Step-by-step method
A reproducible path from question to conclusion.
- 1
Assess the signs
Distinguish an attempted sign-in alert from successful access. Record unrequested changes, sent messages, new devices and observed operations. An unusual location alone may reflect a VPN or imprecision.
- 2
Regain control
Open the official website directly from a trusted device. Use its hacked-account or recovery process. For a managed account, involve the administrator. Avoid links and numbers supplied by a supposed recovery agent.
- 3
Close unnecessary access
Follow the provider’s settings to change the password, remove unknown devices and revoke sessions. Check recovery email and phone, forwarding rules and authorised applications.
- 4
Protect dependencies
List accounts whose reset depends on this mailbox. Prioritise payments, administrative accounts and sensitive storage. Warn affected contacts if fraudulent requests were sent.
- 5
Check stabilisation
Record actions, reviewed access and new events. Recurrence, a suspect device or changed privileges calls for technical investigation.
Sessions, delegation and applications need separate checks
An open session, a forwarding rule and an authorised application are different forms of access. Settings and reset effects vary by service. Do not assume one action covers everything: consult documentation and record the checks actually completed.
For business email, ask the administrator to review delegation, rules, logs and permission changes. Coordinate before modifying organisational settings or evidence.
Choose protection and plan its recovery
CISA distinguishes MFA methods and recommends phishing-resistant FIDO/WebAuthn options where available. The choice should account for the provider, devices and a legitimate recovery path.
Document an appropriate backup method and protect recovery codes outside the mailbox being secured. Test the process with the account owner. Never disclose a temporary code to someone who contacts you.
Close the incident using observable criteria
Closure means access has been reviewed, identified consequences addressed and known limitations accepted by an owner. It does not establish that all data was unaffected.
A short file can record the known start, last signs, actions, preserved logs, notified recipients and next review. If personal data is involved, have the responsible functions assess applicable duties.
Common pitfalls
Four shortcuts that weaken the result.
Resetting then forgetting
Also check sessions and delegated access.
Paying for guaranteed recovery
Use official support rather than an unverified intermediary.
Deleting alerts
Keep the traces needed for the case.
Returning through a suspect device
Seek technical assessment if the device may be compromised.
Practical questions
Frequently asked questions.
Is the password enough?
No. Review the service’s access mechanisms, including sessions, recovery channels and authorised applications.
What if recovery fails?
Follow the provider’s official pathway and keep case references. Contact the administrator for an organisational account.
Does MFA prevent every incident?
No. Protection depends on method and context. It does not replace session review or device and support security.
Public references
Cybermalveillance.gouv.fr — account compromise. French response guidance for recovery and protection.
CISA — More than a Password. MFA methods and phishing resistance.
Editorial scope
Published by Internet Intelligence Service on 3 October 2026. Last content update: 3 October 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.
