← Security Awareness Hub Protect my accounts

Email Account Compromise

Your email is the master key. Whoever controls it can reset everything else.

Every "forgot password" link in your life lands in your inbox. That makes your email account the single most valuable thing an attacker can take — and the first thing you must lock down, before any other account. This is why it gets its own page instead of being lumped in with identity theft.

TL;DR
  • Email is the single point of failure — it can reset your bank, your socials, your shopping, everything.
  • Protect it harder than anything else: unique password + 2FA (app or hardware key, not SMS).
  • The warning signs of takeover are subtle: missing emails, password-reset notices you didn't request, contacts getting spam "from you."
  • If it's compromised, act in a strict order (below) or you'll lock yourself out while the attacker stays in.

Why email is the keystone

Think about what's reachable through your inbox. Password resets for your bank, your government login, your social accounts, your cloud storage with every photo and document. An attacker who owns your email doesn't need to hack any of those individually — they just request a reset and catch it in the inbox they now control. Securing email isn't one of your defences; it's the one that protects all the others.

What to actually do (prevention)

  1. Unique, long password used nowhere else. A password manager makes this painless.
  2. Turn on 2FA — prefer an authenticator app or a hardware key over SMS (SMS can be SIM-swapped; see that page).
  3. Set and verify recovery options — a recovery phone and a recovery email you actually control.
  4. Review connected apps periodically and remove ones you don't recognise.
  5. Check "recent activity / devices" now and then; sign out anything unfamiliar.

Signs your email is compromised

  • Password-reset or "new sign-in" notices you didn't trigger.
  • Emails disappearing, or a filter you didn't create silently deleting/forwarding mail (attackers hide their tracks this way).
  • Contacts say they got spam or odd requests "from you."
  • Sent items you didn't send; settings changed.

If it's already happened — in this order

  1. From a clean device, change the email password. If you can still log in, do it now.
  2. Check for malicious forwarding/filter rules and delete them — this is the step people miss, and it's how attackers keep reading your mail after you change the password.
  3. Sign out all other sessions/devices in the account's security settings.
  4. Re-secure 2FA and recovery options (attacker may have added their own).
  5. Then work outward: reset the most sensitive linked accounts (bank, gov, cloud) since those resets flow through email.
  6. Warn your contacts if spam went out in your name.

🇱🇺 In Luxembourg

  • Phishing that led to the compromise → report to SPAMBEE (spambee.lu) and the URL to CIRCL.
  • If financial accounts were reached through the inbox → call your bank, file a plainte (Police Grand-Ducale).
  • Want to talk it through with a human → BEE SECURE Helpline.
Email is also where most business compromise (BEC) starts. If this is a work account or you're a founder, the exposure is bigger than one inbox — johlem.net.