A scammer having your email address is not the same as having access to your account
If a scammer knows your email address, they can try to reset passwords on your other accounts, send you phishing messages pretending to be a bank or service you use, or sell your address to other scammers. But they cannot read your existing emails or log into your account unless they also have your password. The risk is real, but it is manageable with specific steps taken in the right order.
The first thing to do is check whether they have actually gotten into any of your accounts. The second is to make it harder for them to do so in the future. The third is to watch for the specific ways scammers use an email address once they have it.
Key Takeaways
- Check your account recovery settings in Gmail, Outlook, or whatever email service you use — scammers often add a backup email or phone number so they can lock you out later.
- Change your password to something long and random, and use a different password for every account that matters — a password manager like Bitwarden or 1Password makes this practical.
- Turn on two-factor authentication (a second login step, usually a code from your phone) on your email account first, then on banking and financial accounts.
- Watch for password reset emails from accounts you did not try to reset — these mean someone is actively trying to get in, and you should click the "this was not me" link when ready.
- If a scammer has already reset your password and locked you out, contact the service's support team with proof of identity — most can restore access within hours or days.
Check your email account's recovery settings right now
Scammers often add a backup email address or phone number to your account so that later, when you try to log in, the password reset goes to them instead of you. This locks you out of your own account. Open your email provider's settings and look for "Account recovery", "Security", or "Connected accounts".
In Gmail, go to myaccount.google.com, click "Security" on the left, scroll to "How you sign in to Google", and look at "Recovery email" and "Recovery phone". In Outlook, go to account.microsoft.com, click "Security" at the top, and check "Security info". Remove any phone number or email address you do not recognize. If you see a recovery method you did not add, change your password when ready after removing it.
Do this for every email account you have — work email, personal email, old accounts you barely use. Scammers often target the ones you have forgotten about.
Change your password and use a different one for each account
Your new password should be at least 16 characters long and should not be a word, a date, or anything someone could guess from your social media. The easiest way is to use a password manager — a program that generates and stores random passwords for you. Bitwarden and 1Password are the most common. They cost nothing (Bitwarden) or about $3 a month (1Password), and they mean you never have to remember a password again.
If you do not want to use a password manager, write a long random string on a piece of paper and keep it somewhere safe — a notebook in a drawer, not a sticky note on your monitor. Change it every few months. The point is that if one account gets breached, the scammer cannot use that password to get into your bank account or your email.
Change your email password first. Then change the passwords on accounts that matter: banking, credit cards, PayPal, Amazon, any account linked to a payment method. You can leave less important accounts (social media, forums, old shopping sites) for later.
Turn on two-factor authentication on your email and financial accounts
Two-factor authentication (often called 2FA or MFA) means that even if a scammer has your password, they cannot log in without a second piece of information — usually a code that appears on your phone. This is the single most effective thing you can do.
Turn it on for your email account first. In Gmail, go to myaccount.google.com, click "Security", scroll to "How you sign in to Google", and click "2-Step Verification". In Outlook, go to account.microsoft.com, click "Security info", and click "Add sign-in method". Choose "Authenticator app" if you have a smartphone (apps like Google Authenticator or Authy generate codes), or "Phone number" if you want to receive codes by text.
Then turn it on for your bank, credit card company, PayPal, and any other account with money in it. Most banks have it in their security settings; if you cannot find it, call the customer service number on the back of your card and ask them to enable it.
Watch for password reset emails from accounts you did not try to reset
Once a scammer has your email address, they will try to reset passwords on common services — Gmail, Outlook, Amazon, PayPal, your bank. When they do, you will get an email saying "Someone tried to reset your password" or "Confirm your password change". This is actually good: it means you caught them trying.
Do not ignore these emails. Click the link that says "This was not me" or "I did not request this" or "find your account". This tells the service that someone is trying to break in, and the service will lock the account down. If you do nothing, the scammer might succeed on their next try.
If you see these emails regularly from the same account, it means the scammer is targeting you specifically. After you click "This was not me", change that account's password and turn on two-factor authentication if you have not already.
What to do if a scammer has already locked you out
If you try to log into an account and your password does not work, and you did not change it yourself, a scammer may have already reset it. Do not panic. Most services can restore your access if you can prove you own the account.
Go to the login page and click "Forgot password" or "Cannot sign in". The service will ask you to verify your identity — usually by answering security questions, providing a phone number, or sending a government ID photo. This process takes anywhere from a few hours to a few days. Call the service's customer support line if the online process is not working; phone support is often faster.
Once you regain access, change your password, check your recovery settings, and turn on two-factor authentication. If the scammer added a recovery email or phone number, remove it.
Understand what scammers actually do with an email address
Scammers use email addresses in a few specific ways. They send phishing emails — messages that look like they are from your bank or a service you use, asking you to click a link and "verify" your password. They sell your address to other scammers in bulk. They try to reset passwords on accounts tied to that email. They may use it to sign up for accounts in your name.
You cannot stop them from sending you phishing emails, but you can recognize them: they ask you to click a link and enter a password, they create false urgency ("Your account will be closed"), and the sender's email address is slightly wrong (like "paypa1.com" instead of "paypal.com"). Delete them. Real banks and services do not ask for passwords by email.
If you see accounts you did not create (credit cards, loans, subscriptions), report them to the company when ready and file a report with the Federal Trade Commission at reportfraud.ftc.gov. Keep records of everything: screenshots of the phishing emails, the account statements, the dates you noticed them.
Frequently Asked Questions
Should I change my email address entirely?
No. Changing your email address is disruptive and does not actually solve the problem — scammers will just target your new address too. Instead, find the email address you have by changing your password, turning on two-factor authentication, and checking your recovery settings. That is far more effective.
Can a scammer see my old emails if they have my email address?
Not unless they also have your password and get into your account. Knowing your email address alone does not give them access to your inbox. Once you change your password and turn on two-factor authentication, they cannot get in at all.
What if I keep getting phishing emails from the same sender?
Mark them as spam or phishing in your email client — Gmail, Outlook, and others have a "Report phishing" button. Do not click any links in them. After you report a few, your email provider's filters usually catch the rest automatically. If the emails are pretending to be from a real company, you can also report them to that company's fraud team.
Do I need to pay for a password manager?
No. Bitwarden is free and works well. 1Password costs about $3 a month. Both are better than reusing passwords or writing them down, but if you cannot afford either, a notebook in a safe place is better than no system at all. The key is using a different password for each account that matters.
What if the scammer is using my email address to sign up for accounts?
Check your email for confirmation messages from services you did not sign up for — credit cards, loans, subscriptions, dating sites. If you see them, click the "unsubscribe" or "I did not create this account" link when ready. Then go to that service's website, click "Forgot password", and see if you can log in. If you can, change the password to something random and delete the account. If you cannot, contact the service's support team and tell them the account was created without your consent.