Grahak Mitra

Your email is compromised: what to do first, in the right order (India)

Last updated: 2026-07-11

Your email is the master key: it can reset the password on almost every other account you own — bank, UPI, social media — so if it is compromised, secure the email FIRST, and in the right order. From a trusted device, regain access and change the password; then, before anything else, remove any changes the attacker made to keep getting back in.

Changing only the password is not enough. An attacker who set up mail forwarding, a hidden filter, or a new recovery email or phone can still read your mail and reset your password again even after you change it. The order below is what closes those doors — follow it as written.

Secure your email, in this order

Do these in sequence, from a different, trusted device — not one you think the attacker may still control. The order is load-bearing: each step assumes the ones above it are done.

  1. From a trusted device, regain access and change the password. Use your email provider's own account-recovery flow to get back in, and set a new, unique password. Do this from a device you trust.
  2. Remove the attacker's ways back in — do this immediately, before you relax. Check for and undo anything they set up: mail forwarding rules sending copies of your mail elsewhere; filters that hide, archive, or delete alerts and security warnings; a changed recovery email or phone number; and connected apps or app-passwords they authorised. A password change does not remove any of these — this step is what actually locks them out.
  3. Turn on two-factor authentication. Switch on two-factor (two-step) sign-in so your password alone can no longer let anyone in.
  4. Sign out all other sessions. Use the "sign out of all other sessions / devices" option so any device the attacker is still logged in on is kicked out.
  5. Then check the accounts that use this email. Now that the email is secure, check the accounts it can reset — bank, UPI, social media, shopping — for misuse or password-reset emails you did not request, and reset those passwords too. Turn on two-factor on the important ones.

Only after the email is locked down should you move on to the other accounts — because until it is, the attacker can undo your work through it. Recovery is possible but not guaranteed; the sooner you act, the less an attacker can do with the master key.

Why the order matters

Think of your email as the spare key to your house that also opens every neighbour's door. If a stranger copied it, changing your own lock (the password) helps — but if they also propped a window open (forwarding), left a copy with a friend (a new recovery contact), or set a note to intercept your post (a filter), they still get in. You have to close every one of those, which is why step 2 comes before you consider yourself safe.

Report and check for money lost

File a complaint at cybercrime.gov.in. If the compromise led to any money leaving a bank or UPI account, also call 1930, the national cyber-crime helpline, and note the reference and acknowledgement numbers. If money moved, the first-hour money steps are here: UPI fraud — what to do in the first hour. If your phone lost signal and you cannot get a code, your SIM may have been swapped — see SIM swap fraud: signs and what to do.

Beware a second scam: never pay a "recovery agent", "ethical hacker", or "hacker-for-hire" who promises to get your email back for a fee — that is a fresh fraud. The only real routes are your email provider's own account-recovery flow and, to report, cybercrime.gov.in and 1930. Do every step above from a different, trusted device if you think the attacker still had access to yours.

If you still can't secure it

Keep every complaint acknowledgement number. If your provider's recovery flow does not restore control, keep trying it, and use the National Consumer Helpline (1915) for guidance. All official channels are linked below so you can act directly.

Was this helpful? (anonymous — no sign-up, nothing stored about you)

Official sources (verify everything here — and you can act directly through them)