The signs: contacts tell you about strange messages, e-mails you did not write appear in “Sent”, your password no longer works, or you receive sign-in alerts from a country you are not in.
1. Change the password, from a clean device
If the hack comes from a virus on your computer, changing the password from that computer hands it over again. Use another device. Choose a long password that you use nowhere else. If you can no longer log in, go through the provider’s recovery procedure.
2. Turn on two-factor authentication
Straight away, before anything else. With an authenticator app rather than by SMS. A stolen password will no longer be enough.
3. Sign out of all sessions
In the account’s security settings, close all open sessions and remove any devices you don’t recognise. Otherwise, the hacker stays logged in despite the new password.
4. Look for what the hacker left behind
This is the step people forget, and the most important one. Check: the forwarding rules and filters (an automatic forward to an unknown address lets the hacker keep reading everything), the recovery address and phone number, the automatic reply, the signature, and the apps authorised to access the account.
5. Change the passwords of linked accounts
Everywhere you used the same password, and everywhere this address is used for resets: bank, online shops, social networks, government services. Check the mailbox for any “password reset” e-mails received during the suspicious period.
6. Notify
Your contacts first: messages have gone out in your name, often with a request for money or a booby-trapped link. Your bank, if payment details may have been seen. In a business, your manager and your IT provider, without delay and without embarrassment: the sooner it is said, the less serious it is.
In a business, also
A hacked business mailbox is very often used to send fake invoices to your customers, with a different account number. Warn them. If personal data may have been accessed and the risk to the people concerned is high, the nFADP requires you to report it to the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible. Note what you observe, with the times. This is not legal advice.
Where to report it
The Federal Office for Cybersecurity (NCSC) collects reports from the public on its website. If you have suffered a loss, a complaint is filed with the cantonal police.
How it happened
Almost always in one of these ways: a password reused on a site whose database was stolen, a fake login page, or an infected computer. The habits that prevent it fit in three lines.
In short: password changed from a clean device, two-factor authentication, sessions closed, forwarding rules checked, linked accounts, contacts notified. If you are stuck at a step, see Hacking emergency.