Friends are getting messages you did not send, or there are sent items you do not recognize, and your password still logs you in. The instinct is relief. Maybe it was not a real break-in.
It was, and the password still working is the version to worry about.
When someone changes your password, they have locked you out to buy a few hours before you notice. When they leave it alone, they want to stay inside your account quietly for as long as possible, and they have usually taken steps to make sure they can.
Why they left your password alone
Three explanations, and all of them mean act now.
They are not using the password. Malware that reads a browser takes the session cookie, which is what your browser holds after you have already logged in and passed the two-factor prompt. Whoever has that cookie is inside the account without needing either credential. Changing your password does nothing to an active session until you also sign every device out.
They want the mailbox, not the account. Your email is where password resets land. Someone working through your bank, your shopping accounts and your crypto wallet needs your inbox to stay ordinary and functional. Locking you out ruins that.
They already set up a way back in. A forwarding rule, an app password, a recovery address they added. Once any of those exists, your password is no longer the thing keeping them out, and changing it is not the fix people assume it is.
Do these six things in this order
Order matters here more than in most security advice, because doing them out of sequence leaves the attacker inside while you work.
- Sign out of all sessions. In Gmail this is the “Last account activity” link at the bottom right, then “Sign out of all other web sessions.” In Outlook it is under sign-in activity. This is first, because it is the step that actually evicts someone, and almost every guide puts it third.
- Change the password to something long and used nowhere else. Now that sessions are killed, the new password sticks.
- Turn on strong two-factor, a passkey or an authenticator app rather than a text code. If two-factor was already on and they got in anyway, that is a session cookie or an app password, which is the next step.
- Check the forwarding rules. Covered below, and this is the one people miss.
- Revoke app passwords and connected apps. Any of these is a working key that a password change does not affect.
- Update recovery options. Confirm the recovery email and phone are yours. Attackers add their own so they can reclaim the account after you have finished cleaning it.
Check for the things they leave behind
A password change with none of this is how people get hacked twice in a week and conclude that security is impossible.
Forwarding rules and filters. The signature move is a rule that forwards everything to an address they control, or a filter that catches anything containing “bank” or “password reset”, forwards it, and marks it read so you never see it arrive. In Gmail this lives under Settings, Forwarding and POP/IMAP, and separately under Filters and Blocked Addresses. Read every filter rather than skimming for one that looks wrong.
App passwords. Sixteen-character codes generated for older apps, each one a full credential that ignores your password and your two-factor. Revoke every one you do not actively use.
Connected third-party apps. Anything holding permission to read or send mail as you. Prune it down to what you recognize and currently use.
Signature changes. A malicious link quietly added to your signature, sent out on everything you write.
Your sent and deleted folders. Read what actually went out. It tells you who to warn and what was targeted, and people delete the evidence before they have looked at it.
Working through this list under pressure, at the hour these things are usually discovered, is exactly when steps get skipped. The Breach Recovery Playbook is the whole sequence as a checklist, including the forwarding-rule and app-password sweeps most guides leave out entirely. $11.99.
Then work outward
Your email is the master key, so treat every account it can reset as exposed.
Start with money. Bank, brokerage, anything holding a card. Change the passwords, check for transfers you did not make, and look at whether any account’s own recovery email got changed.
Then anything with your identity in it: your phone carrier account, your government logins, your cloud storage.
Then everything that shared that password, if the old email password was reused. You know whether it was.
Warn your contacts, and be plain about it. “My email was compromised, anything odd from me in the last few days was not me, do not click it.” People are more forgiving about this than you expect, and the ones who get a convincing scam message from your address a week later are not.
Tell people before you feel ready to
The reflex is to clean it up quietly and hope nobody noticed. What that actually does is leave the people closest to you receiving scam messages from a name they trust.
Send the warning first. Clean up afterwards.
How they got in, so this does not repeat
Cleaning up without working this out means doing it again in a month. Four realistic routes, and you can usually narrow it down.
A reused password from someone else’s breach. The most common by a distance. Your password leaked at a company you had forgotten about, and it was the same one. Check your address on Have I Been Pwned and see which breaches list it.
Malware on a device. If you signed in from a machine running something that reads browser data, your session cookie went out and no password was ever needed. Signs: it happened without any breach you can find, or it recurs after a clean password change. Run a scan, and treat any device you cannot verify as untrusted until you do.
A convincing phishing page. You entered the password, and the code too if it asked. These are good now. A login page reached by clicking a link in an email is the common shape.
Someone with physical access. An unlocked laptop, a shared computer, a family member. Uncomfortable and worth considering honestly rather than skipping.
The response differs per route. A reused password means changing it everywhere it went. Malware means cleaning the device first, because otherwise every new password walks straight back out.
The bottom line
A password that still works is not evidence you were fine. It is usually evidence that whoever got in wants to stay, and that they have left themselves a way back that your password change will not touch.
Sign out of all sessions first, then change the password, then hunt for the forwarding rules, filters, app passwords and connected apps they left behind. Then move outward to everything your inbox can reset, starting with anything holding money. Warn your contacts before you have finished, not after.
