Gmail Account Hacked: Recover Access and Lock the Attacker Out
Official Google page for this problem: support.google.com — we link it because the official flow is always the real path; this guide exists to help you get through it.
Realizing someone else has been inside your email is genuinely alarming — email is the master key to most of your other accounts. The good news: if you can still sign in, or the hack is recent, you can usually take the account back and lock the attacker out completely. The caveat: anything the attacker already read, downloaded, or deleted may be beyond your control, and you’ll need to treat every account tied to this address as potentially exposed.
Before you start
Move quickly but methodically. Gather:
- A device you normally use with this account, on your usual home network. Google’s recovery system trusts familiar devices and locations.
- Your recovery phone and recovery email, if you set them up.
- The last password you knew, even if the attacker has changed it since.
- A clean device. If you suspect malware on your computer (this is how many accounts get hacked), do the recovery from your phone instead, and plan to scan or reset the suspect machine.
Step 1: Try to sign in, or start recovery
If your password still works, sign in immediately and skip to Step 2.
If it doesn’t, go to accounts.google.com/signin/recovery. Enter your address and work through the options: your last known password, a code to your recovery phone or email, or a prompt on a signed-in device. Google may ask additional questions; answer carefully and honestly. Attackers often change recovery details, but Google typically keeps your original recovery methods usable for a window of time after a change and may notify you at the old contact points — so act soon and check your recovery email for “your recovery phone was changed”-style alerts, which often include a link to reverse the change.
If recovery fails, retry from your most familiar device and network after a day. See our locked-out guide for the full recovery playbook.
Step 2: Change your password and end other sessions
Once you’re in, change your password immediately at myaccount.google.com/security — pick something long, unique, and not used anywhere else, ideally from a password manager. Also add a passkey if prompted.
Then, on the same security page, find the section listing devices where you’re signed in (“Your devices” / “Manage all devices”) and sign out every device you don’t recognize. This ends the attacker’s active sessions. In Gmail on desktop, you can also scroll to the bottom of your inbox, click Details under “Last account activity,” and sign out all other web sessions.
Step 3: Run Google’s Security Checkup
Go to myaccount.google.com/security-checkup. Work through every item it raises:
- Recovery phone and email: make sure they’re yours. Attackers commonly swap these in so they can re-hack you later. Remove anything you don’t recognize.
- Third-party apps with account access: revoke anything unfamiliar or unnecessary, especially anything with Gmail read access.
- App passwords: delete any you don’t remember creating — these bypass your main password.
- Recent security events: review sign-ins and changes; flag anything as “No, it wasn’t me” if offered.
Turn on 2-Step Verification if it isn’t already, preferably with a passkey or authenticator app rather than SMS alone.
Step 4: Undo the attacker’s changes inside Gmail
This step is skipped by most people and is exactly where attackers hide persistence. In Gmail, open Settings → See all settings and check:
- Forwarding and POP/IMAP: remove any forwarding address you didn’t add. This is the single most common backdoor — the attacker keeps receiving copies of your mail (including password-reset emails) after you’ve locked them out.
- Filters and Blocked Addresses: delete filters you didn’t create, especially ones that auto-forward, auto-delete, or auto-archive messages (attackers use these to hide bank and security alerts from you).
- Accounts → Grant access to your account: remove any delegates you don’t recognize.
- Send mail as / vacation responder: make sure nothing was altered.
Also check Trash and Sent for messages the attacker sent or deleted — you may be able to restore recently deleted mail from Trash within its 30-day window.
Step 5: Assess the damage and protect your other accounts
Assume the attacker searched your mailbox for value. Prioritize:
- Change passwords on accounts that used this email, starting with banking, payment apps, cloud storage, and other email accounts. Do the ones with money first.
- Check those accounts for changes — new payees, changed contact info, password resets you didn’t request.
- Warn your contacts. Attackers often email your address book with scams or malware while posing as you.
- Scan the device you suspect was compromised, or back up and reset it. Recovering the account on a still-infected machine just hands it back.
What NOT to do
- Don’t pay a “hacked account recovery” service. This niche is riddled with scams; nobody outside Google can override its systems, and “hackers for hire” who promise to steal your account back are frequently just a second scam.
- Don’t call phone numbers claiming to be Google support. Google offers no phone line for free Gmail account recovery. These numbers lead to scammers who will ask for remote access or your codes.
- Never share a verification code with anyone, including someone claiming to be from Google, your bank, or the police. Codes are for entering into Google’s own pages only.
- Don’t rapid-fire the recovery form with guessed answers. Careful, spaced attempts from familiar devices work better.
- Don’t just change the password and stop. Without Steps 3 and 4, an attacker with forwarding rules or app passwords stays in.
If nothing works
If you cannot recover the account after multiple careful attempts, be realistic: there is no human escalation path for free Gmail accounts, and the mailbox, contacts, and Drive files under it may be permanently out of reach. If it’s a Google Workspace account (work or school), contact your administrator — they can reset it directly.
Practical containment:
- Treat the address as hostile. The attacker can now receive password resets for anything still pointing at it. Change the email on file for every account you can, starting with financial ones.
- Alert contacts from another channel that mail from that address is no longer you.
- Create a new account properly: unique password, 2-Step Verification, passkey, current recovery phone and email, and a periodic Google Takeout backup so a future incident can’t take your history with it.
- Report identity-theft consequences (fraudulent charges, opened accounts) to your bank and local authorities as applicable.
It’s a rough outcome, but decisive containment limits the damage to one mailbox rather than your whole digital life.
Frequently asked questions
How do I know if my Gmail was actually hacked?
Common signs: a password you know stops working, sent mail you didn't write, security alerts about sign-ins from unfamiliar places, changed recovery info, or new forwarding rules in Gmail settings.
The hacker changed my password. Can I still get back in?
Often yes. Google keeps your original recovery info active for a period after changes, and familiar-device signals still count. Start at accounts.google.com/signin/recovery promptly.
Can the hacker still read my email after I change my password?
Yes, if they left behind app passwords, forwarding rules, delegated access, or connected apps. That's why the cleanup steps matter as much as the password change.
Should I delete my Gmail account after a hack?
Usually no. Deleting it doesn't undo any damage, and it releases your control of the address. Recover it, clean it, and secure it instead.
Will Google tell me what the hacker did?
Partially. The security activity page and Gmail's 'Last account activity' show sign-ins and sessions, but there's no complete audit log of every message they read.
recover.email is not affiliated with Google. This guide is informational and cannot guarantee recovery.