An email address alone is not the same as access to your inbox, but it can be used for targeted phishing, password-reset attempts and searches for information linked to you. Your email account is worth protecting particularly well.
Use the checks below to slow the situation down, verify the claim through a separate route and avoid giving a suspicious contact more information or control.
What an email address can enable
A scammer can send targeted phishing, try password-reset flows on common services, search for public information linked to the address or combine it with leaked data from other incidents.
Protect the email account itself
Your inbox can be the recovery route for many other accounts. Use a strong unique password, enable multi-factor authentication and check recovery addresses, phone numbers and active sessions where your provider offers those controls.
Expect password-reset phishing
A real or fake password-reset message may arrive after someone learns your email address. Do not approve a reset you did not start. Open the affected service independently rather than using a link in an unexpected message.
Do not reuse passwords
If the email address was exposed together with an old password, change any account where that password is still used. Password reuse can turn one old breach into access to several current accounts.
If you think the inbox was accessed
Change the email password from a trusted device, review sign-in activity, remove unknown recovery methods or forwarding rules, and then secure important accounts that depend on that inbox for recovery.
Practical checklist
Quick checklist
- Use a unique password for your email account
- Enable multi-factor authentication
- Do not approve password resets you did not request
- Review recovery details and forwarding rules
- Change reused passwords if an old credential was exposed
- Secure dependent accounts if the inbox was accessed
Official and primary guidance
Scam techniques, platform features and reporting routes change. These sources were checked when this guide was updated: