Most of us treat email as admin. It’s the thing you clear absent-mindedly on the train, the place invoices pile up, and a tab you leave open all day without thinking about it. Very few people would describe their email account as the most sensitive thing they own. Yet if you listed every service you have ever signed up for, including your bank, your accounting software and a shopping site you used once in 2019, nearly all of them would send a password reset to that same address.
Understanding what actually happens after that first unauthorised login tends to change how seriously people take the account, far more than another reminder about picking a strong password.
What happens when your email is hacked
Whoever buys your credentials from a breach dump works silently. The opening move is usually a mail rule: anything from your bank, your card provider or your accountant gets moved straight into a folder you never open, so the alerts arrive and disappear before you see them. Only then do the reset requests start.
The National Cyber Security Centre makes the same point in its top tips for staying secure online, which puts email at the top of the list because so much else hangs off it.
Why your email account is a target in its own right
Even without the reset trick, the contents are worth money. Ten years of correspondence sits in a typical inbox, along with scanned passports, signed contracts and whatever your solicitor sent over during the last house move. Search is fast and an attacker knows which terms to try.
Plenty of people have responded by moving to an email account that encrypts message contents by default, so a breach at the provider does not expose years of correspondence in readable form. That is a sensible step for anyone whose inbox doubles as a filing cabinet.
The damage often lands on someone else
For a small business the worst outcome is rarely the lost account. It is the message sent from your real address to a client, halfway down an existing thread, asking them to pay the outstanding invoice into different bank details. Nothing about it looks wrong. The sender is genuine, the history is genuine, and the tone matches because the attacker has read the previous forty messages.
Anyone who has seen how much automated outreach now lands in a working inbox will recognise the problem. Volume has trained all of us to skim, and a fraudulent message from a familiar contact gets less scrutiny than it deserves.
What actually holds up
Give the account a password you use nowhere else. Turn on two-factor authentication, and choose an app over a text message where that option exists. Once a quarter, read through your forwarding rules and filters, because an attacker who visited last year may still have one running. Check the recovery address is one you can still get into.
None of that takes an afternoon. It gets skipped because email feels ordinary, and the accounts standing behind it are anything but. Ask anyone who has spent a fortnight proving to six different companies that they are still themselves, and they will tell you the half hour was worth finding.