Proton Mail Account Hacked: Lock It Down and Recover

moderate ⏱ 30–60 minutes Updated 2026-08-18

Official Proton page for this problem: proton.me — we link it because the official flow is always the real path; this guide exists to help you get through it.

Discovering that someone else has been inside your Proton Mail account is alarming, and the first hour matters. The good news: if you can still sign in, you can almost always evict the attacker and keep your data. The honest caveat: Proton’s end-to-end encryption protects your mail from outsiders and from Proton itself, but it does not protect it from someone who logged in with your password — a signed-in attacker could read everything, just as you can. And if the attacker changed your password and you must use the reset flow, resetting without a recovery phrase or recovery file will leave your old emails permanently unreadable, even after you regain the account.

Throughout this guide, keep the two goals separate: account recovery (control of the address) and data recovery (your existing encrypted mail).

Before you start

  • Work from a device you trust. If you suspect malware or a keylogger on your usual machine, use a different device — otherwise you may hand the attacker your new password too.
  • Locate your recovery phrase (12 words) or recovery file if you ever saved one. If the attacker locked you out, these determine whether your data survives.
  • Have your password manager ready to generate and store a new, unique password.
  • Note what made you suspicious (sent mail you didn’t write, security notification, changed settings) — useful for assessing damage later.

Step 1: Determine whether you still have access

Go to account.proton.me and try to sign in.

  • You can sign in: continue to Step 2 immediately.
  • Your password no longer works: the attacker likely changed it. Use “Forgot password?” and recover with your recovery phrase if you have one — this restores account and data. If you only have a recovery email or phone, understand that resetting this way locks your existing mail; it may still be the right call to stop active abuse, but do it knowingly. If the attacker also changed your recovery methods, contact Proton support from another account and report the compromise — Proton may ask for evidence of ownership, and their options are limited, but a takeover report is worth filing.

Step 2: Change the password (don’t reset it)

If you’re signed in, go to Settings → Password (Proton may label it Account and password) and change your password. Changing it while signed in re-encrypts what’s needed and preserves access to all your data — this is different from the logged-out reset flow. Pick a long, unique password generated by a password manager. If you reused the old password anywhere else, assume those accounts are at risk too.

Step 3: Revoke every other session

Go to Settings → Security and find the sessions or devices list. Revoke all other sessions. This forcibly signs out the attacker everywhere, including mobile apps and browser sessions. Do this right after the password change, not before — otherwise the attacker can sign back in.

Step 4: Check what the attacker changed

Attackers plant persistence. Review each of these:

  1. Recovery methods (Settings → Recovery): remove any recovery email or phone number you don’t recognize, and re-verify your own. Generate a new recovery phrase if Proton indicates the old one may be compromised.
  2. Two-factor authentication: if 2FA was disabled, re-enable it (an authenticator app or hardware security key). If the attacker enrolled their own 2FA method or key, remove it.
  3. Filters and auto-forwarding (Mail settings): delete any forwarding rule or filter you didn’t create — a forward to an external address silently copies your future mail to the attacker.
  4. Signatures and auto-reply: check for injected phishing links.
  5. Connected apps and sessions for Proton Bridge / third-party clients: revoke anything unfamiliar.
  6. Sent and Trash folders: look for messages the attacker sent or deleted to cover their tracks.

Proton also keeps security events / authentication logs under Settings → Security. Review recent sign-ins for unfamiliar times or locations; enable advanced logging if offered.

Step 5: Assess and contain the damage

Assume the attacker read anything in the mailbox. Act on that:

  • Reset passwords on important accounts that use this email address, starting with banking, government services, and any account whose reset emails land here.
  • If password-reset emails for other services appear in your mailbox history, treat those accounts as compromised.
  • Warn contacts if phishing was sent from your address.
  • Report the compromise to Proton via their abuse/security reporting channel so they have a record.

Step 6: Harden the account

Enable 2FA with an authenticator app or, better, a hardware key. Confirm your recovery phrase is stored somewhere safe and offline, and download a fresh recovery file from Settings → Recovery. Consider enabling any additional protection program Proton offers for high-risk users if that applies to you.

What NOT to do

  • Do not hire a “hacked account recovery” service. Proton’s end-to-end encryption makes third-party recovery of your mailbox outright impossible — no company can decrypt Proton data or override Proton’s authentication. Paid services claiming this are scams, and some are run by the same people who hack accounts.
  • Never share your recovery phrase, password, or 2FA codes with anyone, including callers or emailers claiming to be Proton support. Proton will not ask for these.
  • Don’t use the logged-out password reset if you can still sign in. Change the password from Settings instead — the reset flow without a recovery phrase destroys access to existing mail.
  • Don’t just change the password and stop. If you skip revoking sessions and checking forwarding rules, the attacker often keeps quiet access for months.

If nothing works

If the attacker changed the password and every recovery method, and you have no recovery phrase or file, be realistic: Proton cannot verify ownership through your mail contents (it can’t read them), and it cannot decrypt the mailbox for anyone. The account may be unrecoverable, and the data inside it is unrecoverable by design — for the attacker after Proton disables the account, but also for you.

If you reach that point: report the takeover to Proton so the account can be investigated or frozen, then start fresh. Create a new account, immediately record the recovery phrase, download a recovery file, enable 2FA, and migrate your logins to the new address — treating every service tied to the old mailbox as needing a password reset and a recovery-email update. It is a painful reset, but it is the complete one.

Frequently asked questions

Can a hacker read my old Proton emails?

If they signed in with your password, yes — signing in decrypts the mailbox just as it does for you. End-to-end encryption protects mail from Proton and from network interception, not from someone who has your password.

Should I reset my password or just change it?

If you can still sign in, change the password from Settings — this preserves your data. Only use the reset flow if you're locked out, and use your recovery phrase if you must reset, or your old emails become unreadable.

Can Proton tell me who hacked my account?

No. Proton can't identify attackers for you, and it can't read your mail to assess damage. You can review recent session and security events yourself in Settings, and report the incident to Proton.

The hacker changed my password and recovery email. Is the account gone?

Not necessarily. If you have your recovery phrase, you can reset the password and recover both the account and your data. Without any recovery method, Proton has very limited ability to return the account to you.

Do I need to tell my contacts?

Yes, if the attacker had access for any length of time. They may have sent phishing messages from your address or read threads containing others' information.

recover.email is not affiliated with Proton. This guide is informational and cannot guarantee recovery.