Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Scams & Phishing Security Education Videos Mobile Security Your Security Education Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Has Your Email Been Hacked? Here’s How You Can Tell And What You Can Do
Facebook   X   LinkedIn   Email

Has Your Email Been Hacked? Here’s How You Can Tell And What You Can Do

September 21, 2024

There are any number of signs that may give you a clue that your email has been hacked. And what do you do if it has? You may ponder that very question if you suspect that’s the case. Let’s go over a few indicators of a compromised email box and what you can do about it, if it happens to you.

Indicators

Suspicious login attempt notifications. This might be a familiar notification for you. It will happen if you login with a new phone or computer. It could also happen if you are in a different location depending on whether or not your device has been registered as a trusted device. 

Tip: If you’re receiving multiple notifications about suspicious login attempts on your email account, it could be that someone is attempting to gain access to your account or already has. It might also be a phishing scam, so DON'T CLICK on the email. Instead, login into your email account and change your password and enable Multi-Factor Authentication (MFA) is available.

Your personal data has been changed. Have you received an email from your email provider informing you that some of your personal data in your account has been changed? This may be a sign that it’s been compromised. If you haven't made any changes yourself, it’s worth taking a look to make sure no one else has either.

Tip:  Log into the account separately, rather than clicking on links you may receive in email or in a text. The message letting you know there were changes may actually be phishing rather than a message from your provider.

Spam emails were sent from your account. If contacts in your address book inform you that they have received spam emails from you, this should be a red flag. While there are other reasons your address may appear in the spam emails (spoofing your address, for example), it is also possible that someone is using your account to send spam emails.

Tip: To find out if it’s coming from your mailbox, log in and look at your sent messages. If there are a bunch that you didn’t send, someone has gotten into your account. If not, ask your contacts to hover over the sender’s address (or, on mobile devices, press and hold the sender with your finger). If there’s an email address other than yours, this is "spoofing." This means that the sender has used your name, but your mailbox has not been hacked. Unfortunately, other than putting your worries at ease, there isn’t anything else you can do other than letting your email administrator know.

Address book has been deleted. Sometimes, it’s possible that attackers are using what’s called the "grandparent scam." This is that infamous scam where someone calls pretending to be a grandchild, niece, nephew, child, friend, etc. stating they are in need of financial help and ask the victim to send money right away. They may claim they are in jail or need it for medical treatment, among many other excuses. After performing this scam, the attackers may delete the address book/contact list.

Tip: Any sense of urgency like “I’m in dire need to get out of jail,” or pay a bill or something bad will happen, should set off alarm bells. Contact who they claim to be separately and confirm it. Most of the time, you’ll find out that person is safe and just fine.

Your login failed several times. If you receive a security alert that there have been several failed login attempts to your email account, it may be cause for alarm. If these are not you, it may mean that something is wrong.

Tip: Log into your account separately and make sure your information is still valid. Consider changing your password and be sure to enable multifactor or two-factor authentication.

Email password changed. If you find that you cannot access your mailbox even after entering your password several times and you have not mistyped it, then someone may have taken over your email account.

Tip: If you cannot log in and request to change your password and are unsuccessful, you will need to contact your email provider.

Yes, someone did try to get into my account. Now what?

If you notice signs of unauthorized access, it is best to take the following steps immediately:
Change your password in the settings. Make sure you make it at least eight characters with a combination of letters, numbers, and special characters. Avoid using dictionary words, names, or personal information. Remember to also reset the password in your mobile device apps.

Run a virus scan on all devices. It is important that you run a full virus scan, not a "quick scan." You can find free and paid versions that are good, but you should have something installed on all devices to help catch these. If the virus scan reveals something, change the password again. Yes, it’s a little annoying, but if you don’t, the hacker will also have the password you just changed to.

Change your security question(s): If your email has security questions attached to it, the hackers also had access to those. Therefore, you should change those.

Notify your contacts that your email account has been hacked. Whoever got into your account had the opportunity to send infected emails to all your contacts in order to attract new victims. By letting them know right away, they can avoid falling victim to attacks.

Check your stored data and also your settings. Make sure your spam protection is still activated, if you can toggle it. Check your filter rules if you had any set up, and take a look at the storage period of your email folders. They may have been changed, so you’ll need to recheck them.

Potential reasons for a hacked mailbox

Weak passwords are the most common cause of an attack. If your passwords do not meet the minimum standard, you are making it relatively easy for criminals to gain control of your mailbox or other accounts.

Tip: Be sure to always use strong and unique passwords for every single online account.

Unfortunately, many people fall for phishing lures over and over. Often, it’s a result of stolen passwords and login data resulting from successful phishing excursions or a previous data breach.

Tip: Know the phishing lures such as blurred graphics and photos, typos, and links and attachments that are sent from unknown senders or that are not expected.


Ways To See If Your Data Has Been Stolen

Education

Ways To See If Your Data Has Been Stolen

With all the data breaches, whether by intrusion or accident lately, it’s likely your information was exposed somehow to someone you didn’t intend. After all, the marketing company Exactis, exposed hundreds of traits on us in 350 million records. Yahoo let out email addresses and passwords on billions of people, and of course who can forget the massive breach of Equifax just last year. There is a lot of information that gets leaked on us and the more the bad actors have on us, the more targeted their phishing campaigns can be. Checking on whether or not your data is available in the underground can help you mitigate any fraud or identity theft. READ FULL STORY

How To Create A Strong And Unique  Password For Every Account

Education

How To Create A Strong And Unique Password For Every Account

Most of us know by now not to use the same passwords for different accounts; yet some of us still do. But users who continue to use passwords they know have been exposed in a hack are truly flirting with danger. In a recent study, Google found 1.5% of passwords are still being used despite those users knowing they’ve been compromised. A security researcher discovered more than 22 million unique passwords and over 770 million email addresses were made public on a popular hacker forum earlier this year. READ FULL STORY

Business Email Spoofing On The Rise

Corporate Security

Business Email Spoofing On The Rise

While the headlines are focused on ransomware attacks, spoofed emails are getting sneakier and more successful. Bad actors are always finding new ways to hack their way into businesses, and spoofing email addresses are proven way of doing just that. During the first 100 days of the coronavirus outbreak, spoofing attacks increased by 30%. This type of phishing email can sneak past antivirus security and lead to data theft, fraudulent wire transfers, ransomware, BEC (business email compromise), and more. READ FULL STORY

Email Scams Threaten Extortion And Blackmail

Scams & Phishing

Email Scams Threaten Extortion And Blackmail

An uptick in email scams has cybersecurity professionals concerned, and for good reason. Symantec researchers found that in the first five months of 2019, they prevented almost 300 million extortion email attacks from going forward. Just some of those discovered include blackmail, sextortion, bombs, hit men, and malware threats. The researchers also determined the average cost of paying demands over a 30 day period was $1.2 million in 243 Bitcoin transactions. READ FULL STORY

BOLO for These Most Dangerous Email Attachments

Scams & Phishing

BOLO for These Most Dangerous Email Attachments

Keeping a lookout for suspicious emails has become a daily consequence of our cyber lives. Phishing emails are notorious for having malicious attachments and opening them is a sure way to compromise your device and its data. These attachments are full of malware, ready and waiting to infect your system with a simple click. Make no mistake, any attachment in a questionable email can be dangerous. However, researchers at F-Secure found that some of this year’s biggest email spam campaigns used particular types of malicious attachments more than others. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...