Email Account Hacked? Stop the Spam Now

Cybersecurity & Malware Beginner 👁 9 views 📅 Jun 25, 2026

Your account is sending spam because it got compromised. Change your password and review forwarding rules. Here's how to fix it fast.

Quick Answer: Change Your Password & Kill All Sessions

If your account is sending spam, the attacker still has access. Change your password immediately, log out all other sessions, and check for auto-forwarding rules. Then turn on two-factor authentication.

Why This Happens

Hackers get into email accounts using stolen passwords from data breaches or phishing. They don't need your login to send spam — they just keep a session token alive. The spam usually looks like a fake invoice, a weird link, or a sob story asking for money. Your contacts get it, and you look like a jerk. The real fix is making sure they can't get back in.

This is way more common than you think. I've seen it happen to Gmail, Outlook, Yahoo, and corporate Exchange accounts. The culprit is almost always a reused password or a phishing link you clicked once.

How to Fix It – Step by Step

  1. Change your password immediately. Use a long, random one — 16 characters minimum. Don't reuse any password you've used before. Use a password manager if you have to.
  2. Sign out of all sessions. Every email provider has a way to force-logout all devices. In Gmail, it's in Settings > Accounts > Sign out all other web sessions. Outlook lets you do it under Security & Privacy. Do this after changing the password.
  3. Check email forwarding rules. Hackers often set up rules to forward your emails to them. In Gmail, check Settings > Forwarding and POP/IMAP. In Outlook, go to Rules > Manage Rules & Alerts. Delete any rule you didn't create.
  4. Revoke app-specific passwords and third-party access. Go to your account's connected apps or authorized apps section. Remove anything you don't recognize. This kills any sneaky API access the hacker set up.
  5. Turn on two-factor authentication (2FA). Use an authenticator app (Google Authenticator, Microsoft Authenticator). SMS is better than nothing, but app-based is way more secure.

If the Main Fix Doesn't Work

Sometimes the spam keeps going even after you changed the password. This usually means the attacker set up something you missed, or they're using a backdoor.

Check for Mail Forwarding on Multiple Levels

Some hackers set up forwarding at the server level or through IMAP/SMTP settings. If you use Outlook, check for any ForwardTo rules in the Exchange admin panel. Gmail users should check Settings > Filters and Blocked Addresses — sometimes they hide a filter that forwards emails.

Run a Full Malware Scan

Keyloggers or info-stealers on your computer can grab your new password. Run a full scan with Malwarebytes or Windows Defender Offline. Also check your browser extensions — malicious ones can hijack sessions.

Contact Your Email Provider's Support

For Gmail, use their hacked account recovery tool. For Outlook, use the compromised account recovery form. They can roll back changes the hacker made that you can't see. This is a last resort but it works.

Prevention Tips for Next Time

  • Use a unique password for every account. Password managers make this easy. Don't reuse your email password anywhere.
  • Turn on 2FA now, before you get hacked. It blocks 99% of automated attacks. I've never seen an account with 2FA get hacked this way.
  • Don't click links in emails you weren't expecting. Ransomware and phishing start with one click. If it looks weird, delete it.
  • Check your account activity regularly. Gmail shows recent logins at the bottom of the page. Outlook has a sign-in activity log. If you see a login from Russia, change your password immediately.

This fix works for Gmail, Outlook.com, Yahoo, iCloud, and most corporate Exchange accounts. The steps are the same — change password, kill sessions, check forwarding, and turn on 2FA. Do it now, before your mom clicks that fake invoice you sent her.

Was this solution helpful?