£ GBP

Signs Your Email Account Has Been Compromised, and What to Do First Print

  • 0

Why this matters

A compromised email account is the most common serious security incident we deal with. It rarely announces itself, the attacker's goal is to use your account quietly for as long as possible, sending spam under your name, harvesting your contacts, or watching your mail for invoices to intercept. Knowing the signs means you catch it in hours instead of weeks.

The warning signs

  • Bounce messages for mail you never sent. The classic sign, though first rule out backscatter, where your address was merely forged rather than your account used. Our article on bounce messages for emails you never sent walks through telling the two apart in five minutes using Track Delivery in cPanel.
  • Contacts asking about strange emails from you, especially short messages with just a link, or urgent requests for payments or gift cards.
  • Messages in your Sent folder you did not write, or an empty Sent folder when there should be history, attackers often delete their traces.
  • Mail you expected never arriving, or replies to messages you never saw. Attackers commonly set up forwarders or filters that copy or divert your mail, invoice fraud depends on exactly this.
  • You suddenly can't log in even though the password is correct, or your mail program starts demanding the password repeatedly.
  • Hitting sending limits you never hit before, such as the Max Defers and Failures Per Hour error, when your own sending habits haven't changed.
  • Login warnings from unfamiliar locations or devices, where your mail program or webmail surfaces them.

What to do first, in order

  1. Change the email account password immediately, from a device you trust, to a strong password not used anywhere else. If you cannot log in to change it, open a support ticket or contact us on WhatsApp straight away and we will reset it from our side, see below for how our password resets work.
  2. Change your cPanel password too. If the attacker reached cPanel rather than just the mailbox, changing only the mailbox password leaves them the master key. Do this even if you are not sure, it costs nothing.
  3. Check for forwarders and filters. In cPanel under Email, review Forwarders and Email Filters, and in webmail check the filter settings as well. Delete anything you did not create. This step is the one people skip, and it is the one that lets an attacker keep reading your mail after the password changes.
  4. Check your mail program settings on all devices for reply-to addresses or signatures you did not set.
  5. Review what that mailbox protects. Your email is the reset mechanism for every other service registered to it, banking, accounting software, domain registrars, social media. If the compromise involved a mailbox used for such accounts, change those passwords next and watch the accounts closely.
  6. Work out how it happened, honestly. The usual entries: the same password reused on another site that leaked, a phishing mail you filled your password into, a device with malware, or connecting over an untrusted network with encryption disabled in the mail program. If you cannot identify the route, assume a device problem and run a reputable malware scan on every machine that had the mailbox configured.
  7. Tell your contacts if spam went out under your name, a short warning not to click anything from you in the affected window. Uncomfortable, and far better than a client of yours paying a fraudulent invoice.

How we handle password resets

When you ask us to reset a mailbox password or create a new email account, our staff follow a fixed policy with no exceptions:

  • Passwords are randomly generated, using letters, numbers, and special characters, and are never shorter than 18 characters.
  • We do not set custom passwords on request. If you ask us to set a password of your choosing, we will decline and issue a generated one instead. You are welcome to change it yourself afterwards in cPanel or webmail, but anything set by our staff will always be a secure generated password.
  • We send new passwords via WhatsApp wherever possible, never in an ordinary email, and only ever from our official Business WhatsApp, +27 72 270 9321. A password arriving from any other number, even one claiming to be our staff, or an email claiming to contain a new password from us, is not legitimate: treat it as phishing and report it to us, that is not how we operate.

If sending was suspended during the incident

If we detected the compromise before you did, your mailbox's sending may already be suspended to contain the spam, this is the compromise case described in our article on email suspended for spam or abuse. The steps above are exactly what gets sending re-enabled: once the passwords are changed and the forwarders and filters are verified clean, reply to the suspension notice or the ticket and we will restore sending.

Preventing the next one

  • One strong, unique password per mailbox, ideally from a password manager. Password reuse is the single biggest cause of the incidents we see.
  • Never enter your email password on a page you reached from a link in an email. Log in by typing the address yourself. Warnings about quota or suspension that link to a login page are the most common phishing bait aimed at hosting clients.
  • Keep every device with the mailbox configured updated and scanned, a clean password on an infected laptop is compromised again the day you set it.
  • Delete mailboxes you no longer use. A forgotten mailbox with an old password is the softest target on any account.

Was this answer helpful?

« Back

Powered by WHMCompleteSolution