Why Changing Your Password Does Not Always Fix a Hacked Email Account

Changing your password is an important first step when an email account is compromised. But it may not be the whole solution.

If an attacker already accessed your email, they may have created ways to remain connected or continue monitoring messages, even after the password changes.

Depending on the account and the attack, that can include:

🔓 Active sign-in sessions that have not been revoked

📩 Unauthorized email forwarding settings

🫥 Hidden inbox rules that copy, delete, or redirect messages

🔗 Unknown app connections with access to the mailbox

📱 Changed recovery information or MFA methods

👤 Unrecognized permissions, mailbox delegates, or connected devices

This is why email recovery should be treated as an incident response process, not only a password reset.

For a compromised Microsoft 365 account, response steps can include disabling the account when needed, resetting credentials, revoking active sign-in sessions and refresh tokens, reviewing mailbox rules and forwarding settings, and checking permissions and account activity. Microsoft’s guidance specifically includes revoking active sessions and reviewing inbox rules that can redirect or forward messages without the owner’s knowledge.

A password change matters. A complete review helps make sure the attacker is actually out.

Reach out to Bernie Orglmeister at support@skyviewtek.com or call 610-590-5006.