Storming Solutions

Digital Hub / Web Development

My Webmail Was Hacked: What Do I Do? (Email Security 101)

Updated 2 September 2026

Jump to section

If your webmail is hacked, move fast and in order. Change the password from a device you trust, turn on two-step verification, then remove any hidden forwarding rules the attacker added. Most break-ins start with a phishing link or a reused password, not clever code. In Malaysia, if customer data was exposed, the PDPA can require you to notify the regulator within 72 hours.

The first hour: lock the attacker out

Speed matters more than diagnosis in the first hour. An intruder in your mailbox is reading, resetting, and impersonating in real time.

Work through these steps in order.

Do this first Why it matters
Change the password from a clean device Cuts off the attacker's current access
Turn on two-step verification A stolen password alone no longer works
Sign out all other sessions Kicks the attacker off immediately
Delete unknown forwarding rules and filters Stops them reading your mail after the reset
Confirm your recovery email and phone Prevents them from locking you out

Then review your Sent and Trash folders. That shows what went out under your name, so you can warn anyone the attacker emailed.

How the account got in: usually phishing or a reused password

Most email break-ins trace back to a stolen password, not a cracked server. The two common paths are a phishing page that captured your login, and a password you reused on a site that was later breached.

The reuse problem is mechanical. Once one of your passwords leaks, attackers automatically try it against email providers everywhere, so a single reused password can open many doors at once.

This is exactly what a second step defeats. Google states that two-step verification adds an extra layer of security in case your password is stolen. Passkeys or hardware security keys go further and protect the account from phishing attacks.

In our experience, the email trouble we see comes from reused passwords and phishing, not clever code.

Prevent the next break-in

Prevention costs far less than recovery, and four habits carry most of the weight.

Give every account a unique password, kept in a password manager so you never reuse one. Turn on two-step verification on every mailbox, not only your main one.

Train staff to spot phishing: check the sender's real address, and never log in through a link in an unexpected email.

Use business email that is authenticated with SPF, DKIM, and DMARC, which makes it harder for anyone to spoof your domain and easier for providers to flag fakes.

Email security sits alongside the rest of your site's defenses: a valid SSL certificate, your own backup, updated software, and understanding why sites get hacked in the first place.

If customer data was exposed: the PDPA clock

A hacked business mailbox stops being only your problem the moment it holds customers' personal data.

Under Malaysia's Personal Data Protection Act, amended in 2024, a breach that risks significant harm must be reported to the Commissioner within 72 hours. Affected individuals must be told within 7 days.

So treat a serious email compromise as a possible reportable breach, and handle it with that seriousness. Document what happened and what data was reachable, because that record is what a notification, if one is required, is built from.

Frequently asked questions

How do I know if my email was hacked?

Common signs are being unable to log in, contacts receiving spam from your address, unfamiliar messages sitting in Sent, and password-reset emails you did not request. New forwarding rules or filters you did not create are another giveaway. Any one of these is worth acting on immediately rather than waiting to be sure.

Will changing my password be enough?

Not on its own. An attacker who added a forwarding rule keeps reading your mail even after a password change, and one who stays signed in on another session is untouched. Change the password, then turn on two-step verification, sign out all sessions, and remove any rules or filters you did not set yourself.

Does two-step verification really stop hackers?

It stops the most common attack, a stolen or guessed password, because the code or key is something the attacker does not have. Google notes that passkeys and hardware keys resist phishing too. It is not absolute protection, but it turns most break-in attempts into dead ends before they start.

Should I tell my customers my email was hacked?

If their data was exposed, or they received scam messages from you, yes. Beyond the trust reasons, Malaysia's PDPA can legally require you to notify affected individuals within 7 days when there is a risk of significant harm. Silence in that case is both a trust problem and a compliance one.

Can a hacked email lead to a hacked website?

Yes, and this is why it matters so much. Your email is often the recovery address for your hosting, domain, and website login, so an attacker in your inbox can reset those next. Securing the mailbox protects the accounts that quietly depend on it.

Secure the mailbox, then close the door behind it

Your immediate job is the checklist above, in order, from a device you trust. Your lasting job is making the next attempt fail: unique passwords, two-step verification everywhere, and staff who recognize a phishing page.

Storming Solutions builds and maintains websites, and secures the domains, email, and hosting behind them, for Malaysian businesses from Kuala Lumpur. We will not sell you fear, but we have cleaned up enough compromised accounts to say the prevention is worth an afternoon.

Locked out, or unsure how far a break-in reached? Message us on WhatsApp and we will help you work through it.

WhatsAppCall 011-2333 6888