How to Avoid Email Hacks

Community cybersecurity guide

Don't Get
Phished

Phishing emails may look like an evite, endorsement, RSVP, invoice, voicemail, or message from someone in your contacts. Even if it comes from someone you know, it may not be safe.

Emails like these have become increasingly common

Examples of suspicious invitation-style phishing emails and endorsement messages.

They may look like an evite, endorsement, RSVP, or a message from someone in your contacts.

The fact that it comes from someone you know does not mean it is safe. Likely, their email account has been compromised.

These emails are catchy. When one person gives a hacker access to their account, the hacker sends the same email to all of their contacts, and the attack spreads.

They can try to get you to

  • Click a link that leads to a fake login page, have you sign in, and give over your email password.
  • Give permission to connect to your Google account.
  • Download and run a file that will allow them to connect to your device.

If you follow through with any of those actions, the attacker will likely be able to access your email and send emails to your contacts, see sensitive information in your mailbox, connect to any bank or service connected to your email, or even gain remote access to the device that you are logged into.

Do yourself a favor. Turn on MFA for every email account.

What to do if
you clicked

How to know if you are in danger

  1. If you opened the email but did not click anything, you are safe.
  2. If you were taken to a login page and entered your password, see below. MFA would prevent access.
  3. If you were asked to connect your Google account and clicked Allow, see below.
  4. If you may have downloaded a file, see the downloaded file section.

Check Gmail itself

  1. Open Gmail.
  2. Click "Settings" and hit "See all settings."
  3. Click "Forwarding and POP/IMAP." Under forwarding, remove any addresses you did not set up.
  4. Click Filters and Blocked Addresses. Delete anything you did not set up.

What to do if you
downloaded a file

How to know if you are in danger

  1. If you downloaded and tried to run a file, follow the instructions below urgently.
  2. If you did not run anything, open your downloads folder in file explorer. If you set a different default download location or specifically saved something to another location, check there as well.
  3. Open file explorer, go to downloads, and hit View > Show > File name extensions.
  4. Look for any files downloaded around the time of the phishing email, specifically files ending in .exe, .msi, .zip, .7z, .rar, .iso, .img, .js, .vbs, .bat, .cmd, .lnk, .docm, .xlsm, .html, or .htm.
  5. If you find a file, delete it from downloads and delete it from trash. You should be safe.

If you tried to run a file

  1. If you were asked for permission and clicked No, you should be safe.
  2. If you clicked Yes but your antivirus blocked the file before it ran, you should be safe.
  3. If the file ran, disconnect from the Internet immediately.
  4. Do not sign into any accounts on that device.
  5. The device should be treated as potentially compromised. The safest course is to reset or reinstall the device after backing up important files. You may need professional IT assistance for this.

This guide was compiled as a service to the community by Keystone Cyber Protection. Keystone is a Lakewood-based cybersecurity firm that helps businesses stay secure and avoid getting hacked. We do not work directly with individuals.