What To Do If a Scammer Has Your Email Address

Updated:
Learn what to do if a scammer has your email, from immediate recovery steps to how IT teams contain enterprise-wide fallout.

If a scammer has access to your email, act immediately: Change your email password from a clean device, turn on 2-factor authentication (2FA), scan for malware, alert your contacts, and check whether your credentials appear on the dark web.

As cybercrime and phishing tactics grow more advanced, there's always the chance a scammer could get access to your email address and create a dangerous cybersecurity situation that you need to respond to immediately.

How to tell if your email has been hacked

What can a scammer do with your email? Stolen credentials allow a scammer to send malicious messages or malware links to your contacts, extract personal or financial information from your saved messages, or get your friends and family to send money to them under false pretenses. 

Here are some telltale signs that your email account has been hacked:

  • You can’t log in. One of the first things a scammer might do if they access your email account is change your password. If you’re certain you’re entering the correct username and password for your account and still can’t log in, this could be a red flag.

  • Your account is sending emails you didn’t write. It can be a rude awakening when a friend or family member asks you if you sent them an email that doesn’t sound familiar. Is this email a scammer? If you hear your email account is suddenly delivering mysterious links or spam messages, it could be compromised.

  • Your folders have been emptied or modified. Your email provider will not delete, move, or reorganize saved files or messages. If you notice any changes in your file structure and you do not share the email account password with anyone, you may have been visited by a scammer.

  • Your device is behaving strangely. A compromised email account alone won’t cause your computer or device to slow down or behave strangely. However, a hacker may have already installed malware on your device to get access to your email account, which could account for the drop-off in performance.

  • You receive a security alert. Employers, internet service providers, and cybersecurity apps will often provide you with a security alert if your account information is compromised. These alerts should always be taken seriously, and you should change your password right away if you have been impacted by a data breach.

  • Your information appears on the dark web. Despite being vigilant, you may not always realize when your email account has been compromised. Dark web monitoring is a valuable tool that scans the hidden recesses of the internet for your personal information and credentials. For example, Dashlane’s Dark Web Monitoring immediately alerts users if their password(s) or account information are detected and need to be changed.

What to do if a scammer has access to your email

When your email account is compromised, it means a scammer has access to your account. They could already be sending fraudulent messages or malware links to your contacts. Notify as many of your contacts as possible using an alternate email address or by texting or calling.

After you've contained the immediate threat, follow these tips to thwart the scammer and minimize their impact.

1. Change your email password and security questions

Changing passwords at predefined time intervals is no longer considered a best practice. In fact, the NIST discourages these periodic resets, since minor changes to existing passwords have little value and are easily guessed by hackers.

However, if your email account has been compromised, you need to change your password and security questions immediately. Do this from a device you trust, and make the new password strong and unique with a Password Generator. Then, turn on 2FA so a stolen password alone is no longer enough to get back in.

2. Scan your device for malware

Any changes you make to your account are of little value if your device has been infected by malware. If you don't already have antivirus or anti-malware software installed, now's the time to download it.

Run a complete system scan as soon as possible to isolate and remove any infected files.

3. Ignore them if they reach out to you

One of the worst ways to react to a scammer is by engaging them in their scam. They may try to contact you, even using your own email address, but responding to them will not stop or discourage their behavior.

Instead, any response will simply confirm another "live" contact to exploit. Be sure to mark any emails from the scammer as spam.

4. Report the scammer

Scammers hiding out in cyberspace and changing their location frequently can be difficult to track, but they should be reported anyway.

Search online for the appropriate organization in your country to report the scammer to. If you're in the U.S., report the incident at IdentityTheft.gov, the Federal Trade Commission's (FTC's) official recovery site, which helps you build a recovery plan, deactivate affected accounts, and set up credit monitoring.

5. Create a new email address

To be completely safe, you can follow the steps above, then start fresh with a brand new email address. Since the average person in the U.S. has 100-150 accounts linked to their email address, you will also need to locate and update all of these connected accounts.

How to prevent scammers from accessing your email

As the saying goes, an ounce of prevention is worth a pound of cure. The best way to manage a hacked email account is by preventing it from being hacked in the first place. These additional tips and tricks will help keep you safe from future email breaches.

Use 2-factor or multifactor authentication

2-factor authentication (2FA) makes your email account more secure by requesting a second identifier, such as a unique code sent through an app or text message. This might add a few seconds to your login time, but it will make it nearly impossible for a scammer to access your account without having your device. Multi-factor authentication (MFA) uses two or more identifiers, sometimes including biometric factors like fingerprints or facial recognition. 

Check your backup contact method

Most of us don’t think about or update our recovery email address or backup contact method often, if at all. Make sure the email address and phone number you provide are active and up to date. These backup methods become important when you're locked out of your account and need to reset your password or receive security alerts.

Be on the alert for phishing attacks

How are emails hacked? A phishing attack, often in the form of an unsolicited email, is a social engineering tactic used to trick recipients into sharing account information or passwords. Some also include links to spyware or keyloggers that intercept private communications. Poor grammar, spelling errors, and URLs that do not match the company website can be signs of a phishing attack, but these signs are not always present. Phishing and social engineering tactics are growing ever more advanced with AI. Fortunately, real-time phishing alerts can help.

Use a password manager

A password manager protects all your important accounts by encrypting passwords and account information and storing your information in a secure vault. This can help thwart hacking tactics—like credential stuffing, brute-force attacks, and phishing—that prey on weak email passwords. A password manager also allows you to store, share, and update all your passwords from one secure app.

Why employee email compromise is a high-severity enterprise event

Most employees think of a compromised email account as a personal problem: An inconvenience they need to resolve with their email provider. For the security team, it's the beginning of a potential enterprise-wide incident. Here's why:

  • Email is the universal recovery mechanism. When an employee registers for any online service, their email address is almost always the password reset fallback. An attacker who controls the employee's inbox can trigger a “forgot password” reset on every service that employee has ever registered with, including corporate SaaS tools, cloud infrastructure, VPN portals, and SSO-connected apps. They don't need the employee's original password; they just need the inbox.

  • Compromised personal email can cascade into corporate SSO. If the employee used their personal email address as the backup or recovery contact for their corporate Google Workspace or Microsoft 365 account (a common configuration, especially in organizations that haven't locked down recovery settings), an attacker with the personal inbox can trigger a corporate password reset. From there, SSO access follows. Once the attacker has the corporate email account, they have access to everything that account is authorized to unlock.

  • MFA codes sent to email are interceptable. Many organizations use email-based MFA as a fallback for employees who don't have an authenticator app enrolled. If the attacker controls the employee's inbox, they can intercept those codes in real time. Email-based MFA is not a protection against an attacker who already has email access. It's just an additional avenue of exploitation.

  • Internal impersonation is immediately available. With access to a corporate or personal email account that receives work correspondence, an attacker can impersonate the employee convincingly. Business email compromise attacks frequently begin exactly this way: The attacker monitors the inbox for context, identifies a pending transaction or internal approval process, and inserts themselves at the right moment. Wire transfer fraud, vendor payment redirection, and HR data requests are all common BEC attack patterns that begin with a single compromised inbox.

  • The attack window is longer than IT teams expect. Employees often don't notice their email has been compromised for days or weeks. In that window, the attacker has time to inventory the inbox, identify high-value targets, trigger password resets on connected accounts, and exfiltrate sensitive correspondence, all before IT is even aware of the incident.

The reactive response: What IT teams should do when an employee reports a compromised email

A compromised employee email account is rarely contained to one inbox. Email is the recovery mechanism for dozens of workplace accounts, so an attacker with inbox access can reset passwords across your SaaS stack, impersonate the employee internally, and launch convincing phishing from a trusted address.

But the risk runs deeper than most IT teams initially realize. Email compromise is frequently the first step in a business email compromise (BEC) or SSO takeover chain that can move from one employee's personal inbox to admin access across the organization.

Understanding the escalation path is the foundation of an effective response.

  1. Close the reuse gap. If the employee reused their email password anywhere else, every one of those accounts is exposed. A business password manager with enforced password policies makes unique credentials the default, and Credential Risk Detection surfaces compromised employee credentials even before everyone is onboarded to Dashlane.

  1. Reset and revoke first. Force a password reset, revoke active sessions and OAuth grants on the compromised account, and require re-authentication on connected apps.

  1. Check the blast radius. Review the account's sent mail and password-reset emails to see which connected services the attacker may have touched. Dark Web Insights shows admins which employee credentials have appeared in breaches, so you can prioritize resets.

  1.  Warn the organization. Alert employees that mail from the affected address may be malicious. AI phishing alerts add a real-time safety net if anyone clicks through to a credential-harvesting page.

Mapping the blast radius: A full audit checklist

Step 3 above, “check the blast radius,” is the most time-intensive and most frequently underestimated part of the response. Below is the full audit scope that a security team should work through for any confirmed employee email compromise.

Email account itself:

  • All active sessions (web, mobile, desktop clients): Revoke all
  • All connected third-party apps with OAuth access to the inbox: Review and revoke any not recognized
  • Email forwarding rules: Attackers frequently set silent forwarding rules to maintain access after a password reset
  • Filters and auto-delete rules: Attackers may create rules to delete security alerts automatically so the employee doesn't see them
  • Recovery email address and phone number: Confirm these haven't been changed to attacker-controlled contact info

Connected accounts (triggered via email recovery):

  • All SaaS tools registered with the compromised email address
  • Corporate email (if personal email was the recovery contact)
  • SSO-connected apps: Audit the SSO provider's session logs for the affected account
  • Cloud storage accounts (Dropbox, Google Drive, OneDrive): Check for unusual access or file exfiltration
  • Financial and HR platforms if the employee had access

Communication channels the attacker may have used:

  • Sent mail: what did the attacker send from the compromised address during the exposure window?
  • Password reset confirmation emails: which accounts were reset during the exposure window?
  • Internal calendar: were any meetings accessed, modified, or used for social engineering context?
  • Any ongoing threads involving wire transfers, vendor payments, or sensitive approvals

Organization-wide impact:

  • Which colleagues received mail from the compromised address during the exposure window? Alert each one individually, not just the organization broadly.
  • Were any external parties (clients, vendors, partners) contacted from the compromised address? They need direct notification.
  • Has the attacker attempted to use the compromised email to access any corporate system for which you have login logs?

Dashlane's Dark Web Insights accelerates the prioritization layer of this audit. It shows which employee credentials have already appeared in breach data, so the security team can focus reset efforts on the accounts most likely to have been compromised during the exposure window rather than working through the entire list sequentially.

Before an email is compromised: Proactive controls for IT teams

The reactive response above addresses what to do after an employee's email is compromised. The more valuable question for an IT or security team is what to put in place so that a compromised email account can't cascade into a corporate-wide incident.

  • Eliminate email as an MFA channel for corporate accounts. Email-based MFA codes are interceptable by any attacker who has inbox access. Replace email-based MFA with authenticator apps (TOTP) or phishing-resistant methods (passkeys, hardware security keys) for all corporate account logins. If the attacker gets the email account, they shouldn't automatically get the MFA codes for corporate systems.

  • Remove personal email as the recovery contact for corporate accounts. Audit corporate Google Workspace, Microsoft 365, and SSO provider accounts to confirm that no employee has a personal email address set as a recovery or backup contact. This single configuration change prevents personal email compromise from cascading into corporate SSO takeover.

  • Deploy dark web monitoring. A compromised employee email credential almost always surfaces in dark web breach data before BEC attempts begin. Dark web monitoring watches for credentials associated with email addresses across breach databases continuously, sending alerts when an employee email credential is exposed, before an attacker uses it.

  • Surface at-risk email credentials proactively. Credential Risk Detection in Dashlane identifies weak and compromised email credentials entered in the browser, including for employees who haven't yet created a Dashlane account, giving the security team a prioritized view of which accounts are most likely to be compromised next, not just which have been compromised already. Password Health extends this same prioritization to reused credentials among enrolled employees. Acting on this signal before an incident occurs is the difference between proactive and reactive credential security.

  • Enforce phishing-resistant authentication at the email layer. Since email compromise most commonly begins with phishing, either a phishing email that captures the email password or a credential-harvesting page disguised as a legitimate email login, real-time phishing protection at the credential entry point closes the most common attack vector. Dashlane's AI Phishing Alerts analyze pages at the moment of a credential request and alert employees before they enter their email password on a malicious site.

  • Include email credential rotation in offboarding procedures. When an employee leaves the organization, their corporate email account is typically deprovisioned. But if that employee had connected personal accounts to corporate SSO or if corporate systems were set up to use their personal email as a recovery contact, those connections persist after offboarding and represent continued access risk. Dashlane's admin console enables security teams to confirm credential revocation across connected accounts as part of the offboarding workflow.

How Dashlane protects your email from scammers

Dashlane provides seamless password generation that helps keep all your credentials strong, unique, and safe from scammers. A secure vault safely encrypts and protects your passwords, and zero-knowledge architecture ensures no one but you—not even Dashlane—can decrypt your vault.

For individuals

Dashlane's AI-powered Scam Protection goes beyond the traditional autofill-based phishing alerts most password managers offer. Instead of only intervening when you try to fill a saved login, Scam Protection analyzes the page you're on in real time, checking dozens of signals like URL anomalies and hidden page elements, so it can flag a fake login page, fraudulent checkout, or scam job application, even before you've saved a password there to compare against. It runs on-device and is on by default for Premium and Friends & Family plans.

Our Dark Web Monitoring also scans the depths of the internet for your credentials, including up to five email addresses, and alerts you if your passwords or account information are detected and need to be changed.

For businesses

Employee email compromise rarely stays contained to one inbox, which is why the Dashlane Omnix® platform is built to catch it early and respond fast. Credential Risk Detection and Dark Web Insights surface at-risk and breached employee credentials before an attacker uses them, and AI Phishing Alerts intervene the moment an employee is about to enter a password on a suspicious site.

In addition, the new Omnix AI Advisor lets security teams query all of that credential risk data in plain language—asking things like "who are my riskiest users right now?"—to prioritize response during exactly the kind of exposure window described above.

FAQs: scammers and your email

What can a scammer do with just my email address?

With only your email address (no password), a scammer can send you phishing messages, attempt to impersonate you, and try credential-stuffing attacks using passwords leaked in other breaches. The address alone doesn't grant account access, but it's the starting point for attacks that do, which is why unique passwords and 2FA matter.

How do I secure my email after a breach?

Change your email password immediately from a clean device, turn on 2-factor authentication, review your account's recovery settings and connected apps for anything you don't recognize, scan your devices for malware, and update the password on any account where you reused the old one.

Can a scammer access my other accounts through my email?

Yes. Email is the recovery address for most online accounts, so an attacker with inbox access can trigger password resets on your banking, shopping, and work accounts. That's why securing the email account itself is the first priority after any compromise.

Should my company do anything if my work email is hacked?

Yes. Report it to your IT department right away. A compromised work email can be used to phish coworkers and reset passwords on company systems, so IT needs to revoke sessions, check connected accounts, and warn the organization. Fast reporting shrinks the damage.

What are the biggest credential security risks facing enterprises?

Business email compromise (BEC) remains one of the highest-value attack patterns, and it almost always begins with a compromised email account. Email is the recovery mechanism for corporate accounts, so an attacker who gains inbox access can pivot into SSO, SaaS apps, and corporate systems without needing any further credentials. The upstream risk is the compromised email credential itself, which frequently surfaces in dark web breach data before BEC attempts begin. That's why dark web monitoring is one of the most effective early-warning tools available to enterprise security teams.

How can enterprises protect against credential-based breaches before they happen?

The highest-leverage preventive controls for email-based credential risk are: Eliminating email as an MFA channel for corporate accounts (so inbox access doesn't also mean MFA code access), removing personal email as a recovery contact for corporate accounts (so personal email compromise can't cascade into corporate SSO), deploying dark web monitoring (to detect compromised email credentials at the earliest available signal), and enforcing phishing-resistant authentication at the email login layer (to prevent the phishing attack that most commonly initiates email account compromise).

What tools protect employees from phishing attacks in real time?

Real-time phishing protection operates at the credential entry point, the moment an employee is about to enter their password on a potentially malicious site. Dashlane's AI Phishing Alerts analyze the page in under one second and alert the employee if the site looks suspicious, regardless of whether the phishing link arrived through email, SMS, or a compromised website. This protection works even when the phishing page is convincingly identical to the real login page because the analysis happens the moment an employee visits the site, rather than relying on a known-bad URL list.

How do security teams remediate compromised credentials at scale?

Effective remediation for a compromised email credential requires four parallel actions: Forcing a password reset on the compromised email account, revoking all active sessions and OAuth grants connected to that account, auditing the sent mail and password-reset history during the exposure window to identify which connected accounts were touched, and alerting colleagues who received mail from the compromised address during the exposure window. Dashlane's Dark Web Insights and Credential Risk Detection accelerate this workflow by providing the security team with a prioritized view of which accounts are most at risk, so remediation efforts are directed at the highest-severity exposure first.

Should IT teams treat personal email compromise the same as corporate email compromise?

Yes, when the employee's personal email is connected to corporate systems in any way, including as a recovery contact, as an alternate login method, or as the email address used to register for corporate SaaS tools. Personal email compromise that has no connection to corporate systems is an employee personal matter. Personal email compromise where the inbox is connected to corporate account recovery, corporate SSO, or corporate SaaS registrations is a corporate security event that requires the same response as a compromised corporate email account.

Sign up to receive news and updates about Dashlane