January 6, 2026

Hacked or Spoofed? When an Email Appears to Have Been Sent From Your Own Address

Hacked or Spoofed? When an Email Appears to Have Been Sent From Your Own Address

Receiving an email that appears to have been sent from your own address can be alarming.

It may suggest that somebody has accessed your account, but that is not always what has happened.

In many cases, the sender address has simply been spoofed. In others, the account may genuinely have been compromised.

Distinguishing between those scenarios matters because the appropriate response can be very different.

A spoofed message may require improved email security and filtering. A genuine compromise may require containment, forensic review, credential changes and investigation into what information was accessed or misused.

What Is Email Spoofing?

Email spoofing occurs when a sender manipulates the information displayed in an email so that it appears to originate from another address.

The visible "From" field can be made to show:

  • Your own email address.
  • A colleague's address.
  • A senior executive.
  • A supplier.
  • A bank or professional adviser.
  • Another trusted organisation.

This does not necessarily mean the genuine email account has been accessed.

It is similar to putting somebody else's return address on an envelope. The information displayed to the recipient may not accurately identify where the message originated.

Spoofing is commonly used in phishing, payment-diversion fraud and other forms of impersonation.

Does an Email From Your Own Address Mean You Have Been Hacked?

No.

The fact that an email appears to come from your own address is not, by itself, proof that somebody has accessed your mailbox.

There are two broad possibilities:

The address has been spoofed.
The attacker has made the message appear to originate from your account without actually logging into it.

The account has been compromised.
An unauthorised person has gained access to the genuine account and may have sent messages, read correspondence or changed settings.

Determining which has occurred requires more than looking at the sender name displayed in the inbox.

How Email Headers Can Help

Every email contains technical information known as headers.

These can record details about how the message travelled between mail systems, including:

  • The servers involved.
  • Authentication results.
  • Sending infrastructure.
  • Message routing.
  • Timestamps.
  • Sender-related information.

Reviewing those headers can help determine whether a message genuinely passed through the organisation's normal email infrastructure or whether the sender information was falsified.

However, headers should be interpreted carefully.

Email systems vary, and individual header fields can be misleading when viewed without the wider technical context.

Where the incident is important, preserving the original message is preferable to relying only on screenshots.

Conflict International's Forensic Digital Investigation Services can support the examination of digital material where it is necessary to understand how an email or other electronic communication was created, transmitted or altered.

Signs an Email Account May Have Been Compromised

A suspicious message becomes more concerning where there are additional indicators of unauthorised access.

These may include:

  • Login notifications from unfamiliar locations or devices.
  • Password-reset messages you did not request.
  • Emails appearing in the sent folder that you did not send.
  • Deleted or moved messages.
  • New forwarding rules.
  • Changes to mailbox settings.
  • Contacts reporting unusual messages from your account.
  • Security settings being altered.
  • Multi-factor authentication prompts you did not initiate.

Attackers may also create mailbox rules designed to hide replies, delete security warnings or automatically forward correspondence elsewhere.

These changes can allow access to continue without the account holder immediately noticing.

Business Email Compromise

Email compromise can become particularly serious in a business environment.

A criminal who gains access to a genuine mailbox may monitor communications until an opportunity arises to manipulate a payment or commercial transaction.

For example, an attacker may:

  • Identify an upcoming supplier payment.
  • Learn how invoices are approved.
  • Monitor a property transaction.
  • Observe correspondence between executives.
  • Wait for a genuine request for funds.
  • Substitute fraudulent bank details.

Because the attacker has access to legitimate correspondence, the resulting message can appear significantly more credible than ordinary phishing.

It may contain genuine names, transaction details, signatures and previous email history.

That is why unusual payment instructions should always be independently verified, even where the email itself appears authentic.

Spoofing Can Also Be Used for Extortion

Some spoofed emails are designed to frighten the recipient rather than steal money through a conventional payment diversion.

A message may appear to come from the victim's own account and claim that:

  • The mailbox has been hacked.
  • The device has been compromised.
  • Sensitive files have been stolen.
  • A camera or microphone has been accessed.
  • Browsing activity has been recorded.
  • Cryptocurrency must be paid to prevent disclosure.

The apparent sender address is then presented as "proof" that the attacker has access.

In many cases, the sender address alone proves nothing.

The threat should still be assessed carefully, but the visible "From" field should not be treated as evidence of compromise.

What to Do If You Receive a Suspicious Email

If you believe an email may indicate compromise, avoid interacting unnecessarily with the message.

Consider the following steps:

  • Preserve the original email.
  • Do not click links or open unexpected attachments.
  • Check recent account activity.
  • Review mailbox forwarding and filtering rules.
  • Change the account password from a trusted device where appropriate.
  • Ensure multi-factor authentication is enabled.
  • Review other accounts using the same or similar credentials.
  • Contact your IT or security provider where the account belongs to an organisation.

If money has already been transferred following a suspicious email, contact the relevant bank or payment provider promptly.

Preserving the original messages, attachments, transaction details and related communications can also assist subsequent enquiries.

Why Screenshots May Not Be Enough

Screenshots can be useful for showing what a recipient saw, but they do not normally preserve all of the technical information contained in the original message.

If the incident could lead to an internal investigation, insurance claim, commercial dispute or legal proceedings, retaining the original email may be important.

Relevant material can include:

  • Original message files.
  • Full email headers.
  • Attachments.
  • Login records.
  • Security alerts.
  • Mailbox rules.
  • Related messages.
  • Device information.

A forensic review may help establish what can and cannot be supported by the available digital material.

It should not be assumed that a single email will provide a definitive answer in every case.

When Cyber Security Support May Be Required

A suspected account compromise may be part of a wider security incident.

Other issues could include:

  • Stolen credentials.
  • Malware.
  • Compromised devices.
  • Phishing.
  • Weak authentication.
  • Reused passwords.
  • Unauthorised access to cloud services.

Where there are signs of an active incident, the immediate priority is usually containment and securing the affected environment.

Conflict International's Cyber Security Services support organisations dealing with cyber incidents, account compromise and wider security concerns.

Digital Evidence and Disputes

Email evidence can also become relevant to commercial disputes, fraud enquiries or internal investigations.

In those situations, the role of digital examination is to establish what the available data supports.

That may involve determining:

  • Whether an email originated from a particular account or system.
  • Whether authentication records indicate unauthorised access.
  • Whether mailbox rules were changed.
  • Whether relevant messages were forwarded or deleted.
  • Whether the timing of digital activity corresponds with other events.

The findings should be reported with appropriate limitations.

Digital examination can assist lawyers and decision-makers, but questions of admissibility, evidential weight and legal interpretation remain matters for the relevant legal process.

Spoofed or Compromised?

An email that appears to have been sent from your own address should be taken seriously, but it should not automatically be interpreted as proof of hacking.

The important question is whether the sender information has simply been falsified or whether an unauthorised person actually gained access to the account.

That distinction can often be clarified through a combination of email-header analysis, account activity, authentication records and other digital evidence.

Conflict International supports businesses, legal teams and private clients dealing with suspected email compromise, spoofing, fraud and related digital incidents.

If you are concerned that an email account or digital system may have been compromised, contact Conflict International for a confidential discussion.

Get a quote today!

Can we help you? Contact us in confidence. We are always happy to help and give you an indication of how we may be able to assist.

Please provide a brief background to your case and the reasons for initiating an investigation.

What is your required outcome? (e.g. Asset Identification, Litigation Support, Due Diligence, or Risk Mitigation).

Please define your relationship to the person or entity of interest (e.g. Legal Counsel, Business Partner, Family Member, or Victim of Fraud).

Please list any specific details you currently possess, such as names, addresses, or any other known details which may assist.

Need our help?
Get a free consultation today.

Get started
© 2026 Conflict International · Privacy Policy · Cookie Policy · Website by ghostwhite