To regain control of your hacked email account, follow these steps:
- Disable the Compromised Account: If you have access to the account settings, disable the account to prevent further unauthorized access.
- If you are using Microsoft 365, you can disable the account using PowerShell commands. You will need to install the Microsoft Graph PowerShell module and run the necessary commands to disable the user account.
- Reset Your Password: If you haven't already, change your password to a strong one that includes upper and lowercase letters, numbers, and special characters. Avoid using any of your last five passwords. Make sure not to send the new password via email.
- Revoke User Access: Immediately invalidate any active sessions using the stolen credentials. You can do this by connecting to Microsoft Graph and revoking the user's sign-in session.
- Enable Multifactor Authentication (MFA): If you regain access, enable MFA for added security. This will help protect your account from future compromises.
- Check for Suspicious Activity: Look for any unauthorized changes in your account settings, such as email forwarding rules, changes to your contact information, or suspicious emails in your Sent Items or Deleted Items folders.
- Monitor Your Account: Keep an eye on your account for any further suspicious activity and consider notifying your contacts that your email was compromised.
- Contact Support: If you are unable to regain access or if the situation escalates, contact Microsoft support for further assistance.
Following these steps will help you regain control of your email account and secure it against future attacks.