Think Your Google Account Was Hacked? Do These Things First
A digital safety action guide to secure your account from a trusted device, remove unauthorized access, and protect linked financial services.
Start Here: 30-Second Immediate Triage
Immediate action before changing complex settings
If you suspect unauthorized access to your Google or Gmail account, act immediately from a personal device you know is clean and trusted.
Quick Diagnostic Checks
Most Likely Causes
Understanding the mechanism prevents guessing and avoids creating new system issues.
Password Reuse Across Breached Websites
Using the same password on multiple websites allows credential-stuffing bots to test breached credentials against your Google account.
Phishing Email or Fake Login Page
Entering your email and password on a deceptive lookalike page that harvested your login credentials and 2-step verification code.
Malicious Browser Extension or Session Hijack
A compromised browser extension or malware stole your active session cookies, bypassing password requirements without logging your credentials.
Unattended Public Computer Session
Failing to log out or uncheck "Remember me" on a shared hotel, school, or library computer.
Third-Party App Permission Abuse
Granting overly broad "Full Google Account Access" to a suspicious third-party mobile app or quiz game.
Signs Your Google Account May Be Compromised
Check these indicators to determine if unauthorized access has occurred:
Step-by-Step Resolution Protocol
Work through these steps in order. Click to check off items as you complete them.
Log In & Change Password Immediately
- From a trusted device, go directly to https://myaccount.google.com/security.
- Under "How you sign in to Google", click Password.
- Create a strong, unique passphrase with at least 16 characters (e.g. 4 random words combined with numbers/symbols).
- Do NOT reuse this password on any other service or platform.
If Locked Out: Use Official Google Account Recovery
- Navigate directly to https://accounts.google.com/signin/recovery in your browser.
- Perform this step on a device (phone/computer) and Wi-Fi network you have frequently used in the past.
- Answer all security verification questions as accurately as possible.
- If prompted, check your backup email or SMS code on your registered phone.
Terminate All Unknown Devices & Active Sessions
- Go to https://myaccount.google.com/device-activity.
- Review the list of devices where your account is currently signed in.
- Click on any unfamiliar phone, tablet, computer, or unexpected geographical location > click "Sign out".
- This invalidates all active session tokens on the attacker's hardware.
Verify Recovery Email & Phone Number
- In Google Security settings, check "Recovery phone" and "Recovery email".
- Confirm that the phone number and recovery address belong to you.
- If an unfamiliar phone number or email address was added by the attacker, delete it immediately and add your correct details.
Strengthen 2-Step Verification (2FA)
- Go to https://myaccount.google.com/signinoptions/two-step-verification.
- Enable Google Authenticator app or Google Prompts (push notifications to your trusted phone).
- Generate and print 10 "Backup codes" and store them in a secure physical location (these let you log in if you lose your phone).
Inspect Gmail Forwarding & Filter Rules
- Open Gmail on a computer > click the gear icon (Settings) > "See all settings".
- Go to the "Forwarding and POP/IMAP" tab: verify no unauthorized email address is set to receive your incoming mail.
- Go to the "Filters and Blocked Addresses" tab: attackers often create filters that automatically delete emails with words like "bank", "statement", "verification", or "password reset" so you do not see security alerts.
Revoke Suspicious Third-Party App Permissions
- Go to https://myaccount.google.com/data-and-privacy > scroll down to "Apps and services" > "Third-party apps & services".
- Review all connected apps and web tools that have access to your Google account.
- Remove access for any service you do not recognize or no longer use.
Secure Other Accounts Reusing the Same Password
- Immediately change the passwords for critical accounts: Bank/Credit cards, PayPal, Amazon, Apple ID, Social Media, and your Password Manager.
- Check Google Pay (https://pay.google.com) to verify no unauthorized purchases or subscriptions were made with saved payment methods.
Understanding Account Security Status
Evidence Preservation & Final Safeguards
Safe escalation pathways
If you need to document the breach for banking or legal purposes:
- 1Take screenshots of unrecognized device sessions and IP addresses in myaccount.google.com/device-activity before signing them out.
- 2Keep records of any Google security notification emails received.
- 3Contact your financial institutions to place temporary fraud alerts on your credit reports if identity documents were stored in Google Drive.
Digital Safety Rules: When to Stop
Use the Interactive 10-Step Tech Fixer
Prefer an interactive checklist with real-time step trackers? Launch the full FixTheDay Tech Fixer for this issue.
Authoritative & Official Sources
Verified, non-commercial documentation and government safety guidance
Official automated recovery flow for Google and Gmail accounts.
Inspect active devices, 2FA settings, and third-party app permissions.
Official US government reporting and recovery resource for identity theft.