Breach Detection
By Tim O. · July 28, 2026 · 10 min read
7 Signs Your Account Is Already Hacked
Companies that pay full-time security teams still take about six months, on average, to notice they have been breached. IBM's 2025 research puts the mean time to even identify an intrusion at 181 days, before anyone starts cleaning it up. If the people paid to watch for this miss it for half a year, the odds that you will spot a quiet compromise of your own email are not great.
Most people do not discover a hack because they noticed something off. They find out because a bank flags a charge, a friend asks about a message they never sent, or a service they use forces a password reset after its own breach. By then the account has usually been open to someone else for weeks.
So this is the checklist I run for the friends and family who ask me the same thing every few months: how would I even know? The signs below are ordered roughly by how loudly they scream compromise. If you can tick even one with confidence, jump to the recovery steps and start there.
Login alerts or MFA codes you did not ask for
CriticalIf your phone buzzes with a verification code you did not request, someone is standing at your front door with your password already typed in, and that code is the only thing left between them and your account. People see these and assume a glitch. It is far more often a login attempt happening in real time. Never approve a prompt you did not start, and treat even a single one as active.
Check now: open the account's recent security or sign-in activity and look for attempts you cannot account for.
Password reset emails you never requested
HighOne stray reset email you can wave off. A pattern of them, across different services, means someone is walking your email address through login pages to see what it unlocks. They are mapping your accounts before they pick a lock. The version that should worry you most is the reset that goes through while you never see the email, because it was quietly deleted.
Check now: search your inbox and trash for "reset", "verify", and "security alert" over the last month.
Messages, posts, or emails you did not send
CriticalWhen friends reply to a message you never wrote, the account is not just compromised, it is being used. Attackers send from hijacked accounts precisely because your contacts trust you, so your name becomes the bait for the next victim. Anything sitting in your Sent folder or your social messages that you do not remember writing is proof, not suspicion.
Check now: scan your Sent mail and direct messages for anything you did not personally send.
Strange forwarding rules, connected apps, or new devices
CriticalAlmost nobody checks this one, which is exactly why it does the most damage. A patient attacker does not just read your email once and leave. They set a forwarding rule that copies every message to an address you will never look at, or they authorize an app that keeps its own access even after you change your password. That is how someone stays inside an account for months without tripping a single alarm.
Check now: open account settings and review forwarding, connected apps, app passwords, and recovery email or phone. Remove anything you did not add.
Your address turns up in a breach checker
HighPaste your email into a reputable breach lookup such as Have I Been Pwned. If it appears, at least one service holding your credentials has been dumped. That by itself does not prove your account is open, but if you reused that password anywhere, every reused account is now exposed. Breach dumps are where most account takeovers actually begin, long before anyone types your name into a login box. Our analysis of 50,000 breached passwords shows exactly what attackers pull from these dumps first.
Check now: run your main email addresses through a breach checker, then note every place you reused that password.
Logins from places or devices you do not recognize
HighMost major services keep a log of recent sessions with rough locations and device types. A sign-in from a city you have never visited, or a device you do not own, is a live session you need to end. A far-off location is not always an attacker, since VPNs and mobile carriers can muddy the picture, but pair it with any other sign on this list and it stops being ambiguous.
Check now: find "recent activity" or "where you are signed in" and end any session you do not recognize.
Alerts and notifications suddenly go quiet
MediumA subtler symptom: your notifications dry up, or emails you normally expect stop arriving. Someone with access will often delete security warnings and reset confirmations to stay hidden, or build filters that trash them on arrival. If your inbox feels unusually calm right after one of the louder signs above, assume the quiet is deliberate and go inspect your filters.
Check now: review your email filters and rules for anything that deletes or archives security messages automatically.
Overwhelmed? Let it run for you
That is a lot to check by hand across every account you own. The 30-Minute Digital Life Audit walks you through every one of these checks in order, account by account, so nothing slips past you. It is the quickest way to get from "I think I was hacked" to "I know I am locked down."
Get the audit · $9Found a sign? Do this in the next hour
Order matters. Skip a step and you can leave the door propped open.
Not ready to do all this right now?
Get the free Account Lockdown Checklist as a one-page PDF and work through it when you have a clear ten minutes. Same steps, in order, nothing to remember.
One email with the checklist, then the occasional security tip. Unsubscribe anytime.
-
Change the password from a device you trust
Do it from a computer or phone you are confident is clean, not the one you suspect. Make the new password long and unrelated to anything you have used before. If you are stuck for one, our free password generator will build something strong you do not have to invent on the spot, and you can check any password you already use with the strength checker.
-
Sign out every other session
Changing the password is not enough on its own if the attacker's session stays logged in. Find the "sign out all devices" or "log out other sessions" option and use it. This is what actually boots them, not the password change by itself.
-
Rip out the persistence
Go back to those forwarding rules, connected apps, app passwords, and recovery contacts. Remove anything you did not set up yourself. Attackers plant these so that a password change alone does not lock them out.
-
Turn on real MFA
Add multi-factor authentication using an authenticator app rather than text messages wherever you have the choice, since SMS codes can be intercepted. This is the single change that stops a stolen password from being enough on its own.
-
Fix the reuse problem for good
The step people skip is the one that decides whether this happens again: password reuse. If the password on the hacked account guarded anything else, you have to change it everywhere, and doing that from memory is how accounts get missed.
Recommended fix
A password manager gives every account its own long, unique password and fills them for you, so the next time a service you use gets breached, the leak stays contained to one login instead of cascading through your whole life. I point most people toward NordPass for this, because it handles the unique-password-per-site problem without much fuss and imports what you already have. If you want to compare options first, our password manager guide lays them out side by side.
Try NordPass free for 30 daysAffiliate link. SPG earns a commission at no extra cost to you.
Common questions
A breach checker says my email was exposed. Am I hacked?
Not necessarily. Exposure means your credentials were part of a leaked dataset somewhere, which is a warning rather than proof that your specific account is open. The real danger is reuse: if the leaked password guards other accounts, those are the ones to change first. Treat exposure as a prompt to rotate that password everywhere it lived and switch on MFA.
Will changing my password log the hacker out?
Only partly. On many services a password change does not end sessions that are already open, and it does nothing about forwarding rules or connected apps an attacker set up. Change the password, then sign out all other sessions, then remove any persistence you find, in that order.
How do I know if my email was hacked and not just one app?
Your email is the master key, because most password resets flow through it. If you see reset emails you never requested, new forwarding rules, or sign-ins you do not recognize on the email account itself, treat that as the priority and secure it before anything else. An email takeover can quietly unlock everything else you own.
I have MFA. Do I still need a password manager?
Yes, because they solve different problems. MFA stops a stolen password from being enough to log in. A password manager stops passwords from being stolen in bulk in the first place by making every one unique, so a single breach cannot cascade. Strong accounts use both.
The sign that shows up last
The uncomfortable part of all this is that the loudest sign, someone openly using your account, usually arrives last, after weeks of quieter ones you could have caught. If you would rather not guess, the 30-Minute Digital Life Audit walks you through every one of these checks in order, account by account, so nothing slips past you. And if reuse is your real weak point, and for most people it is, close that gap first.
Get the audit · $9Related reading
Free security tools