You open your email and see a person you trust, like your boss or a co-worker. The email looks normal, but at the bottom, their signature has a link that says something like "Click for shared files" or "Update your profile." If you hover over that link, the address looks wrong – maybe it says http://bad-site.com/update instead of something like dropbox.com. This is not a accident. Someone changed their email signature to make you click on a malicious link.
This happens when a hacker gets into the email account of that person. They don't send spam from the inbox. They change the signature in the settings. The email goes out to everyone the person writes to, and anyone who clicks ends up on a phishing site or downloads malware.
The root cause is simple: the email account password was weak, or the user clicked a fake login link before. The hacker uses that access to edit the signature. They don't mess with other stuff right away, so the person doesn't notice until someone clicks the bad link.
What You Need to Fix It
- Access to the email account settings (webmail or Outlook).
- A strong new password you haven't used before.
- Two-factor authentication (2FA) turned on after you're done.
- About 15 minutes of your time.
Step-by-Step Fix
Step 1: Log Into Email Account Through Webmail
Open a browser. Go to your email provider's website (Outlook.com, Gmail, or your company's webmail). Log in with your normal username and password. Do not do this from a link in an email.
After you log in, you should see your inbox. If you can't log in, your password might already be changed. Contact your IT person.
Step 2: Go to Signature Settings
Each email service is a little different. Here's where to look:
- Outlook.com (personal): Click the gear icon (Settings) at the top right. Choose "View all Outlook settings" at the bottom. Then go to "Mail" > "Compose and reply."
- Gmail: Click the gear icon. Choose "See all settings." Scroll down to the "Signature" section.
- Outlook desktop (Exchange): Open Outlook. Click "File" > "Options" > "Mail." Then click "Signatures" under "Compose messages."
- Company webmail (like cPanel): Look for "Email" or "Signature" in the settings menu.
Once you're there, you'll see the signature box. Look for any link that doesn't belong. It might be a short link like bit.ly/xyz123 or a weird URL with numbers. The usual stuff – your name, phone number, job title – should still be there.
Step 3: Remove the Bad Link
Select the entire signature text. Highlight everything. Delete it all. Do not try to edit just the link – the hacker might have hidden it in the HTML. Wipe it clean.
Then type your real signature again. Just your name, title, phone number, and maybe your company website. Do not paste any links from a file or email. Type them manually.
If you use a signature template, rebuild it from scratch. Do not copy from a saved file – that file might also be infected.
Step 4: Save the Changes
Click "Save" or "OK" at the bottom of the settings page. The exact button depends on your email provider. After you click it, go back to your inbox and send a test email to yourself. Open it and check the signature. You should see only your clean signature with no hidden links.
Step 5: Change Your Password Right Now
Do not wait. Go to your account security settings and change the password. Use a password that is at least 12 characters long with a mix of letters, numbers, and symbols. Do not reuse a password from any other account.
After you change it, you'll be logged out of all devices. That kicks the hacker out too.
Step 6: Turn On Two-Factor Authentication (2FA)
Go back to security settings and enable 2FA. Use an authenticator app like Google Authenticator or Microsoft Authenticator. Do not use SMS if you can avoid it – SMS can be intercepted. With 2FA, even if someone gets your password, they can't log in without your phone.
What to Check If It Still Fails
If the bad link comes back after you fix it, here's what's probably happening:
- Another device is still logged in: An old phone or work computer might still have the hacker's session. Go to your account settings and click "Sign out of all sessions" or "Log out of all devices." Then change your password again.
- A recovery email or phone is still compromised: Check your account recovery options. If the hacker changed your backup email or phone number, they can reset your password anytime. Remove any unknown email or phone from recovery settings.
- Third-party app has too much access: In Gmail or Outlook, go to "Connected apps" or "App permissions." Remove any apps you don't recognize. Hackers sometimes use these to keep access.
- The problem is not just yours: If you're the one getting emails with bad signatures from others, tell them to follow these steps too. The whole company might be targeted.
If none of that works, contact your IT department or email provider support. They can see login logs and find where the hacker is coming from.
One more thing: after you fix your signature, warn your contacts. Send a quick email saying "My signature had a bad link – don't click anything from my old emails." This stops the chain.