Account Protection & Incident Response

Your email account is one of the most valuable pieces of your online life. This page explains why organized criminal groups work so hard to take over individual email accounts, what they gain when they succeed, the real risks to you if your account is compromised, how Pacific Internet responds when we detect a problem, and the practical steps you can take to keep your account secure.

Looking for how to spot phishing?

Our Email Security page covers phishing, spam filtering, sender spoofing, and fraudulent websites in detail.

Email Security & Phishing →
Did you reach this page after seeing a “security hold” notice in your mailbox? Your email has not been lost — it is safely stored and new mail is still arriving. Your account has been temporarily locked to protect it. Please call us at (707) 468‑1005 so we can help you change your password and restore your normal mailbox. See How Pacific Internet responds below for what this means and why we do it.
Pacific Internet will never ask you for your password by email, text message, or phone call. Anyone who does is attempting to steal your account. If you are ever unsure whether a message is genuine, stop and contact us directly at support@pacific.net or (707) 468‑1005.

5. How to Stay Safe

Strong passwords, phishing awareness, and everyday habits that protect you.

Read how to stay safe »

6. If You Suspect a Problem

What to do right now if you think your account has been compromised.

Read what to do »

Why Criminal Groups Target Individual Email Accounts

It is easy to assume that only banks, large companies, or wealthy or famous people are worth attacking. In reality, ordinary individual email accounts are targeted constantly, and often deliberately. Much of this activity is not the work of a lone individual, but of organized criminal groups that treat account theft as a business.

There are several reasons an everyday email account is valuable to these groups:

Your email account is the key to everything else

Think about how many other services are connected to your email address. Online banking, shopping accounts, social media, utility and phone accounts, medical portals, and government services almost all rely on your email address for sign-in, notifications, and — critically — password resets. Whoever controls your email inbox can often request a password reset for those other accounts and receive the reset link directly. This makes email a master key that unlocks far more than email itself.

Attacks are automated and inexpensive

Criminals rarely target one person at a time by hand. They use automated tools to attempt logins against millions of accounts, to send millions of phishing messages, and to test stolen passwords across many services at once. Because the cost of each attempt is almost nothing, attackers do not need a specific reason to target you. Your account is attacked simply because it exists and can be reached.

Stolen passwords are traded in bulk

When any website suffers a data breach, the email addresses and passwords from that site are frequently collected, combined with data from other breaches, and sold or shared among criminals. Because many people reuse the same password in more than one place, a password stolen from one unrelated website is often tried against email accounts, and it works far more often than it should. This technique is known as credential stuffing.

A trusted account is a better weapon

A message coming from a real, established email account — yours — is far more convincing than a message from a stranger. Your account carries a history and a reputation with your contacts and with mail systems around the world. To an attacker, taking over an account you already own and trust is more useful than creating a brand-new fake one.

The takeaway: You do not have to be a high-value target to be attacked. Automated, large-scale attacks treat every account as worth trying, and a normal personal account is genuinely useful to criminals.

What Attackers Hope to Gain by Controlling Your Account

Once criminals gain control of an email account, they have a number of ways to profit from it. Understanding these motives helps explain why account security matters so much, and why Pacific Internet acts quickly when we detect a problem.

Resetting the passwords of your other accounts

As described above, control of your inbox often means control of everything that uses it for password recovery. An attacker may quietly reset the password on a bank, payment, shopping, or investment account, then drain funds or make fraudulent purchases before you notice.

Financial theft and fraud

Attackers search a captured mailbox for anything with financial value: banking messages, invoices, tax documents, saved receipts, gift-card codes, and stored payment details. They may also use your account to redirect a payment you were expecting, or to send a fraudulent invoice to someone who trusts you.

Impersonating you to defraud your contacts

Your friends, family, coworkers, and customers trust messages that come from your address. Attackers exploit that trust by sending urgent requests for money, gift cards, or wire transfers, or by asking your contacts to open a malicious attachment or link. These “help, I’m in trouble” and fake-invoice scams are far more effective when they genuinely come from your real account.

Harvesting personal and identity information

A mailbox is a detailed record of your life: your full name, address, phone number, birth date, employer, family relationships, account numbers, and more. This information can be used to commit identity theft, open accounts in your name, answer security questions, or build a convincing profile for future fraud.

Sending spam, scams, and malware at scale

A working email account is a resource attackers can rent out or use directly to send spam, phishing, and malware to large numbers of people. Because the mail originates from a legitimate account and server, it is more likely to reach inboxes than mail from a known-bad source.

Quietly monitoring you

Not every intrusion is loud. Some attackers set up hidden mail forwarding rules or filters so that copies of your incoming mail are secretly sent to them, or so that security warnings are automatically deleted before you see them. This lets them watch for valuable messages — and stay in control — long after the initial break-in.

Selling the access

Even if an attacker has no immediate use for your account, working access to it is a product. Valid accounts are bought and sold among criminals, so one break-in can lead to many different people misusing your account over time.

The Risks to You If Your Account Is Compromised

The consequences of a compromised email account can extend well beyond a few unwanted messages. Depending on how the account is used, the impact on you can be serious and long-lasting.

Risk What it can mean for you
Financial loss Money taken from bank, payment, or shopping accounts; fraudulent purchases; funds sent by contacts who were tricked into thinking they were helping you.
Loss of other accounts Attackers use your email to reset and seize your banking, social media, shopping, and other logins, sometimes locking you out entirely.
Identity theft Personal details harvested from your mail are used to open credit, file fraudulent claims, or impersonate you elsewhere.
Harm to your contacts Friends, family, and business contacts are scammed or infected with malware by messages that appear to come from you.
Reputation damage People who receive scam or spam mail “from you” may lose trust, and your address may be added to spam blocklists.
Loss of your own data Attackers may delete your mail, contacts, and saved messages, or lock you out of your own history.
Interrupted email service To stop abuse, a compromised account is placed on a temporary security hold — locked until you contact us and secure it (see below). Your mail is preserved throughout.
Compromise is not always obvious. A careful attacker may use your account quietly for weeks. Warning signs include contacts reporting strange messages from you, mail you never sent in your Sent folder, password-reset notices you did not request, mail vanishing from your inbox, or unfamiliar forwarding rules or filters you did not create.

How Pacific Internet Responds to Account Security Incidents

Pacific Internet performs routine security scans and evaluates account activity across our mail systems in order to protect our subscribers, our network, and the reputation of our service. When an account shows signs of compromise, our priority is to stop the abuse quickly, limit the harm to you and to others, and help you regain secure control of your account.

How we detect a problem

An account may be flagged for review when we observe activity that is inconsistent with normal use, such as:

Placing the account on security hold

If our review determines that an account is compromised, we place it on a security hold. This is a protective lock that immediately stops the account from being misused while we work with you to secure it. When an account is on security hold:

Why we lock the account rather than simply watch it. Once there is reason to believe a third party controls an account, allowing it to keep operating — even briefly — is unacceptable. A compromised account can be used to commit fraud, deceive your contacts, and expose your personal information within minutes. A temporary security hold is inconvenient, but it is far safer than letting a compromised account keep running unrestricted.

Restoring your access

Restoring your mailbox is straightforward, and we aim to do it as quickly as possible. To lift a security hold, we work with you to confirm the account is genuinely back in your hands. This generally requires:

Once your password has been changed and your account secured, we promptly restore your normal mailbox — with your existing messages and any mail received during the hold intact. Pacific Internet reserves the right to keep an account on hold if it continues to exhibit suspicious, abusive, or compromised behavior.

How we will — and will not — contact you

If we need to act on your account, we will contact you using the phone number or contact information on file, or through a notice you can verify. We will never ask you to reply with your password, and we will never send you a link demanding that you “verify” your account to avoid suspension. If you receive a message like that claiming to be from Pacific Internet, treat it as a scam and contact us directly using the details at the bottom of this page.

How to Protect Your Account

Most account compromises are preventable. The two things that protect you most are a strong, unique password and a healthy skepticism toward messages that ask you to log in, pay, or act urgently.

Use a strong, unique password

Your password is the single most important lock on your account. A good email password should be:

A simple, strong approach is to combine several random, unrelated words into a passphrase, for example:

correct-harbor-village-lantern purple-otter-canyon-teapot

These are examples only — do not use them. Invent your own, and use a different one for every important account.

Consider a password manager

Remembering a different strong password for every account is difficult, and that difficulty is exactly why people reuse passwords. A reputable password manager creates and stores long, unique passwords for you, so you only need to remember one strong master password. This is one of the most effective single steps most people can take to improve their security.

Recognize phishing and don’t take the bait

The most common way passwords are stolen is not high-tech guessing — it is tricking you into typing your password into a fake login page. Be cautious with any message that pressures you to act:

S
Sender
Check the actual email address, not just the display name. A familiar name can hide an unfamiliar address.
T
Tone
Be wary of urgency, threats, or alarming claims that your account will be closed unless you act now.
O
Offers
Distrust unexpected refunds, prizes, warnings, or anything that seems too good to be true.
P
Phishing
Never enter your password after clicking a link in an unexpected message. Type the known web address yourself.

For a fuller explanation of phishing, spoofed sender names, and fraudulent websites, see our Email Security page.

Everyday habits that keep you safe

Education is protection. The most valuable security tool is an informed, unhurried user. Attackers rely on speed and fear. Slowing down and thinking critically defeats the great majority of attacks.

If You Think Your Account Has Been Compromised

If you notice warning signs — messages you did not send, contacts reporting strange mail from you, password-reset notices you did not request, or missing mail — act promptly:

  1. Change your email password right away to a new, strong password you have never used anywhere else.
  2. Change the password on any other account that shared that password, starting with banking, payment, and important accounts.
  3. Check for unauthorized changes, such as mail forwarding rules, filters, or an altered reply-to address, and remove anything you did not set up.
  4. Review your Sent and Trash folders for messages you did not send, which can tell you and your contacts what the attacker may have done.
  5. Warn your contacts if scam messages may have been sent in your name, so they do not fall for them.
  6. Contact Pacific Internet support so we can help you secure the account and restore any service that was suspended for protection.

Need help securing your account?

Our support team can help you reset your password, check your account settings, and restore access.

Contact Support →

Questions?

If you have questions about protecting your Pacific Internet email account, or you believe your account has been compromised, please contact Pacific Internet support directly at support@pacific.net or (707) 468‑1005.