What to do first after a phishing attack
If you need to know how to recover Google account after phishing attack, the first few minutes matter.
The goal is to stop further damage, regain access, and prevent the attacker from locking you out again.
Phishing can expose your password, recovery email, phone number, Gmail, Google Drive files, and even connected services like YouTube, Google Photos, and Chrome sync.
Acting quickly improves your chances of a full recovery.
Recognize the signs of a compromised Google account
Before you start recovery, confirm that the issue is truly a phishing compromise.
Common warning signs include:
- Security alerts from Google about a suspicious sign-in
- Password changes you did not make
- Unknown devices in your Google account activity
- Emails sent from your Gmail account without your knowledge
- Recovery options changed to unfamiliar phone numbers or email addresses
- Missing files, deleted emails, or changed settings
Google may also notify you through a recovery email, a trusted device, or an in-product security alert.
If you still have access to any trusted device, use it immediately for account recovery.
How to recover Google account after phishing attack
The main recovery path is Google’s official account recovery process.
Use a device, browser, and location you have used before if possible, because Google’s systems use signals like device familiarity and login history.
1. Go to the Google Account Recovery page
Visit the official recovery page and select the option that best matches your situation, such as forgotten password or unable to sign in.
Enter your Gmail address or phone number linked to the account.
2. Answer verification prompts accurately
Google may ask for your last remembered password, a code sent to a recovery phone number, a code sent to a recovery email, or a prompt on a signed-in device.
Use exact information when possible, including older passwords you remember, because prior password history can help prove ownership.
3. Use a trusted device and familiar network
If you signed in from a laptop, phone, or home network before, recover from that same environment.
A trusted device with saved Chrome data or a known IP address can improve verification success.
4. Follow the account recovery flow without delays
Google may limit repeated attempts in a short time.
If you fail once, wait and try again from a trusted device rather than making many fast attempts, which can reduce confidence in your identity.
5. Reset your password immediately
Once access is restored, create a strong new password that is unique and not reused anywhere else.
A password manager such as Google Password Manager, 1Password, Bitwarden, or Dashlane can help generate and store strong credentials safely.
Secure the account right after recovery
Recovering access is only the first step.
You also need to remove the attacker’s foothold and close any security gaps they used.
- Change the Google password again if you suspect the attacker already saw it
- Review and update recovery email and recovery phone number
- Sign out of all devices you do not recognize
- Turn on 2-Step Verification or passkeys
- Check Gmail filters, forwarding rules, and delegated access
- Review third-party app access in your Google Account
In Gmail, phishing attackers often create filters that automatically forward, delete, archive, or hide incoming mail.
Look carefully for rules you did not create, especially ones involving banking, password reset, or security alert messages.
Check for suspicious activity in connected Google services
A compromised Google account can affect more than email.
Review the security and data for Google services linked to the same identity.
Gmail
Check sent mail, trash, archived messages, filters, forwarding settings, and recovery settings.
Look for evidence that the attacker used your inbox to send phishing messages to contacts.
Google Drive
Inspect shared folders, deleted files, and access permissions.
If business or school documents were exposed, note which files may contain personal or financial data.
Google Photos
Review shared albums and recent uploads.
Attackers may use personal content to help with impersonation or social engineering.
Chrome and synced data
If Chrome sync was enabled, review saved passwords, bookmarks, extensions, and browsing history.
Remove suspicious extensions and reset sync if needed.
Report the phishing attack and preserve evidence
Reporting helps reduce future attacks and supports any identity theft or fraud investigation.
Save screenshots, message headers, sender addresses, login notifications, and any URLs involved in the scam.
- Report the phishing email in Gmail as phishing
- Forward suspicious messages to your organization’s IT or security team if applicable
- Report financial fraud to your bank or card issuer if payment data was exposed
- Change passwords for any other accounts that used the same or similar password
If the attacker accessed sensitive business or customer data, your company may need to follow incident response, privacy, or compliance procedures under frameworks such as NIST guidance, ISO 27001 controls, or internal security policy.
Strengthen your Google account against future phishing
Phishing campaigns continue to target Gmail users because Google accounts are high-value targets.
Strong preventative controls lower the odds of a second compromise.
Use passkeys or 2-Step Verification
Passkeys reduce reliance on passwords and are resistant to many phishing attacks.
If passkeys are unavailable for your setup, enable 2-Step Verification with an authenticator app or security key instead of relying only on SMS.
Review recovery options regularly
Keep recovery email and phone details current.
Remove old numbers, inactive inboxes, or shared family addresses that no longer belong to you.
Watch for realistic phishing tactics
Modern phishing often mimics Google login pages, security alerts, file-sharing notices, or account verification emails.
Always inspect the sender address, hover over links, and navigate directly to Google rather than clicking embedded login buttons.
Limit app and browser exposure
Only install trusted browser extensions and apps.
Periodically audit third-party access in your Google Account and remove any service you no longer use.
When you should contact Google support or your organization
Some recovery cases require extra help.
Contact Google support pathways if you cannot pass account verification, if your recovery options were changed, or if your account is tied to a business identity with administrative controls.
If you use Google Workspace, contact your administrator immediately.
Workspace admins may be able to reset credentials, revoke sessions, review logs, and restore access faster than consumer recovery methods.
What to remember during the recovery process
The most important parts of how to recover Google account after phishing attack are speed, accurate verification, and immediate hardening after you regain access.
Use trusted devices, preserve evidence, and secure every recovery path so the attacker cannot return.
By treating account recovery as both a restoration and a security reset, you reduce the risk of repeat compromise and protect the rest of your digital identity.