ACTIVE INCIDENT RIGHT NOW? Gridisys 24/7 emergency triage — £0 first 15 minutes.
24/7 EMERGENCY INCIDENT RESPONSE · UK

Email Hacked? — UK Email Account Compromise Response

If your email account has been hacked — emails sent to your contacts, suspicious autoforwarding, attackers reading your inbox, password no longer works, fraudsters trying to reset your bank login — we recover it within hours, not days. UK-based 24/7 incident response for Microsoft 365, Gmail, Outlook.com, Virgin Media, BT Internet and other UK email providers.

We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.

YOU MAY HAVE SEARCHED

"my email has been hacked UK""email account compromised what do I do""someone is sending emails from my account""my email password doesn't work anymore""I can't log into my email account""suspicious autoforward rule in my inbox""gmail account hacked recovery UK""outlook.com account compromised""virgin media email hacked help""btinternet email hacked what to do""yahoo email hacked UK""fraudster reset my bank using my email""supplier says my email address sent phishing"

Do these 4 things in the next 10 minutes

  1. 1

    Try to log in. If the password no longer works, attacker has changed it — go to the provider's recovery flow (Google: myaccount.google.com / Microsoft: account.live.com / Virgin/BT: their help portal) and choose ' Forgotten password / account recovery'. Use a recovery email or phone you still control.

  2. 2

    From a separate clean device, change the password on every account that uses this email address for password resets — bank, PayPal, credit card, HMRC, Companies House, AWS, social media, online shopping. Assume the attacker has read your inbox and knows what services you use.

  3. 3

    If you can still log into the email account: check Inbox Rules / Filters / Forwarding (Gmail: Settings → Forwarding and POP/IMAP + Filters; Outlook: Rules; BT/Virgin/Yahoo: Settings → Filters). Look for unknown rules that autoforward to external addresses or auto-delete incoming mail on keywords like 'invoice', 'bank', 'password'. Delete any attacker rules.

  4. 4

    Turn on 2-step verification / 2FA as soon as you regain access — Google: myaccount.google.com/security; Microsoft: account.microsoft.com/security; BT/Virgin via their help portal. SMS is OK short-term; an authenticator app is safer.

Most people don't discover their email was hacked for 7–21 days. By then the attacker has typically read your inbox, set up hidden autoforwarding and used what they found to attempt password resets on your bank, PayPal, AWS or HMRC account. Acting now compresses the breach window, knocks the attacker out sooner, and protects every account that uses that email address for recovery. We've handled hundreds of UK email account compromise cases.

What we do — the Gridisys incident timeline

From the moment you engage, within fixed-price limits.

First 60-120 minutes

Triage + scoping (Hour 0-2)

  • Free 15-min triage call — which provider, how access was lost, what's already been tried
  • Identify likely attack vector — phishing link, password reuse, SIM-swap, malicious OAuth grant, reused password from a breached site
  • Check HaveIBeenPwned for the email address — find what password leaks it's already in
  • Walk the client through provider-level account recovery if they haven't done it yet
Within 6 hours of engagement

Recovery + attacker purge (Hour 2-6)

  • Regain access to the email account via provider recovery flow, with verification
  • Change password to a fresh random password (don't reuse a pattern from your other accounts)
  • Force-end all other active sessions (Gmail: Manage devices; Outlook: Recent activity; BT/Virgin: equivalents)
  • Purge every attacker rule and autoforward — check both Inbox rules and sweep rules, plus any connected third-party apps with mail read/send permission (OAuth grants)
  • Enable 2-step verification / 2FA — authenticator-app based, not SMS if possible
Days 1-2

Blast-radius investigation (Hour 6-48)

  • Audit every password-reset email received in the last 30–90 days (sent folder + deleted items + spam) — identify which other accounts the attacker likely targeted
  • Identify which services used this email address for recovery: bank, HMRC, Companies House, AWS, PayPal, social media, online banking, share-trading platforms
  • Identify any BEC (Business Email Compromise) sent from the account — fraudulent supplier bank-change requests, fake invoices, executive impersonation
  • Identify any personal data exposed — clients, employees, suppliers whose personal data sat in the inbox (triggers UK GDPR / DPA 2018 ICO notification)
1-7 days

Re-secure + rollback (Day 2-7)

  • Change passwords on every account that used this email for recovery — bank, HMRC, pension, share-trading — using a password manager with random unique passwords
  • Replace recovery-email address + recovery-phone where possible (a fresh SIM is safer if a SIM-swap was likely)
  • Document what was sent/received during the breach window for the breach register / ICO submission
  • Set up a clean account alias / forwarding architecture if account reputation is contaminated (sender blacklist, spoofed domain, bounce-back loop)
72-hour ICO clock

ICO + Action Fraud + bank notifications (Day 1-7)

  • Assess whether personal data was likely accessed / exfiltrated — triggers UK GDPR / DPA 2018 ICO 72-hour notification
  • Draft ICO notification submission (threshold assessment, breach description, mitigation actions, risk tier)
  • File Action Fraud UK report if financial fraud was attempted or succeeded — faster Action Fraud notification significantly improves bank reimbursement odds
  • Coordinated bank notification protocol if any payment-account password resets were received during the breach window (suspicious-bank-login prevention)
  • Cyber insurance notification — most UK policies require insurer notification within 24-72h of becoming aware

What it costs

Triage + first 4 hours: free. All email compromise investigations are fixed-price — personal account recovery, business mailbox compromise with BEC investigation + ICO + customer-notification pack, or multi-account / tenant-wide compromise. Optional ongoing managed SOC monitoring available after the incident. Contact us for a tailored quote.

Full pricing breakdown

What we cover

Account recovery across Microsoft 365 / Gmail / Outlook.com / Virgin Media / BT Internet / Yahoo / Apple iCloud / other UK providers
Attacker persistence removal — hidden autoforward rules, sweep rules,OAuth grant abuse, recovery-email / recovery-phone changes reverted
Password-reset audit — which other accounts the attacker likely pivoted to from this email (bank, HMRC, AWS, social, share-trading)
BEC (Business Email Compromise) investigation — fraud sent from your address to your suppliers / finance team / contacts
2FA / 2-step verification setup — authenticator-app based, backup codes generated, recovery contacts set
Breach-register documentation + ICO 72-hour notification assessment (UK GDPR / DPA 2018)
Action Fraud UK report drafting + cyber insurance notification pack
Bank notification coordination if bank-account password resets were received during breach
Incident timeline evidence pack — what was accessed, what was sent, what was attempted, mitigation actions, residual risk

Frequently asked questions

Talk to us now

The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.