
GMail Hacked? Here's where you start!
So Your Gmail Has Been Hacked...
What Do You Do Now?

It’s a lazy, three-day weekend. You’re half asleep and would like a little more time, but your phone keeps buzzing on the nightstand.
You check it and find several messages from clients, coworkers, or family members:
> “What’s this Evite you sent me?”
> “You may have been hacked. Check your email.”
> “I clicked something by accident. Is this really from you?”
Your stomach drops.
If the account is your work Gmail or Google Workspace account, the concern is bigger than an embarrassing message. That inbox may be connected to client information, shared files, financial platforms, payroll systems, social media accounts, and password resets for nearly every service your business uses.
The good news? A compromised Gmail account is usually recoverable.
The important thing is to respond carefully. Don’t randomly click around. Don’t assume changing the password solved everything.
Here’s what you need to do and why each step matters.
1. Ask Someone Who Knows What They’re Doing for Help
If you’re reading this, you probably know someone you can ask: a trusted employee, a family member, your IT provider, or a cybersecurity professional.
Reach out before you do anything else if you can.
A compromised account rarely has one single point of failure. An attacker may have:
Changed your password
Added a forwarding address
Created filters that hide important messages
Altered your recovery phone number or email
Connected a third-party application
Left a device or session logged in
Created an app password
Accessed other accounts tied to your email address
Changing the password is important. It is not the whole fix.
Someone experienced can review these settings together instead of stopping after the first step and assuming the problem is over. That matters even more when the account belongs to your business.
If you can’t get help immediately, work through the steps below as carefully as possible.
2. Confirm That the Account Was Actually Compromised
Before you panic, determine whether someone accessed your account or simply made it look like they did.
There are two common possibilities:
Your account was compromised. Someone signed in and sent messages through Gmail.
Your address was spoofed. Someone forged your email address, but the messages never came from your account.
Start by checking your Sent folder and Trash folder.
If the suspicious messages are sitting in Sent or Trash, they were likely sent through your account. That is a strong sign someone had access.
If the messages aren’t there, spoofing is more likely. Your account may not have been breached, although you should still investigate if anything feels wrong.
Next, visit Google’s Security Checkup and account security settings. Review:
Recent security activity
Sign-in locations you don’t recognize
Devices you’ve never used
Timestamps that don’t match your activity
Recovery information that has changed
Connected apps you don’t recognize
A sign-in from a city or country you’ve never visited is an obvious warning. But don’t rely only on location. Attackers don’t always leave clear evidence.
If your Sent folder, filters, or forwarding settings look strange, keep going.

3. Change Your Password Immediately , If You Can Still Log In
If you still have access to the account, change the password now.
Use a long, unique password that you have never used anywhere else. Don’t use a variation of the old one. Adding a “1” or another exclamation mark isn’t enough.
A password manager can generate and store a strong password for you. That means you don’t have to depend on memory or reuse the same password across multiple business systems.
Google recommends changing a compromised account password through your Google Account security settings.
If the attacker changed your password and locked you out, skip ahead to step seven.
4. Turn On Two-Factor Authentication
Two-factor authentication, also called 2FA or two-step verification, is one of the most effective ways to prevent someone from using a stolen password.
The idea is simple. Your account requires:
Something you know, such as a password
Something you have, such as your phone, authenticator app, passkey, or security key
A criminal may steal or guess your password. They generally won’t have your phone or security key in hand.
If 2FA wasn’t enabled before the incident, turn it on after you regain control of the account. You can start from Google’s 2-Step Verification page.
An authenticator app or passkey is generally preferable to text-message codes when available. SMS can be exposed through SIM-swapping attacks.
For a business using Google Workspace, your administrator may also be able to apply stronger sign-in requirements across the organization.
5. Check and Remove Forwarding Rules
This is one of the most important steps, and it’s one people often skip.
Attackers may create a forwarding rule that silently sends copies of your email to them. That can include:
Password reset messages
Financial notifications
Client conversations
Vendor invoices
Security alerts
Messages containing sensitive attachments
Changing your password won’t necessarily tell you that forwarding was enabled.
In Gmail, open Settings, then See all settings. Review:
Forwarding and POP/IMAP
Filters and Blocked Addresses
Look for forwarding addresses you don’t recognize. Also look for filters that automatically:
Forward messages
Delete messages
Archive messages
Mark messages as read
Move messages into unfamiliar labels
Remove anything you didn’t create.
If this is a work account, be especially careful. A hidden rule can let an attacker continue collecting information after you believe the account is secure.
6. Check Connected Apps and Devices
A password change may not remove every existing session or connected application.
Go back to your Google Account security page and review Your devices. Sign out of anything you don’t recognize.
Then review third-party apps and services with account access. Revoke access for anything you:
Don’t recognize
Don’t actively use
Don’t remember authorizing
No longer need
Also look for unfamiliar app passwords.
A third-party application can act as a backdoor. In some cases, an attacker grants an application access to email or files, then continues using that access even after the main password changes.
For a Google Workspace account, your administrator may need to revoke OAuth tokens, remove app passwords, or temporarily suspend the affected account. Google provides additional guidance for identifying and securing compromised Workspace accounts.
This is why account recovery is more than a password reset.

7. If You’re Locked Out Completely
If the attacker changed your password, recovery phone number, or recovery email, use Google’s Account Recovery process.
You may be asked for:
The approximate date you created the account
Previous passwords you remember
Access to a recovery phone number
Access to a recovery email address
Other information that helps verify your identity
Be accurate and patient. Recovery may take more than one attempt.
Avoid guessing wildly. Use the information you know is correct, and try the process from a device or location you regularly use to access the account.
If this is a Google Workspace account, contact your Workspace administrator as soon as possible. Your administrator may have additional options to suspend the account, reset access, review activity, or protect other users.
8. Assess the Damage After You’re Back In
Getting back into the account is a major step. It is not the final step.
Review:
Sent mail
What did the attacker send? Which clients, vendors, employees, or contacts received it?
Drafts and Trash
Attackers sometimes stage phishing messages in Drafts or move evidence to Trash.
Linked accounts
Which services use this email address for password recovery? Check banking, payroll, social media, cloud storage, accounting software, and business applications.
Change those passwords, beginning with your most sensitive accounts.
Shared files and business tools
For work accounts, review Google Drive, shared drives, calendars, contacts, and connected business applications. Look for unexpected sharing settings, downloads, or account changes.
If your business handles health, financial, legal, or customer information, consider whether sensitive data may have been exposed. You may need to involve your attorney, insurer, compliance advisor, or other appropriate professional.
9. Notify the People Who Need to Know
If your account sent suspicious messages, let recipients know.
Keep it short:
> My email account was compromised. Please ignore anything unusual you received from me recently, and don’t click links or open attachments from those messages.
If the account belongs to your business, notify your employees and anyone responsible for IT, cybersecurity, finance, or compliance.
A quick warning can prevent one compromised inbox from becoming several compromised accounts.
Preventing the Next One
Once the account is secure, take a few minutes to reduce the chance of another incident.
Use a password manager
Use a different password for every account
Keep 2FA enabled everywhere it’s available
Review connected apps and devices periodically
Be cautious with urgent requests to click, log in, verify, or send money
Confirm unusual payment or password-reset requests through another channel
Keep your phone, computer, browser, and applications updated
Make sure recovery information belongs to you and is current
Attackers create urgency because urgency causes mistakes.
Pause before you click.
A Compromised Account Is Serious : and Usually Recoverable
A hacked Gmail account is stressful, especially when it’s tied to your business. But you can regain control if you work through the problem methodically.
Confirm the breach. Change the password. Turn on 2FA. Remove forwarding rules. Review connected apps and devices. Recover the account if necessary. Then assess what may have been exposed.
Don’t stop after the first fix.
If this is your work email and you’re not sure your business accounts are fully locked down, we’re happy to take a look. You can learn more about our cybersecurity services or request an initial conversation with no obligation.


