What to do first after a Google account hack
If you are trying to figure out how to secure Google account after being hacked, speed matters.
The first goal is to stop further access, confirm what changed, and begin recovery before the attacker can lock you out completely.
Start from a trusted device and trusted network if possible.
Avoid using a public computer or shared Wi-Fi while you are changing passwords and reviewing account activity.
Immediate actions to take
- Change your Google Account password right away if you still have access.
- Use Google’s Account Recovery page if you can no longer sign in.
- Review recent security alerts from Google and any recovery emails or phone messages.
- Check whether your recovery email, recovery phone, or backup codes were changed.
- Sign out of unknown devices and sessions as soon as you regain access.
How to recover access to the account
Google’s account recovery flow is designed to verify that you are the legitimate owner using signals such as your password history, recovery options, device familiarity, and location.
The more accurate information you provide, the better your chance of regaining control.
Go to Google’s Account Recovery page and follow the prompts carefully.
Enter the most recent password you remember, even if you are unsure it is correct, because prior passwords can help verify ownership.
Information Google may ask for
- Previous passwords
- Recovery email address
- Recovery phone number
- Approximate account creation date
- Verification codes sent to trusted devices
If the attacker changed your recovery details, continue trying from a device and location you have used before.
Google often uses device recognition and sign-in patterns to evaluate the request.
Review the account for unauthorized changes
Once you regain access, assume the account was altered beyond the password.
Attackers often change settings to maintain access, intercept communications, or use the account for phishing.
Check account details immediately
- Recovery email and recovery phone number
- Password and two-step verification settings
- Connected third-party apps and extensions
- Device list under Google Account security settings
- Forwarding rules and filters in Gmail
- Delegated access or account sharing settings
In Gmail, look for suspicious forwarding addresses, hidden filters that archive security emails, and any changes to the signature or out-of-office reply.
These are common persistence methods after compromise.
Remove unauthorized devices and sessions
Attackers may stay signed in on devices even after you change the password.
Google lets you review active sessions and sign out of devices you do not recognize.
Open the Security section of your Google Account and check every device listed.
Remove anything unfamiliar, including old phones, browsers, tablets, or virtual machines you did not use.
Why this matters
Ending sessions helps cut off token-based access, which can continue even after a password change.
This is a critical step in securing a Google account after it has been hacked.
Change your password the right way
Use a strong, unique password that has never been used on any other site.
A password manager such as Google Password Manager, 1Password, or Bitwarden can generate and store a secure password for you.
Strong password guidelines
- At least 12 to 16 characters
- Mix of letters, numbers, and symbols
- No names, birthdays, or reused phrases
- Unique across every major account
If your email password was reused anywhere else, change those accounts too.
Credential stuffing is one of the most common ways attackers move from one service to another.
Turn on stronger two-step verification
Two-step verification adds a second layer of protection, making it harder for someone to log in even if they know your password.
For higher security, use passkeys or a hardware security key rather than SMS alone.
Best options for Google account protection
- Passkeys on a trusted phone or device
- Hardware security keys such as YubiKey or Titan Security Key
- Authenticator apps like Google Authenticator or Authy
- Google prompts on a secured mobile device
SMS codes are better than nothing, but they can be vulnerable to SIM swapping or phone-number takeover.
If available, use a stronger method tied to a physical device.
Audit Gmail for misuse and hidden access
If the hacker had access to Gmail, they may have used it to reset passwords on other services, forward messages, or impersonate you.
Search for signs of tampering in sent mail, trash, archived folders, and settings.
Look for these warning signs
- Messages you did not send
- Deleted security emails from banks or platforms
- New email filters you did not create
- Forwarding rules sending mail to unknown addresses
- Signatures or labels that were added without your knowledge
Also review your Google Account’s third-party access.
Remove any apps you do not recognize, especially mail clients, browser extensions, or automation tools.
Protect other accounts that may be affected
A compromised Google account can expose other services linked to that email address.
Focus first on financial, communication, and identity-related accounts.
Accounts to secure next
- Banking and credit card logins
- Social media accounts
- Apple ID, Microsoft account, and cloud storage
- E-commerce accounts
- Work or school services connected to the email
Change passwords on those services, update recovery email addresses, and enable two-factor authentication wherever possible.
If you receive suspicious password reset emails, treat them as an indicator that the attacker is still probing your identity.
Scan your devices for malware or browser hijackers
Account compromise can happen after a device infection.
Keyloggers, browser extensions, and phishing kits may capture sign-ins even after you clean up the account.
Run a full scan with reputable security software on every device used to access Google.
Remove unknown browser extensions, update the operating system, and install the latest browser patches.
Device hygiene checklist
- Update Chrome, Firefox, Safari, or Edge
- Remove suspicious extensions and apps
- Check for remote-access software you did not install
- Restart devices after cleanup
- Use antivirus or endpoint protection scans
Set up alerts and recovery safeguards
Once your account is stable, configure alerts so you are notified about future changes.
Google security alerts can help you catch suspicious sign-ins early.
Make sure your recovery email and phone number are current and controlled by you.
Save backup codes in a safe offline location, such as a locked drawer or password manager vault.
Recommended long-term safeguards
- Keep recovery information current
- Use passkeys or a hardware security key
- Review Security Checkup regularly
- Store backup codes securely
- Avoid signing in on shared or untrusted devices
When to contact Google support and additional help
If you cannot recover the account through Google’s automated process, keep trying from familiar devices and review the help pages for account recovery.
In some cases, especially with Workspace accounts, a domain administrator or employer IT team can help restore access.
If financial accounts, identity records, or sensitive personal data were exposed, notify the relevant institutions quickly.
For severe cases involving fraud or identity theft, document the incident, save screenshots, and consider filing a report with local authorities or consumer protection agencies.
How to secure Google account after being hacked without missing critical steps
The most effective recovery plan is to regain access, remove all attacker controls, change the password, strengthen two-step verification, and review every connected account and device.
Taking these steps in order gives you the best chance of fully securing the account and preventing repeat compromise.