sessions. Do this from a device you trust.
Locked out Official Google or Microsoft recovery only. Answer the ownership questions once. Do not hammer retries.
Hidden back doors Check recovery phone, backup email, filters, forwarding, and connected apps. This is the step people skip.
Clean device If the PC may be infected, do not type the new password on it. Scan it before you use it again.
Australia Report through ReportCyber and Scamwatch. Call police if money or identity theft is involved.

Your first 30 to 60 minutes

Attackers move faster than the shock. They add a recovery phone. They turn on a silent forward. They send a gift-card story to your sister. The order below limits that.

  1. Try a normal sign-in. If it works, change the password immediately.
  2. If it fails, go straight to the provider's official recovery page. Type the address yourself.
  3. Sign out every other session. Google and Microsoft both have a "sign out of all devices" control.
  4. Turn on multi-factor authentication before you read another message.
  5. Do this from a device you trust. Not the one that may have captured the old password.
  6. Ignore any "verify your account" mail that arrives in this window. They send those too.

Pro Tip: Write the new password on paper first. Then put it in a password manager once the panic drops. Trying to invent and remember a strong phrase while you are shaking is how people reuse an old one.

This is not a weekend project. It is one hour of boring, official steps. That hour is worth more than clever workarounds.

If you can still sign in

This is the better seat. You can shut them out yourself instead of waiting on a form. The job is simple. Remove every way they got in, and every way they could walk back in.

Use a long, unique passphrase. Four random words beat a short "clever" password. Store it in a password manager, not in the browser autofill that malware can read.

  • Sign out of all other sessions in the account's device or activity list.
  • Open recovery phone and backup email. Delete anything you do not recognise.
  • Check filters, forwarding rules, and auto-replies for a copy being sent elsewhere.
  • Review connected apps and revoke anything you do not use.

They often add their own recovery details in the first few minutes. That is why a password change alone is not enough. The account looks "fixed" and they stroll back in tomorrow.

Pro Tip: Do the audit even if nothing looks wrong. A forwarding rule that silently copies mail can sit there for months.

Newcastle and Hunter inboxes that need a person on the lock-down can start from cybersecurity help in Newcastle.

If you cannot get in

Losing the sign-in feels worse. It is also where people click the second trap. A "recover your account" link in a fresh email is often the attacker again, not the fix.

  1. Open the official tool yourself. For Gmail, use Google's account recovery steps. For Outlook or a Microsoft account, use Microsoft's recovery process.
  2. Have proof ready: roughly when you created the account, subject lines you remember, devices you used, and any billing tied to it.
  3. Answer every question as honestly as you can. Partial accuracy across a few questions beats one perfect guess.
  4. Submit once. Then wait. Repeated failures can make your own request look suspicious.

The Australian Cyber Security Centre says these official workflows are the right channel. Extra checks can take a few days. That wait is the system working. It is not a sign you have failed.

Checks after you are back in

Getting in is half the job. An account that is recovered but not audited often gets hit again. Treat it like an incident, not a login glitch.

  • Remove third-party apps you do not recognise or no longer use.
  • If this password was reused anywhere else, change those too. One leak becomes five.
  • Re-check the recovery phone and backup email. Prefer an authenticator app or a hardware key over SMS alone.
  • Rotate passwords on banking, cloud storage, and anything that holds a card, because those resets go to this inbox.

Pro Tip: Set a reminder for 30 days. Some attackers wait a few weeks, then test whether their old back door still works.

If this started with a fake login page, keep phishing email examples handy. The next one will look calmer than you expect.

Use a different device if this one feels dirty

Yes. If malware grabbed the old password, typing a new one on the same machine hands it straight back.

  • Use a clean phone, a work laptop, or a machine you have just reset to change the password and submit recovery.
  • Run a full antivirus and anti-malware scan on the affected computer. Install pending updates before you sign into anything important on it again.
  • If you suspect ransomware, or a scan that never stays clean, unplug it from the network and get help before you reconnect it.

This step feels fussy when you just want the inbox back. It is the one that stops a second lock-out tonight.

Who you should tell

Your contacts are next. A hacked address is a trusted messenger. Attackers use that trust.

  • Tell colleagues, family, and suppliers. Ask them to ignore urgent gift-card, invoice, or money requests from this address.
  • Check Sent, Drafts, and Bin for mail you did not write. That tells you who was targeted, so the warning can be specific.
  • The ACSC treats those folder checks as a normal part of working out what happened.
  • If bank details sat in old mail, watch the accounts. A credit check is reasonable if identity details went with them.

How to report a hacked email in Australia

Reporting is not paperwork for its own sake. It helps them spot a pattern, and it can get a spoofed address looked at. Do it even if the damage already feels done.

  • Lodge the incident through ReportCyber and Scamwatch. Note what happened. Keep copies of the odd messages.
  • If your address is being used to spoof others, send an abuse report to the provider as well.
  • Contact police if there is financial loss, identity theft, or a threat. Keep the logs. Do not tidy the evidence away first.

The ACSC recovery page for a compromised email is the same family of advice as the Google and Microsoft tools. Official pages only. No "helper" sites from a search ad.

When to call for help

Some of this is a form and a checklist. Some of it is not. Malware that comes back after a scan, suspected ransomware, or a Microsoft 365 mailbox compromised at the admin level can chew a weekend and still not be clean.

Write down what you noticed, when you noticed it, and which devices were involved. That short list speeds the next step. Remote help covers a lot of inbox lock-downs in a day. Onsite help earns its keep when the computer itself is the problem.

PC Scientist can lock the inbox with you

If you would rather not sort a compromised inbox on your own, that is a fair choice. Cybersecurity Scientist covers the clean-up: sign-in, odd forwarding rules, malware on the device, and the mailbox underneath. Remote first if photos and a timeline are enough. Onsite if the computer itself is the hole.

Tell us whether you can still sign in, which provider it is, and whether a work Microsoft 365 admin account is involved. We will say what you can finish tonight, and what needs a person. Call 0493 563 381, or pick your area below.

PC Scientist

Sources

These pages help when you want the official steps, not a random forum:

Help centre

Frequently Asked Questions

Straight answers about a hacked email - without jargon or pressure. Call 0493 563 381 for advice, or get help below.

Want the quickest answer? 0493 563 381 for free advice.

Yes. Most people get back in with the provider's official recovery page. It can take a few days if Google or Microsoft wants extra checks. Stay on that page. Do not use a link from a new email.

If you can still sign in, change the password now and turn on MFA. Sign out every other session. If you cannot sign in, open the official Google or Microsoft recovery page yourself and prove you own the account.

Someone can read your mail, reset passwords on linked accounts, and send scams that look like you. They often add their own recovery phone or a silent forwarding rule so they can walk back in later.

Start with Google or Microsoft recovery. Then report it through ReportCyber and Scamwatch. Call 0493 563 381 if malware keeps coming back, you suspect ransomware, or a business Microsoft 365 admin account is involved.

Yes. A short ReportCyber note helps them track the scam pattern. Add Scamwatch if money or a fake invoice was involved. Keep copies of the odd messages rather than deleting everything first.

Cybersecurity across NSW

If the inbox still does not feel safe, that is okay. Get help in your area and we will take it from here.

Cybersecurity statewide

Start here

Get cybersecurity help

Optional Need a Sydney city or region?

Choose a side of Sydney

These are Sydney cities and regions, such as the Northern Beaches or Inner West. First tap a side of Sydney. Then open the city or region that covers you.

C Sydney City / Inner 3 areas
N Northern Sydney 6 areas
NW North-West / Central Sydney 3 areas
W Western Sydney 1 area
SW South-West Sydney 3 areas
S Southern Sydney 2 areas
Optional Find your suburb

Type a suburb from our listed coverage. This opens the matching city or region page for this topic. Listed suburb pages are general technology services, not this specialist page.

If your suburb is not listed, use the city or region list above, or call 0493 563 381.

    Need help with your setup? Call or text PC Scientist on 0493 563 381 for initial advice, request a callback at a suitable time, get a quote or book online to receive the advertised online-booking discount where applicable.

    Disclaimer

    The information in this article is provided for general educational and informational purposes only. While PC Scientist strives to keep all content accurate and up to date, technology issues can vary depending on your device, software, network configuration, and individual circumstances. Always back up important data before attempting repairs or system changes. If you are unsure or the issue cannot be resolved safely, contact PC Scientist today for professional onsite or remote IT support. PC Scientist is not liable for any loss of data, damage, or other issues resulting from the use of the information provided in this article.

    shape
    shape
    Need help now? Not sure what to click or what to do next?

    Talk to PC Scientist for free advice, calm and practical IT help