iCloud Mail Hacked: Secure a Compromised Apple Account

moderate ⏱ 30–60 minutes Updated 2026-08-18

Official Apple page for this problem: support.apple.com — we link it because the official flow is always the real path; this guide exists to help you get through it.

Discovering that someone else has been in your iCloud Mail or Apple Account is unsettling, but in most cases you can take the account back and shut the intruder out completely. What you can’t undo is what they already saw: assume any email in the mailbox during the compromise was read. This guide walks through regaining control, then the audit that most people skip — and it’s the audit that prevents round two.

Apple renamed Apple ID to “Apple Account” in 2024; older security emails and articles may use the old name.

Before you start

  • A trusted device — an iPhone, iPad, or Mac still signed in to the account. If the intruder hasn’t removed your devices, this is your fastest way back in.
  • Your trusted phone number and the phone itself.
  • A clean computer or phone — if you suspect malware on a device (a real possibility if the compromise started with a phishing link or a downloaded file), do the recovery from a different device.
  • A few minutes to list what’s connected to this account: subscriptions, banks that email you here, other accounts that use this address for password resets. You’ll need this list for the audit.

Step 1: Take back control of the password

Act in this order — the password change is what actually ends the intruder’s session:

  1. If you’re still signed in on a device: go to Settings > [your name] > Sign-In & Security > Change Password, enter your device passcode, and set a new, unique password. Do this immediately, before anything else.
  2. If the password was changed on you: go to iforgot.apple.com and reset it. With a trusted device or trusted phone number you can usually complete this in minutes. If the intruder changed your trusted phone number too, you’ll be routed into account recovery, which involves a waiting period of days — see our lost-2fa guide for that process.
  3. Choose a password you’ve never used anywhere else. If the same password protected other accounts, change those too — password reuse is the most common way iCloud accounts get compromised in the first place.

Step 2: Sign out every session and remove unknown devices

  1. On a trusted device, go to Settings > [your name] and scroll to the device list (on the web, sign in at account.apple.com and open Devices).
  2. Look for anything you don’t recognize — an unfamiliar iPhone model, a Windows PC, a browser session. Tap each unknown device and choose Remove from Account.
  3. Changing the password already invalidates web sessions at icloud.com, but removing devices ensures nothing stays signed in.

Step 3: Audit your security and recovery information

An attacker’s goal is often to plant a way back in. Check each of these at Settings > [your name] > Sign-In & Security or account.apple.com:

  • Trusted phone numbers: remove any number you don’t recognize. Make sure yours is still listed.
  • Recovery contacts and recovery key: confirm nothing was added or changed. If a recovery key you never created is now enabled, that’s an intruder foothold — regenerate or remove it.
  • Two-factor authentication: it should be on. If your account somehow predates mandatory two-factor and it’s off, turn it on now.
  • Apple Account email and rescue addresses: verify they’re all yours.
  • App-specific passwords: revoke all of them; regenerate the ones you actually use.

Step 4: Check iCloud Mail itself for tampering

This step is specific to mail compromises and frequently missed:

  1. Sign in at icloud.com/mail and open Mail settings (the gear icon).
  2. Check forwarding. Attackers commonly set your mail to auto-forward to an address they control, so they keep reading your email even after you change the password. Turn off any forwarding you didn’t set.
  3. Check mail rules/filters. Look for rules that delete or move messages (especially ones matching “password”, “verification”, or your bank’s name). Delete anything you didn’t create.
  4. Check aliases and send-from addresses for additions you don’t recognize.
  5. Skim Sent and Trash for messages you didn’t write — attackers use hijacked accounts to phish your contacts. If you find any, warn the recipients.

Step 5: Contain the wider damage

Your email address is the master key to your other accounts, because password resets flow through it.

  1. Change passwords on high-value accounts that use this address: banking, other email, social media, your password manager.
  2. Review recent password-reset emails in your iCloud inbox and trash — they show which accounts the attacker may have pivoted into.
  3. Check Settings > [your name] > Payment & Shipping and your purchase history at reportaproblem.apple.com for charges you didn’t make; dispute any through Apple.
  4. If money was stolen or identity fraud occurred, file a report with your local police and, in the US, at reportfraud.ftc.gov. Apple may ask for a case number if disputes escalate.

What NOT to do

  • Don’t pay a “hacked account recovery” service. No third party can access or repair an Apple Account. These offers — common in search ads and social media replies — are scams, and some are run by the same people who compromise accounts.
  • Never share a verification code with anyone. The single most common Apple Account takeover today is a phone call from fake “Apple support” asking you to read back a code “to verify your identity.” Apple never calls you unprompted and never asks for codes, passwords, or recovery keys.
  • Don’t click links in “security alert” emails. Type iforgot.apple.com or account.apple.com yourself. Real Apple alerts never ask you to sign in via an embedded link to “verify” your account.
  • Don’t delete the account or wipe devices in a panic. You’ll destroy evidence of what happened and forfeit data that is still recoverable.
  • If you end up in account recovery, don’t cancel and restart the request — each restart resets the waiting period.

If nothing works

If the attacker changed your password, your trusted phone number, and removed your devices before you noticed, your remaining path is Apple’s account recovery process at iforgot.apple.com — a waiting period of days to weeks while Apple verifies you. If that request is ultimately denied, the account is not coming back, and you should assume the intruder controls it:

  • Treat the address as hostile. Tell your contacts not to trust email from it, and remove it as the recovery address on every other account you own.
  • Your mail history is lost unless a desktop mail client on one of your computers downloaded copies.
  • Activation Lock: devices tied to the lost account may stay locked to it. Apple can remove Activation Lock with proof of purchase (a receipt showing the serial number) even when the account can’t be recovered.
  • Start fresh with better defaults: new Apple Account, unique password in a password manager, two trusted devices, a recovery contact, and a periodic glance at your device list. The audit in Steps 3 and 4 is worth repeating once a year even on a healthy account.

Frequently asked questions

How do I know if my Apple Account was actually hacked?

Warning signs include password-change or new-sign-in emails you didn't trigger, unfamiliar devices in your device list, sent emails you didn't write, changed recovery information, or purchases you didn't make. Any one of these justifies a full security pass.

Can a hacker read my old iCloud emails?

If they had your password and could pass two-factor authentication, yes — anything in the mailbox while they had access should be considered read. Changing your password ends their access going forward but can't undo what was already seen.

Will Apple tell me what the hacker did in my account?

No. Apple doesn't provide an activity log of actions taken in your account. You have to audit the account yourself: devices, mail rules, forwarding, recovery info, and payment methods.

Should I delete my Apple Account after a hack?

Usually not. Once you've changed the password, removed unknown devices, and fixed recovery info, the account is yours again. Deleting it forfeits purchases, iCloud data, and your @icloud.com address permanently.

The hacker changed my password and I can't get in. Is it over?

Not necessarily. If you still have a trusted device or trusted phone number, you can often reset the password at iforgot.apple.com and take the account back. Apple's two-factor design makes it hard for an intruder to fully lock out the real owner quickly.

recover.email is not affiliated with Apple. This guide is informational and cannot guarantee recovery.