What to do if your email account has been compromised

An email account can become the control centre for your digital life. It may contain private conversations, invoices, travel details and password-reset links for banking, shopping, social media and other services. If someone has accessed it, quick action can limit the damage and prevent the intruder from locking you out.

A compromised account does not always show obvious signs. You might notice unfamiliar sent messages, changed settings, unexpected login alerts or password-reset emails you did not request. Sometimes the first warning comes from a friend in Sydney, Melbourne or Brisbane who received a suspicious message from your address.

Recognise the warning signs

Look for activity that does not match your normal habits. Check the sent, deleted and archived folders for messages you did not write. Review login history for unfamiliar devices, locations or browsers, keeping in mind that mobile networks and virtual private networks can make locations appear imprecise.

Other clues include a changed recovery phone number, missing emails, new forwarding rules, unfamiliar email signatures and notifications about password changes. A sudden increase in spam can also indicate that your address has been added to a mailing list or exposed in a data breach.

Do not click links in unexpected security alerts. Open the provider’s official app or type its address into your browser yourself. This is especially important when browsing entertainment or betting-related pages: for example, a page such as a casino mirror site should never be used as a reason to enter your email password or approve an unfamiliar login.

Contain the account quickly

Use a trusted device that is free from suspicious software. Change the email password immediately, making it long, unique and unrelated to names, teams, pets or Australian postcodes. If you cannot sign in, use the provider’s account-recovery process rather than relying on links in messages.

Sign out of all other sessions after changing the password. This step matters because an attacker may still have an active browser session even after the old password stops working. Remove unknown devices, app passwords and connected applications, then confirm that your recovery email and phone number belong to you.

Turn on multifactor authentication, preferably with an authenticator app or security key. SMS verification is better than no second factor, though it can be exposed through phone-number theft or SIM-swap fraud. Save recovery codes somewhere secure and offline rather than inside the affected mailbox.

Check what the intruder changed

Attackers often try to stay hidden by creating rules that automatically forward messages, move security alerts to a low-visibility folder or delete replies from banks and retailers. Review forwarding addresses, filters, blocked senders, delegated access and automatic replies. Remove anything you did not create.

Search the mailbox for terms such as “password,” “verification,” “invoice,” “bank,” “tax,” “Medicare” and “identity.” This can reveal which accounts may have been targeted. Examine recent emails for fake payment instructions or messages asking contacts to send money.

Tell regular contacts that your account was accessed and that recent unusual messages should be ignored. If a work or university mailbox is involved, contact the organisation’s IT or security team immediately. They may need to revoke sessions, inspect logs and warn other people before the same phishing campaign spreads.

Match the response to the damage

The right next step depends on what evidence you find. An ordinary password reset is different from an account that has been used to access financial records or impersonate you. The following guide provides a practical starting point.

Situation Immediate action Follow-up
Suspicious login but no changes Change the password and sign out everywhere Enable multifactor authentication and monitor alerts
Forwarding rules or unknown apps Remove rules, access permissions and app passwords Search for exposed personal or financial information
Banking or payment details viewed Contact the bank using its official number Freeze cards, replace credentials and review transactions
Messages sent to contacts Warn recipients and preserve copies Scan devices and report phishing or impersonation
You cannot recover the mailbox Use the provider’s official recovery process Secure linked accounts and consider identity protection

Keep screenshots, timestamps, alert emails and copies of suspicious messages. Do not delete evidence before checking whether your bank, employer, insurer or a government reporting service may need it.

Protect accounts connected to email

Change passwords on every important account that reused the compromised password or used the email address for recovery. Start with banking, superannuation, government services, shopping accounts, cloud storage and social media. Use a password manager to generate different credentials and store them securely.

Review recent activity on financial accounts and contact your bank through the number printed on your card or shown in its official app. Australian banks can place extra monitoring on an account, cancel cards or help investigate unauthorised transactions. Act quickly, since delay can complicate recovery.

Be careful with messages that exploit current events or everyday Australian routines, such as parcel deliveries, energy bills, tax notices or requests related to a local football club. A suspicious link presented beside legitimate-looking content, including a horse racing betting app review, still deserves the same scrutiny as any other unfamiliar link.

Report identity and financial risks in Australia

If money has been lost or you suspect a scam, contact your bank first, then report the matter to ReportCyber or Scamwatch as appropriate. Scamwatch helps Australians report scams and understand common fraud patterns, while ReportCyber is used for cybercrime reporting. These reports may support broader investigations even when recovery is uncertain.

For identity theft concerns, contact IDCARE and consider checking your credit files with Australian credit reporting bodies. If personal information held by an organisation was exposed, the Australian Privacy Act and Notifiable Data Breaches scheme may be relevant. The organisation responsible for the breach should explain what happened and what protective measures are available.

If the mailbox is used for work, notify your employer because the incident may involve customer or staff information. If it contains health, education or government records, make the relevant provider aware. Keep a written timeline with Australian Eastern, Central or Western time noted clearly when communicating across states or with overseas support teams.

Build a safer recovery routine

Once the immediate problem is contained, make account security part of ordinary digital housekeeping. Review recovery options every few months, install updates on phones and laptops, and remove apps you no longer use. Avoid checking sensitive accounts over open public Wi-Fi in cafés, airports or hotel lobbies unless the connection is trusted and the device is protected.

A simple routine can reduce the chance of another takeover:

A simple informational page such as Casinotest3’s main site may be useful for general navigation, but no website should receive your mailbox password or authentication code. Treat every page as a separate security boundary, even when its design, branding or buttons appear familiar.

The key point is to regain control first, investigate what was exposed second and protect every connected account afterwards. A changed password helps, but a complete response also removes hidden access, checks financial and identity risks, warns affected people and preserves useful evidence.