Email is often the key to resetting passwords for other accounts. If someone gains access to it, quick and organized action can limit the damage.
Use a trusted device
If possible, make changes from a device you believe is safe. If your computer is showing pop-ups, redirects, or other suspicious behavior, have it checked before entering new passwords. Learn why a browser may keep redirecting.
Change the password and enable two-step verification
Choose a new, unique password that you have not used anywhere else. Turn on two-step verification and save recovery codes in a safe place. A password manager can help keep every account different.
Review recovery and forwarding settings
Check the recovery email, phone number, trusted devices, active sessions, forwarding rules, filters, and automatic replies. Attackers sometimes add a hidden forwarding rule so they can keep receiving messages after the password changes.
Protect connected accounts
Change passwords for banking, shopping, social media, cloud storage, and business tools that used the same password or can be reset through the affected inbox. Start with accounts containing payment, customer, or personal information.
Warn your contacts
Tell contacts to ignore recent unexpected links, invoices, attachments, or requests for money. Review Sent, Trash, and login activity for clues about what the attacker did. Read how to stop phishing emails before they cost you.
Get help when the problem spreads
If you cannot regain access, suspicious messages continue, or the computer may also be infected, contact Clemtech Computers for calm, practical help securing the device and accounts.

