Gmail is one of the most important accounts because it is often used to open Facebook, Instagram, YouTube, bank apps, hosting, business tools, documents, Google Drive and many other accounts. If someone steals your Gmail, they can try to reset passwords for your other services, read your emails, delete information, send scam messages or take important documents.
A hacked Gmail is not a small issue. It is a security problem for your whole digital identity. That is why when you discover your Gmail has been accessed by someone else, the first steps must be taken quickly and in order. Do not only change the password without checking devices, recovery settings, filters, forwarding and apps with access.
The first sign of a hacked Gmail is failing to log in with your normal password. If the password you usually use suddenly does not work, someone may have changed it. However, before concluding, make sure you did not type the wrong password, keyboard language, caps lock or select the wrong account.
The second sign is receiving a security alert from Google. Google may send a notification that there was a new login, password changed, recovery phone changed or new device signed in. Do not ignore these alerts. If you do not recognize the activity, act quickly.
The third sign is seeing sent emails you did not send. Open the Sent folder and check for strange messages. A hacker can use your Gmail to send scam links to people you communicate with. This can damage your reputation and put others at risk.
The fourth sign is important emails disappearing. A hacker may delete security alerts, bank emails, reset emails or messages that can expose them. Check Trash, Spam, All Mail and filters. Sometimes a hacker creates a filter that deletes or archives security emails.
The fifth sign is recovery email or phone being changed. If recovery details are no longer yours, your account is in greater danger. If a hacker changes recovery options, they can make it harder for you to recover the account. That is why recovery settings must be checked immediately after login.
The first step when you discover Gmail is hacked is trying to sign in through the official Google Account Recovery process. Do not use links sent by other people. Open the official recovery page through Google Account or Gmail app. Use a device you normally used for that account, your usual location, and your usual network if possible. This can help Google confirm you are the owner.
The second step is using the last password you remember. During recovery, Google may ask for an old password. Enter the last password you used for that account. Even if the hacker changed the password, the old password can help confirm ownership.
The third step is using recovery phone or email. If the recovery phone/email is still yours, Google may send a code. Make sure you have access to that number or email. If you do not have access, try other recovery options. Do not give anyone the code you receive.
The fourth step is answering recovery questions as accurately as possible. Google may ask for account creation date, devices used or verification details. If you do not remember the exact date, try the closest information you remember. Use true information, not random guesses.
The fifth step is doing recovery on a safe device. If you think your computer or phone has a virus, do not use that device to change password. Use another device you trust. If you set a new password on a device with malware, the hacker may get it again.
The sixth step after login is changing the password immediately. The new password should be long, different from other passwords, and hard to guess. Do not use your name, phone number, birthday or a password you used somewhere else. A good password can be a long sentence with letters, numbers and symbols.
The seventh step is using a password manager. A password manager can help you create and store strong passwords without memorizing all of them. It also helps prevent using the same password on many accounts. Your Gmail needs a completely unique password.
The eighth step is checking devices signed in to the account. Go to Google Account, Security, Your devices. Check phones, laptops, browsers and locations signed in. Log out any device you do not recognize. If unsure, sign out from all devices and sign in again only on your own devices.
The ninth step is checking recent security activity. In Google Account Security, check recent actions such as password changes, recovery changes, new sign-ins and app access. These activities can show when the hacker entered and what they changed.
The tenth step is enabling two-step verification. 2FA adds another layer of security. Even if someone gets the password, they need extra verification. Use an authenticator app, Google prompt, security key or another secure method. SMS is better than no 2FA, but authenticator app or security key is usually safer.
The eleventh step is saving backup codes. After enabling 2FA, Google may give you backup codes. Store them somewhere safe, not only inside the same Gmail. You can store them in a password manager or safe offline place. Backup codes help if you lose your phone.
The twelfth step is fixing recovery phone and recovery email. Make sure recovery phone is your active number and recovery email belongs to you. Remove recovery details you do not recognize. If a hacker added their email or phone, remove it immediately.
The thirteenth step is checking Gmail forwarding. A hacker can set your emails to be forwarded to them quietly. Open Gmail Settings, Forwarding and POP/IMAP. Check whether there is an unknown forwarding address. If there is, remove it and save changes.
The fourteenth step is checking Gmail filters. This is a very important part many people forget. A hacker can create a filter that deletes emails from Google, bank, Facebook, Instagram or hosting provider. Go to Settings, Filters and Blocked Addresses. Delete filters you do not recognize.
The fifteenth step is checking blocked addresses. A hacker can block important emails so you do not receive alerts. Review blocked senders and remove those you do not recognize. Especially check whether Google, bank, social media or business contacts were blocked.
The sixteenth step is checking delegated access. Gmail can allow another person to read or send email on your behalf through delegation. Check whether there is an account with access. Remove delegated accounts you do not recognize or no longer need.
The seventeenth step is checking third-party apps with access. Other apps may have permission to read Gmail, contacts, Drive or Google Account. Go to Google Account, Security, Third-party access. Remove unknown apps, old apps or untrusted apps.
The eighteenth step is checking app passwords. If you use 2FA, some old apps may use app passwords. If a hacker creates an app password, they may continue to access the account. Review app passwords and delete those you do not recognize.
The nineteenth step is checking POP and IMAP. A hacker may use a mail client to download emails through POP/IMAP. If you do not use mail clients such as Outlook or Thunderbird, you can disable POP/IMAP or check their settings. If you use them, make sure the settings are yours.
The twentieth step is checking Google Drive. If Gmail is hacked, Google Drive may also be at risk. Review your files, shared files, recent activity and important documents. Remove unknown sharing. Make sure sensitive documents are not shared with people you do not know.
The twenty-first step is checking Google Photos if the account is personal. If the account contains personal photos, make sure there is no unknown sharing. A hacker can see or share your photos if they have access to the account. Change password and log out devices quickly.
The twenty-second step is checking YouTube if your Gmail has a channel. Many Gmail accounts are connected to YouTube channels. A hacker can change the channel name, delete videos, post scams or damage monetization. Check YouTube Studio, permissions and brand account access.
The twenty-third step is checking other accounts connected to Gmail. Facebook, Instagram, TikTok, hosting, domain registrar, bank apps, payment providers and business systems often use Gmail for password reset. Change passwords for important accounts, especially if Gmail was used to receive reset emails.
The twenty-fourth step is checking social media recovery email. If Gmail was hacked, the hacker may try to take Facebook or Instagram. Log in to your social media accounts, check email/phone, login activity, 2FA and connected devices. Remove sessions you do not recognize.
The twenty-fifth step is informing people if your Gmail sent scam messages. If the hacker sent emails to your contacts, send a short notice that your account was accessed and they should not click links they received. This protects others and rebuilds your trust.
The twenty-sixth step is checking Trash and Sent folder. A hacker may delete evidence or send messages without your knowledge. Check Trash, Spam, Sent, Drafts and All Mail. This helps you understand what happened while the account was in someone else’s hands.
The twenty-seventh step is checking bank and payment emails. Search for emails from bank, mobile money, PayPal, payment gateways or online shops. Make sure there are no password reset, transaction, withdrawal or login alerts you do not recognize. If there is financial activity, contact the provider quickly.
The twenty-eighth step is checking hosting and domain accounts. If your Gmail manages a website, domain or hosting, a hacker may try to change DNS, email, website files or billing. Log in to hosting/domain accounts, change password, enable 2FA and review activity.
The twenty-ninth step is doing a malware scan. If you do not know how the hacker got your password, your device may have malware, a dangerous browser extension or keylogger. Scan computer and phone, remove unknown apps/extensions, update system and use trusted antivirus/security tools.
The thirtieth step is checking browser extensions. Extensions can read pages, cookies or browser data. Remove extensions you do not use or do not trust. Do not use “free download,” “coupon,” “AI tools” or “video downloader” extensions without knowing them well.
The thirty-first step is checking saved passwords in the browser. If your browser stored passwords and the hacker accessed the device, other passwords may be at risk. Change passwords for important accounts. It is better to use a password manager with a strong master password than an unprotected browser.
The thirty-second step is checking whether your password was reused elsewhere. If you used your Gmail password on another website, change the password there too. A hacker may try credential stuffing, meaning using the same email/password on many websites.
The thirty-third step is identifying the cause of the problem. Did you click a fake link? Install an unofficial app? Give someone an OTP? Use a weak password? Log in on someone else’s computer? Knowing the cause helps prevent the problem from returning.
The thirty-fourth step is avoiding public computers for important Gmail. Internet café computers, other people’s office computers or public devices may have keyloggers or browsers that save sessions. If you must use one, do not save password, use private mode, log out properly and change password later if suspicious.
The thirty-fifth step is never sharing your password. No friend, technician, employee or support person should know your Gmail password. If someone needs access to documents or business email, use official sharing/permissions instead of giving your password.
The thirty-sixth step is using separate accounts for business and personal use. If one Gmail is used for everything, the risk increases. For business, it is better to have business email, separate admin accounts, 2FA and a recovery plan. This reduces damage if one account has a problem.
The thirty-seventh step is preparing a recovery plan. Make sure you have recovery phone, recovery email, backup codes, safe device and password manager. Do not wait until the account is hacked to start looking for an old number or email you no longer use.
The thirty-eighth step is acting if recovery fails. If you cannot recover the account, try again from a familiar device/location, use correct information, and do not try too many times with random answers. If the account belongs to work/school, contact the organization admin.
The thirty-ninth step is protecting the account after recovery. Recovering the account alone is not enough. You must change password, enable 2FA, remove unknown devices, remove forwarding/filters, review apps, and change passwords of important accounts connected to it.
The fortieth step is doing security checkup regularly. Google Account has Security Checkup that shows important issues. Run checkup at least every few months or immediately after noticing an alert. An important account needs regular management.
In general, when Gmail is hacked, do not look at password only. Check the entire account: devices, recovery info, 2FA, forwarding, filters, blocked senders, delegated access, third-party apps, Google Drive, YouTube and other accounts using that Gmail. A hacker may leave a way back even after you change password.
Remember: your Gmail is the key to your online life. Protect it with a unique password, 2FA, correct recovery details, backup codes and the habit of not clicking strange links. If you see signs of hacking, act quickly but in an organized way.
FAQ - Frequently Asked Questions
1. How do I know if my Gmail is hacked?
Signs include password not working, unknown security alerts, emails sent without you, recovery phone/email changed, unknown devices or important emails disappearing.
2. What should I do first if Gmail is hacked?
Try signing in through Google Account Recovery, use a familiar device, change password, log out unknown devices and enable 2FA.
3. Why is changing password alone not enough?
A hacker may have set forwarding, filters, app passwords, third-party apps or devices that remain logged in. You must review all security settings.
4. Can Gmail filters be abused?
Yes. A hacker can create a filter that deletes or archives security alerts, bank emails or password reset emails so you do not notice what is happening.
5. Is 2FA important for Gmail?
Yes. 2FA helps protect your account even if the password is known. Use an authenticator app, Google prompt or security key if possible.
6. What should I do if the recovery phone was changed by a hacker?
Use Google Account Recovery from a familiar device/location, old password and accurate information. If you regain access, remove the hacker’s recovery details immediately.
7. Can hacked Gmail affect Facebook or Instagram?
Yes. If Facebook or Instagram use that Gmail for recovery, the hacker may try to reset their passwords. Check your social media accounts immediately.
8. What should I do if my Gmail sent scam emails to people?
After recovering the account, tell your contacts not to click the links they received, change password, enable 2FA and check Sent folder and filters.