What to Do First When Your Google Account Is Hacked
If you are searching for how to recover hacked Google account access, speed matters.
Start by checking whether you can still sign in, then move quickly to recovery and security steps before the attacker changes more settings.
A compromised Google Account can expose Gmail, Google Drive, Google Photos, YouTube, Google Pay, and connected third-party logins.
The goal is to regain control, block the attacker, and confirm that no recovery method or device remains unsafe.
How to Recover a Hacked Google Account
The most reliable path is Google’s account recovery flow.
Use a trusted device and a familiar location if possible, because Google uses device history, location signals, and previous sign-in behavior to verify ownership.
- Go to the Google Account recovery page and enter your Gmail address or phone number.
- Select Forgot password if you still control the account password but suspect unauthorized access.
- If you cannot sign in, follow the prompts to confirm identity using a recovery phone number, recovery email, or device prompt.
- Answer questions as accurately as possible, including the last password you remember.
- Complete verification using the phone or email linked to the account.
If you recently changed the password and no longer recognize recovery details, keep retrying from a device and network you have used before.
Google may deny some attempts if the information does not match, but repeated attempts from a trusted context can improve results.
Signs Your Google Account Has Been Compromised
Knowing the indicators of takeover helps you act before more damage occurs.
Common signs include:
- Password reset emails you did not request
- Messages sent from your Gmail account that you did not write
- Changes to recovery phone number or recovery email
- Unrecognized sign-ins in Google security activity
- New forwarding rules or filters in Gmail
- Files missing from Google Drive or Photos
- Unexpected changes to YouTube channel settings or Google Pay activity
Some attackers also disable notifications or delete emails that mention security alerts.
Review the inbox, spam folder, and trash for missed alerts.
Secure the Account Immediately After Recovery
Once you regain access, assume the attacker may still have a session token, a connected app, or another route back in.
Lock down the account immediately.
Change the password to a new one
Create a strong, unique password that is not used anywhere else.
A password manager such as 1Password, Bitwarden, or Google Password Manager can help generate and store a long, random password.
Turn on two-step verification
Enable two-step verification with an authenticator app or security key rather than relying only on SMS.
Google supports options such as Google Prompt, authenticator apps, and passkeys.
Security keys based on FIDO2 provide strong protection against phishing.
Sign out of all devices
Review the list of devices signed into your account and sign out of anything you do not recognize.
Remove old phones, tablets, laptops, and smart TVs if they are no longer in use.
Check recovery information
Update the recovery phone number and recovery email so the attacker cannot reuse stale information.
Make sure these recovery methods belong only to you.
Inspect Gmail for Attacker Persistence
Hackers often create hidden ways to keep access even after a password reset.
Gmail is especially important because forwarding, filters, and delegated access can silently reroute mail.
- Check Forwarding and POP/IMAP settings for unauthorized forwarding addresses.
- Review Filters and Blocked Addresses for rules that archive, delete, or forward security messages.
- Inspect Mail delegation to make sure no one else can read your mail.
- Look for suspicious labels that hide conversations from the inbox.
Also check sent mail, trash, and archive folders for messages that suggest fraud, phishing, or account abuse.
Review Security Activity and Connected Apps
Google’s security page shows recent sign-ins, devices, and third-party access.
This is where many account compromises are exposed.
- Look for logins from unfamiliar countries, cities, or devices.
- Remove access for apps you no longer trust.
- Revoke OAuth permissions for services you do not recognize.
- Check browser extensions that may have stolen session data or passwords.
Connected apps can be a major risk because they may continue accessing Gmail, Drive, or Calendar even after you change your password.
Remove anything unnecessary, especially productivity tools, mail clients, or extensions you do not use.
Protect Google Drive, Photos, and Other Services
A hacked Google Account often affects more than email.
Review the rest of your Google ecosystem carefully.
Google Drive
Check shared files, recent uploads, and trash.
Attackers may download documents, delete evidence, or share sensitive files with outside accounts.
Google Photos
Review album sharing and linked devices.
If the account was accessed through a synced phone, photos and backups may have been exposed.
YouTube and Google Play
Verify channel ownership, uploads, subscriptions, and payment methods.
Remove unauthorized purchases or app subscriptions if possible.
Google Pay and payment methods
Check cards, bank accounts, and transaction history.
Report suspicious activity to your financial institution immediately if payment data was exposed.
What If You Cannot Recover the Account?
If the attacker changed the password, recovery email, and phone number, use Google’s account recovery process as quickly as possible and keep trying with accurate details.
Recovery success often depends on whether Google can match your behavior, device, and historical information.
If the account is tied to a business, school, or organization, contact the Google Workspace administrator.
Admins may be able to reset access, review login activity, and preserve data.
If you lose access permanently, secure any external accounts that used that Google Account as a login method.
Update those services with a new email address so you do not lose access elsewhere.
How to Tell Whether the Hacker Stole Data
Account recovery is only part of the response.
You also need to assess what the attacker may have viewed, copied, or deleted.
- Check recent Gmail search queries and sent items for signs of reconnaissance.
- Look at Drive sharing activity and file access history where available.
- Review login notifications from financial, shopping, and social media accounts.
- Change passwords on accounts that used Gmail for reset links or two-factor codes.
If you use the same password elsewhere, treat those accounts as compromised too.
Credential reuse is one of the fastest ways attackers move from a single Google Account breach to broader identity theft.
Best Practices to Prevent Another Google Account Hack
Long-term protection matters after you recover access.
These habits reduce the chance of another compromise.
- Use a unique password for every important account.
- Prefer passkeys or an authenticator app over SMS codes.
- Keep recovery email and recovery phone current.
- Use trusted devices and avoid signing in on public computers.
- Watch for phishing emails that mimic Google alerts.
- Regularly review security checkup results in your Google Account.
- Keep your operating system, browser, and antivirus software updated.
Advanced users should also consider security keys, especially for high-value accounts such as business email, creator channels, and cloud storage containing sensitive documents.
When to Contact Additional Support
If you suspect identity theft, unauthorized financial charges, or an active extortion attempt, contact the appropriate support channels immediately.
Your bank, card issuer, mobile carrier, and local authorities may need to be involved depending on what data was exposed.
For organizations, notify IT or security teams so they can invalidate sessions, audit access logs, and protect shared resources.
If Gmail was used for work, a fast coordinated response can reduce downtime and prevent lateral movement to other systems.