How to Recover Hacked Gmail in 2026
If your Gmail account was hacked, quick action can help you regain access before the attacker changes recovery details or uses your account to target others.
This guide explains how to recover hacked Gmail, what Google looks for during account recovery, and how to lock your account down afterward.
Gmail is tied to Google Account services such as Google Drive, Google Photos, YouTube, and Google Pay, so account compromise can spread beyond email.
The faster you act, the better your chances of recovery.
Signs Your Gmail Account Was Hacked
Before starting recovery, look for clear indicators of unauthorized access.
These signs often appear before a full lockout happens.
- Unexpected password change alerts from Google
- Emails in your Sent folder that you did not write
- Messages marked as read that you never opened
- Inbox forwarding rules you did not create
- Recovery email or phone number changed
- Login alerts from unknown devices or locations
- Spam, phishing, or scam emails sent from your address
If you notice one or more of these symptoms, treat the account as compromised immediately.
What to Do First
Start with the fastest recovery path available.
Do not keep retrying random passwords, because repeated failed attempts can slow the process and may not help if the attacker already changed credentials.
- Go to the Google Account recovery page: accounts.google.com/signin/recovery.
- Enter your Gmail address and click through the prompts.
- Use a trusted device, browser, or location you have used before if possible.
- Check your phone, recovery email, and authenticator app for verification codes.
If you are still signed in on another device, use that session to change your password immediately.
A still-active login often gives you the best chance to regain control before the attacker blocks access.
How to Recover Hacked Gmail Step by Step
1. Use Google Account Recovery
Google’s recovery system is the primary method for restoring access.
It uses signals such as prior passwords, device history, browser cookies, and recovery methods to confirm identity.
- Enter the most recent password you remember.
- Answer account questions as accurately as possible.
- Approve verification prompts sent to your phone or recovery email.
- Follow any additional identity checks Google presents.
Even if you are unsure about the exact password, provide your best answer.
Accurate details increase your chance of passing the recovery process.
2. Check for Recovery Method Changes
Hackers often replace your recovery phone number and email address to prevent you from reclaiming the account.
During recovery, review every prompt carefully and stop if the details no longer belong to you.
If you still have access to the original recovery email or phone, secure those accounts too.
A compromised recovery method can be used to re-enter Gmail later.
3. Use a Trusted Device and Network
Google often gives stronger trust signals to devices and networks you have used in the past.
If possible, attempt recovery from your usual laptop, home Wi-Fi, or mobile device.
Avoid public Wi-Fi, shared computers, or VPNs during recovery unless necessary.
Unfamiliar environments may weaken the trust signals Google relies on.
4. Confirm Identity with Backup Options
Some accounts may allow backup codes, Google prompts, or two-step verification apps such as Google Authenticator, Authy, or similar time-based code generators.
Use any method that is still under your control.
If you enabled passkeys or security keys, try those as well.
Hardware keys from vendors like YubiKey can be especially effective if they were set up before the attack.
What If You Cannot Log In?
If Google recovery does not work right away, continue trying from a familiar device and provide as much accurate account information as possible.
The system may require several attempts before approving access.
Useful details can include:
- Approximate date the account was created
- Previous passwords you remember
- Names of labels or folders you created
- Frequently emailed contacts
- Devices you used to sign in
Do not fabricate information.
Consistency matters more than guessing.
If you no longer have access after multiple attempts, keep monitoring your recovery email and phone for Google instructions.
How to Secure Gmail After Recovery
Once you regain access, assume the attacker may still know something about your account.
The next step is to remove all unauthorized access and close every security gap.
Change Your Password Immediately
Create a strong, unique password that you do not use anywhere else.
A password manager such as 1Password, Bitwarden, or LastPass can help generate and store a high-entropy password.
Avoid reusing old passwords or simple variations, because attackers often test those first.
Sign Out of All Devices
Use the Google Account security page to review connected devices and active sessions.
Sign out of anything you do not recognize, and if needed, sign out of all devices to force a fresh login everywhere.
This step is important because an attacker may still have a valid session cookie even after you change the password.
Remove Suspicious Forwarding and Filters
Check Gmail settings for forwarding addresses, filters, and blocked addresses.
Hackers often add hidden rules to auto-forward messages, delete security alerts, or conceal financial notices.
- Review Forwarding and POP/IMAP settings
- Inspect all Filters and Blocked Addresses
- Delete rules you did not create
- Check delegated access and account sharing settings
Restore Recovery Information
Verify that your recovery phone number and recovery email are correct.
Replace any data the attacker changed, and make sure the recovery methods point to accounts you fully control.
Turn On Two-Step Verification
Two-step verification adds a second layer of protection beyond the password.
Google supports security keys, authenticator apps, prompts, SMS in some cases, and passkeys on supported devices.
For stronger protection, prefer:
- Passkeys or security keys
- Authenticator apps over SMS
- Multiple backup codes stored securely offline
How to Tell If the Attack Spread Beyond Gmail
Many Gmail hacks are really broader Google Account compromises.
Check connected services for unusual activity, payments, or data exposure.
- Google Drive: look for deleted, shared, or downloaded files
- Google Photos: check for unusual sharing or access
- YouTube: review channel changes, subscriptions, or uploads
- Google Pay and Play: inspect transactions and saved payment methods
- Other accounts: reset passwords where Gmail was used for login or password recovery
If Gmail was used as the recovery email for banking, shopping, or social media accounts, update those credentials quickly.
Attackers often pivot from email access to password resets on other platforms.
When to Contact Google Support or Your Organization
If this is a personal Gmail account, Google’s automated recovery is usually the main path.
If the account belongs to a Google Workspace domain, contact your administrator right away.
You should also escalate if:
- The attacker changed the recovery information and you cannot reverse it
- You see unauthorized purchases, subscriptions, or transfers
- Business email, customer data, or sensitive files were exposed
- There is evidence of phishing sent from your address
For business accounts, preserve logs, screenshots, and timestamps so your IT or security team can investigate the incident quickly.
How to Prevent Future Gmail Hacks
After recovery, focus on making repeat compromise much harder.
Strong account hygiene reduces the chance of another breach.
- Use a unique password stored in a password manager
- Enable two-step verification with a security key or authenticator app
- Review security alerts from Google promptly
- Avoid entering Gmail credentials on unfamiliar sites
- Be cautious with phishing emails, fake login pages, and QR code scams
- Keep your browser, operating system, and mobile apps updated
- Audit third-party apps connected to your Google Account
Regularly checking your Google Account security page can reveal weak spots before they become a problem.
A few minutes of review each month can prevent a major account takeover.
Common Mistakes to Avoid During Recovery
Recovery can fail if you make choices that reduce trust or create confusion for Google’s systems.
Avoid these common mistakes:
- Trying recovery from a new device every time
- Guessing wildly at passwords or account details
- Ignoring security alerts in your backup email or phone
- Using public Wi-Fi or shared computers
- Leaving suspicious forwarding rules in place
- Forgetting to secure other accounts tied to Gmail
Staying consistent and acting quickly gives you the best chance to recover hacked Gmail and protect everything connected to it.
What should you do right after recovering a hacked Gmail account?
Change the password, sign out of all devices, remove suspicious forwarding rules, restore recovery details, and enable two-step verification before checking other linked accounts.