If your ex hacked your email, yes, you can press charges. Unauthorized access to someone else’s email is a federal crime under the Computer Fraud and Abuse Act and, depending on how the access happened, the Electronic Communications Privacy Act as well. A first offense can carry up to five years in prison when the access was tied to financial gain or another crime, and you have a separate right to sue your ex directly for money damages and a court order to stay out of your accounts. What you do in the first day or two determines how much of that is actually available to you.
Preserve the Evidence Before You Change a Thing
The instinct after finding out your ex was in your email is to change the password immediately and delete whatever they touched. Don’t. That instinct wipes out the digital trail that police, prosecutors, and a civil judge would need to tie the intrusion to your ex specifically.
Open your email provider’s recent login activity first. Gmail, Outlook, and the other major providers show sign-in locations, IP addresses, and timestamps. Screenshot or export that log before you touch anything else. Some providers overwrite session history once you reset the password, so this record can disappear the moment you try to secure the account. Logins from your ex’s home, their phone, or their workplace are exactly the kind of evidence that turns a suspicion into a case.
Save the full headers of any suspicious messages sent from your account or received during the period you think they had access. Headers contain routing information and originating IP addresses a forensic analyst can trace. Most email clients expose headers through the message options menu. Save them as text files, not just screenshots, because courts prefer data in its native form.
Check for forwarding rules, filters, and recovery addresses your ex may have added, and do not delete them yet. Those settings are evidence of how they kept access and what they were siphoning off. Screenshot each one, then disable it. Only after you have documented the breach thoroughly should you change your password, turn on two-factor authentication, and revoke access from any device you don’t recognize.
Where to Report It
Pressing charges means getting the report in front of an agency that can actually investigate and prosecute. There are three places to file, and each does something different.
The FBI’s Internet Crime Complaint Center
The Internet Crime Complaint Center, IC3, is the FBI’s central portal for cybercrime reports. You submit the complaint at ic3.gov with a description of the breach, the evidence you preserved, and any financial losses.1Internet Crime Complaint Center. Home – Internet Crime Complaint Center IC3 analysts review complaints, look for patterns, and refer cases to the appropriate FBI field office or other agency.
Be realistic. The FBI prioritizes cybercrime cases with large financial losses or organized activity, and a single hacked personal account may not trigger a full investigation on its own. The report still matters. It creates an official federal record of the intrusion on the date you filed it, and that record supports everything else you might do later.
Your Local Police
File a report with your local police department too. This is the report banks, creditors, and credit bureaus tend to ask for when you dispute fraudulent activity. Some departments have officers trained in cybercrime; many will take the report and hand the technical work to state or federal agencies. Either way, get the report number and keep a copy. When the suspect is someone you know and can name, local police can act on that in ways federal agencies rarely will for a single-victim case.
The FTC If Identity Theft Followed
If your ex used what they found in your email to open accounts, make purchases, or otherwise impersonate you, file at IdentityTheft.gov. The site walks you through a recovery plan and generates an official Identity Theft Report that carries legal weight under the Fair Credit Reporting Act, unlocking extended fraud alerts, the ability to block fraudulent accounts from your credit report, and the right to obtain records from companies the thief used.2Office for Victims of Crime. Statement of Rights for Identity Theft Victims
What Federal Law Says Your Ex Did
Two federal statutes are doing the work in a case like yours.
The Computer Fraud and Abuse Act
The CFAA makes it illegal to access a computer without authorization or to exceed the access you were given.3Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection with Computers Breaking into your email fits squarely inside it. A simple unauthorized access on a first offense can bring up to a year in prison; access tied to financial gain or in furtherance of another crime raises the ceiling to five years; intentional damage to data can push it to ten. Repeat offenders face doubled maximum sentences.
There is one wrinkle that matters more in ex-partner cases than almost anywhere else. In 2021 the Supreme Court ruled in Van Buren v. United States that a person “exceeds authorized access” only when they reach into areas of a system that are off-limits to them, not when they use legitimately accessible information for an improper purpose.4Supreme Court of the United States. Van Buren v. United States, 593 U.S. 374 (2021) For most email hacking, that doesn’t change anything. But if your ex logged in using a password you gave them during the relationship and never explicitly revoked, expect the defense to argue authorization was ambiguous. Revoking access clearly, in writing where possible, and documenting when you did it, cuts that argument off.
The Electronic Communications Privacy Act
The ECPA makes it a federal crime to intentionally intercept electronic communications, including emails, without authorization.5Office of the Law Revision Counsel. 18 USC 2511 – Interception and Disclosure of Wire, Oral, or Electronic Communications Prohibited If your ex set up a forwarding rule that quietly copied your incoming mail to their inbox, that’s the ongoing interception the ECPA targets. It also opens a separate civil door that’s often more useful to individual victims than the CFAA.
Suing Your Ex Yourself
Criminal charges are the government’s decision. A civil suit is yours, and you can bring one even if prosecutors decline the case.
The CFAA lets any person who suffered damage or loss from a violation sue for compensatory damages and a court order.3Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection with Computers There’s a catch: you generally need to show at least $5,000 in loss over a one-year period, or one of the other qualifying harms like modified medical records or physical injury. The $5,000 figure isn’t just money your ex stole. It includes what you spent responding — forensic help, time securing accounts, lost business income, legal costs. If the only qualifying harm is money, though, you can’t recover for emotional distress under the CFAA.
The ECPA’s civil remedy is friendlier for the smaller, more personal case. It sets a statutory minimum of $1,000 in damages even when actual losses are hard to pin down, allows punitive damages for willful violations, and lets a court order the defendant to pay your attorney’s fees.6Office of the Law Revision Counsel. 18 USC 2707 – Civil Action If the violation was more privacy invasion than financial theft — reading your messages, forwarding them to themselves, sharing them with others — the ECPA is probably where the stronger claim lives.
Beyond money, courts can issue injunctive relief: an order prohibiting your ex from accessing your accounts, requiring them to destroy any data they took, and in some cases barring further contact through electronic means. When the person who hacked you is an ex, that order is often the most valuable thing a lawsuit produces, because the same person is likely to try again.
How Long You Have to Act
Both criminal and civil paths have hard deadlines.
Federal prosecutors generally have five years from the date of the offense to bring charges for a cybercrime.7Office of the Law Revision Counsel. 18 USC 3282 – Offenses Not Capital The clock runs from the hack, not from the day you found out.
A civil suit under the CFAA has to be filed within two years, but the two-year clock runs from either the hack itself or the date you discovered the damage, whichever is later.3Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection with Computers That discovery rule matters, because plenty of people don’t learn their ex was in their email until months after it started. Once you know, though, two years goes fast when you factor in investigation, evidence gathering, and finding a lawyer who handles these cases.
Lock Down the Fallout
Your email is the recovery address for your bank, your investment accounts, your social profiles, and your medical portals. Anyone inside it can reset passwords to everything connected to it. Even if the criminal case is months or years away, these steps limit what your ex can still do with what they took.
Place a credit freeze with all three major credit bureaus. Under federal law, the bureaus must place the freeze for free within one business day of an online or phone request, and lift it within one hour when you ask.8Office of the Law Revision Counsel. 15 USC 1681c-1 – Identity Theft Prevention; Fraud Alerts and Active Duty Alerts A freeze has no expiration and blocks new credit accounts from being opened in your name. It’s the single most effective step against your ex turning stolen personal information into new debt.
Add a fraud alert. An initial 90-day alert tells creditors to verify identity before issuing credit and gets you a free credit report from each bureau. Once you have an Identity Theft Report from IdentityTheft.gov or law enforcement, you can extend the alert to seven years and get two free credit reports per bureau per year.2Office for Victims of Crime. Statement of Rights for Identity Theft Victims
Know the liability caps and the deadlines that come with them. Fraudulent credit card charges: liability capped at $50 if you notify the issuer within 60 days of the statement showing the charges. A lost or stolen debit card: $50 cap if you notify the bank within two business days of discovering the loss. Electronic withdrawals made without physically stealing the card: nothing owed, provided you notify the bank within 60 days of the statement date.2Office for Victims of Crime. Statement of Rights for Identity Theft Victims Miss those windows and what you owe can jump sharply.
If Your Ex Used Your Identity, the Stakes Go Up
An ex who broke into your email and then used what they found to impersonate you faces a separate federal charge with real teeth. Under the aggravated identity theft statute, anyone who uses another person’s identifying information during and in connection with a federal felony gets a mandatory two-year prison sentence added on top of the sentence for the underlying crime.9Office of the Law Revision Counsel. 18 USC 1028A – Aggravated Identity Theft It runs consecutively, so a judge can’t fold it into the other sentence. That mandatory add-on shows up in plea negotiations and gives prosecutors significant leverage, which is worth knowing when you’re deciding how forcefully to push for charges and how much detail to put in your reports.