Hacked Gmail Account: How to Recover It Step by Step

How do you recover a hacked Gmail account?
To recover a hacked Gmail account, you use Google's official account recovery flow to regain access, then remove whatever the attacker left behind. You change the password, sign out every device, turn on 2-Step Verification, and delete hidden forwarding rules. Google's recovery help page is the only place to start.
This guide follows the order a locked-out user should work through. We are a digital marketing and web team, not Google, and we do not offer Gmail recovery services. Also, for every claim about Google's tools, we relied on Google's own Help and security pages.
Menu names change as Google updates its interface. If you cannot find a setting, search for its name in the Google Account search box. In practice, the labels we quote may look slightly different on your screen.
What are the signs of a hacked Gmail account?
Google's security help page lists typical warning signs. One sign alone does not prove a break-in. Two or three together should push you to act right away.
- Your recovery phone, recovery email, account name, or 2-Step Verification settings changed, and you did not change them.
- Your Sent folder shows messages you never wrote, or friends tell you they received spam from your address.
- Emails have disappeared from your inbox.
- You see unfamiliar purchases in Google Pay or the Play Store.
- Your device list shows a device you do not recognize.
- A YouTube video you never uploaded appears, Drive files vanish, or a Photos album gets shared.
For example, if a colleague says "why did you send me that odd link?", open your Sent folder first. Also, a message you did not write there is a strong hint that someone else controls the account.
Gmail also helps. Then, at the bottom of the inbox, the "Last account activity" link shows recent sign-ins with time and device type. Also, if you see a sign-in you do not know, you can sign out the other sessions from the same screen.
In what order should you act in the first few minutes?
Order matters in a panic. First you regain access, then you close the attacker's lasting paths. After that, you protect your other accounts. If you reverse the order, the attacker may see your new password and walk back in.
- Open Google's recovery page from a device and browser you normally use.
- If you can sign in, change the password and sign out all sessions.
- Turn on 2-Step Verification and add a passkey if you can.
- Check Gmail forwarding, filters, and delegation settings.
- Review third-party apps that can access your account.
- Change the password on every account that shared the old one.
- Warn your contacts.
We unpack each step below. Your own device may also be infected, so change the password from a clean, updated device whenever possible.
How does Google's recovery flow work when you cannot sign in?
When your password no longer works, the recovery flow takes over. Google tries to confirm the account is yours by asking a few questions. These can touch your password, your recovery details, and roughly when you created the account.
You reach the flow through Google's account recovery help page. A verification code may arrive at your recovery email or phone. In practice, type that code only into Google's own screen.
If you are unsure which account was hacked, Google also offers a way to recover your username. Also, if you own several Gmail addresses, if you own several Gmail addresses, try each one separately.
Stay on one browser tab throughout and check that the address belongs to Google. In practice, look for the padlock and the correct domain. In practice, that simple check protects you from fake recovery pages.
Also avoid shared computers and public networks for this job. Then, recover the account only from a device you trust and keep updated.
What improves your chances of Gmail account recovery?
Google's tips for completing recovery are specific. Most of them are signals that prove you are the real owner. The more familiar the signals look, the better your odds.
| Tip | Why it helps |
|---|---|
| --- | --- |
| Use a device you often sign in from | Google has seen that device before |
| Try from a place you usually sign in, such as home or work | A familiar location builds trust |
| Use your usual browser | The browser details match |
| Enter the most recent password you remember | Older passwords can also count as a signal |
| Do not skip questions, guess instead | A blank answer gives Google nothing |
| Provide recovery emails and phone numbers | They match records tied to the account |
If the code email does not arrive, check your spam folder. According to Google's help page, Google never asks for your password or verification codes by email, phone call, or message.
What if the attacker changed your recovery details?
Attackers often swap your recovery phone and email for their own. Then the codes go to them when you try to recover the account. That makes recovery harder, but not impossible.
Stay calm and apply the same tips more carefully. Try again from a device and location Google knows. Also, answer every question, even with a best guess. Next, Google may sometimes ask you to wait a few days or try again later. In practice, that delay is normal and exists for security.
If your attempts fail, the official recovery page offers other options. Google's help also suggests creating a replacement account and reviewing your security habits if recovery fails. Do not rush to websites that promise guaranteed recovery. In practice, we return to that risk below.
What should you do first once you are back in?
Do not close the tab and relax once you sign in. The attacker may still hold an open session. Work through these steps.
- Set a new, long, unique password.
- In your Google Account, open the security section ("Security & sign-in") and review recent security events.
- Under "Your devices", sign out of any device you do not recognize.
- Check your recovery phone and recovery email, and remove anything that is not yours.
Changing the password may not sign out every device automatically. Put simply, that is why you sign out manually from the device list. If you skip this, an old session can stay alive.
If you struggle to invent a strong password, our password generator creates a long random one. Next, store the result in a password manager.
How do you set up 2-Step Verification and a passkey?
A password alone is not enough. Google's security page recommends turning on 2-Step Verification and considering passkeys. With 2-Step Verification, signing in needs your password plus a second proof, such as your phone or a security key.
To set it up, open the security section of your Google Account and turn on "2-Step Verification". Next, follow the on-screen prompts. Add a backup method, or you could lock yourself out again after losing your phone.
A passkey replaces the password with your device's screen lock. It is hard to hand over on a fake page. Then, even so, make sure your own device is clean before you create one. Menu names vary by version, so the quickest route is to search "passkey" in the Google Account search box.
Printing backup codes and storing them somewhere safe is also smart. Likewise, do not keep them as plain text in your email or cloud storage.
SMS codes are better than nothing. Still, security keys and passkeys resist phishing better. Likewise, for accounts that hold money or business data, choose the strongest method available.
What does Google's Security Checkup show you?
Security Checkup is Google's tool that lists the risks on your account in one place. Google recommends running it after recovery. You can open it directly at myaccount.google.com/security-checkup.
You will usually see these items.
- Devices and sessions connected to your account.
- Whether your recovery details are current.
- Third-party apps with access to your account.
- Warnings about saved passwords.
The suggestions may differ by version. Also, read each one anyway. Put simply, if you skip a warning by accident, an attacker's access might stay open.
Which hidden Gmail settings might the attacker have left behind?
Getting the account back is not enough. Attackers often leave themselves a quiet window. Google's help page names three Gmail settings in particular: mail delegation, automatic forwarding, and filters.
| Setting | What an attacker does | Where to look |
|---|---|---|
| --- | --- | --- |
| Automatic forwarding | Sends a copy of your incoming mail to their address | Settings, See all settings, Forwarding and POP/IMAP |
| Filters | Creates rules that delete or label security alerts | Settings, Filters and Blocked Addresses |
| Account access for others | Adds another person as a delegate | Settings, Accounts and Import |
Delete every entry you do not recognize. In practice, watch for filters that delete mail from your bank or contain the word "security". A filter might also hide password reset emails without you noticing.
For more on how forwarding works, read our guide on setting up email forwarding. Also review your labels and blocked address list.
Check your signature and vacation reply as well. Attackers sometimes add their own links to a signature or use an auto reply to reach your contacts. Then, after the review, send yourself a test email from another address and confirm it arrives.
How do you clean up connected apps and third-party access?
When you choose "Sign in with Google" on an app, you give it access to parts of your account. An attacker may have used a fake app to get that permission. Some permissions can survive a password change.
Google's page calls this list "Apps with access to your account". Also, open it and remove access for apps you do not recognize, no longer use, or that ask for more than they need.
If you use Chrome, remove extensions you do not recognize. Google's help page specifically reminds you of this. Also check sharing permissions in Drive and Photos. Next, if a folder is shared with someone you do not know, turn the sharing off.
Removing an app's access does not break the app. You can grant access again later. Put simply, when in doubt, removing is safer than leaving it.
Look at the type of permission, not only the app's name. Specifically, an app that can read your email, delete files, or reach your contacts holds far more power than a simple game. In practice, closing needless permissions shrinks your attack surface.
How do you protect other accounts that used the same password?
If the attacker reached Gmail, every account that shared the password is at risk. Besides, Gmail is usually where "forgot password" links for other accounts arrive. Your email account is therefore the key to your digital life.
Work in this priority order.
- Banking and payment apps.
- Shopping sites and saved cards.
- Social media accounts.
- Cloud storage and work tools.
- Your password manager and other email addresses.
Use a separate, unique password for each account. For your bank, change the password and also check your cards for suspicious activity through the bank's official app or the official number on the back of your card. Never call a number from a message you received.
A password manager is the most practical fix here. Likewise, it generates a random, long password for each account, and you remember only one master password. Next, never reuse that master password anywhere else.
Some services keep sessions open after a password change. Also, look for a "sign out of all devices" option in each important account. If a social account was also hit, our article on Instagram accounts that keep getting disabled covers extra checks.
How do you warn your contacts?
The attacker may have sent links, money requests, or files in your name. Once you recover the account, a short and clear warning protects both you and your contacts.
Include these points.
- Your account was in someone else's hands for a while.
- They should not trust links or money requests that arrived in that period.
- They should confirm anything doubtful with you through another channel, such as a phone call.
Send the message after you change your password. Then, do not share your password, a code, or personal details in it. In practice, if someone already clicked a link, tell them to change their own password.
You can also post a short note in your team chat or on social media to reach people who will not see the email. Also, keep the tone calm. Do not blame anyone. Just say which dates to be suspicious of.
Why are paid recovery services and fake support messages scam signs?
People who lose an account feel desperate, and scammers know it. You may see ads or posts that promise "we will get your account back". Treat every one with suspicion.
Google's recovery flow is free and runs only on Google's official pages. Besides, a third party cannot "recover" the account for you. Put simply, someone who sells account recovery for a fee usually wants to collect your ID details or steal your password.
Stop when you notice any of these signs.
- Anyone who asks for your password, verification code, or photo ID.
- Any "support" service that demands payment or gift cards upfront.
- Messages that pressure you to decide fast.
- Pushes to move to an unofficial website or messaging app.
To tell a real Google alert from a fake one, check your Google Account directly instead of clicking a link. A real security alert will also show up there. Put simply, an alert that does not appear is probably fake.
Fake messages also tend to have typos, urgent wording, and odd sender addresses. Also, none of these is proof, but each should raise your guard.
We do not offer Gmail recovery services and make no offer on this topic. Put simply, this article is general information only.
Where do you report fraud or identity theft?
If you lost money or someone used your identity, changing the password is not enough. Official reporting channels differ by country, and we do not list agency names or phone numbers we cannot verify.
Instead, we suggest these general steps.
- Contact your bank through its official app or the official number on your card.
- Confirm the right authority on your own government's official website.
- Keep screenshots, email headers, and transaction records.
- Read current instructions on the agency's own page before you file anything.
This section is not legal advice. If the loss is large, speak with a lawyer.
What if a Google Workspace work account was hacked?
If your company email runs on Google Workspace, an administrator controls the account. Tell your administrator first. The admin can review the account's access and security settings.
Do not spend hours experimenting alone with a hacked Gmail account at work. Recovery options depend on the domain admin's settings. Because company data is involved, record the event as a security incident.
If you have no business email setup yet, our business email with a custom domain guide gives a basic frame. The website data security and encryption guide adds a complementary view.
How does a hacked Gmail account affect your business and website?
Many businesses use their Gmail address for more than mail. The same address may connect to Google Ads, Analytics, Search Console, and Business Profile. If the attacker got into Gmail, a password reset could open those tools too.
After you recover a hacked Gmail account, check these points.
- Did someone add an unknown user to your ad account?
- Is there a new owner or user in Analytics and Search Console?
- Is this Gmail also the admin email for your domain and hosting account?
- Does this Gmail receive password resets for your social accounts?
Remove unknown users. Also, if the address manages your domain, change that password in your registrar's panel. Then, if a payment method is saved anywhere, review recent activity.
Relying on one personal address is risky for a business. In practice, a separate, company-owned admin address with 2-Step Verification makes recovery easier and spreads the risk.
How do accounts usually get hacked in the first place?
Knowing the routes helps you prevent the next hacked Gmail account. Google's help pages do not rank attack methods. Still, security specialists describe a handful of common paths that apply to everyone.
- Fake sign-in page: A message sends you to a page that looks like Google and asks for your password.
- Password reuse: A password leaked from another site gets tried on Gmail.
- Malware: Software on your device steals your session details.
- Social engineering: A fake support agent asks you for a verification code.
That is why 2-Step Verification and passkeys matter. Even if the password leaks, signing in becomes harder without the second proof. In practice, if you share the code, that protection collapses.
A message saying "your account will be closed, tell us the code" tries to bypass the second step. Specifically, besides, a real Google notice never asks you to read a code to someone else.
Which mistakes make Gmail account recovery harder?
Rushed moves can slow recovery down. Based on Google's recovery tips, we listed the mistakes that affect the outcome most.
- Trying from a different device and location each time. Google looks for a familiar signal.
- Answering recovery questions at random or skipping them.
- Forgetting to check the spam folder for the code email.
- Typing your password into fake "support" pages.
- Changing the password but leaving old sessions open.
- Skipping the forwarding and filter check after recovery.
Repeating attempts back to back in seconds does not help either. If one attempt fails, calm down, switch to a known device, and try later. Next, start again the next day if needed.
Gmail account recovery takes patience. Next, each failed attempt wastes a chance to give Google the right details.
How do you clean your phone and browser afterwards?
Even after you recover the account, an infected device can let the attacker back in. So look at device security alongside account security.
- Update the operating system and the browser.
- Remove apps and browser extensions you do not recognize.
- Review saved passwords in the browser and delete the ones you do not use.
- Run the device's built-in security scan.
- If doubt remains, take the device to the maker's official service or a security professional.
If a browser session is still open, sign out and clear cookies. Otherwise old session data can linger on the device.
These steps look dull, but they work. Put simply, if the device is not clean, the same software may see your new password. Follow the order of device first, then password, whenever you can. Likewise, if you doubt the device, change the password from another clean one.
Which cases should you not handle yourself?
You do not have to fix everything alone. In some cases expert help protects you from needless risk.
- Google Workspace account: contact your administrator.
- Money loss or identity misuse: contact your bank and the official authorities.
- Malware suspicion on your device: show it to a security professional or the maker's official service.
- Cannot recover the account: use only Google's official channels.
Never hand over your password or verification code to anyone, even someone who says they will help.
Is the "sign in from a previous device" error the same as a hack?
No. The "sign in from a device you used before" prompt is often a Google security check. It does not mean your account was stolen. We covered it separately, so we will not repeat it here.
You may see the same prompt when you sign in from an unfamiliar device. For details, read our article on the Google account recovery sign-in from a previous device error.
The difference is simple. If you triggered the prompt yourself, it is probably an identity check. Likewise, an alert you did not expect, an unknown device, or a changed password points more strongly to a hack.
If you are unsure, check recent events in the security section of your Google Account first. Put simply, if no unfamiliar sign-in appears there, you probably face only a verification issue. Also, in both cases, 2-Step Verification and current recovery details solve problems much faster.
Which habits prevent a hacked Gmail account next time?
After recovery, the real work begins. Small habits lower the chance of a repeat.
- Use a different, long password on every account.
- Use a password manager.
- Keep 2-Step Verification and passkeys on.
- Keep your recovery phone and email current.
- Read the sender address before you click a link.
- Run Security Checkup again every few months.
If you run a website, the email addresses linked to your domain and hosting also need the same protection. Likewise, our website backup strategy guide helps you prepare for a loss.
Which step closes which risk after recovery?
Let us gather every step in one table. Each step closes a different risk. If one is missing, the attacker may return through another door.
| Step | Risk it closes |
|---|---|
| --- | --- |
| Password change | Signing in again with the old password |
| Sign out of devices | A session the attacker left open |
| 2-Step Verification | Sign-in with a password alone |
| Passkey | Giving a password to a fake page |
| Forwarding and filter cleanup | Silent copying of your mail |
| Third-party access cleanup | Lasting access without a password |
| Passwords on other accounts | Chain takeovers through reuse |
| Warning your contacts | Fraud in your name |
Keep this list and read it again when you finish. In practice, tick off every step you complete. Also, your account counts as safe only when every row is closed.



