Articles

Concerned GMail Account Owner

GMail Hacked? Here's where you start!

September 07, 20268 min read

So Your Gmail Has Been Hacked...
What Do You Do Now?

Small-business owner reviewing a suspicious email security alert on a laptop and smartphone

It’s a lazy, three-day weekend. You’re half asleep and would like a little more time, but your phone keeps buzzing on the nightstand.

You check it and find several messages from clients, coworkers, or family members:

> “What’s this Evite you sent me?”
> “You may have been hacked. Check your email.”
> “I clicked something by accident. Is this really from you?”

Your stomach drops.

If the account is your work Gmail or Google Workspace account, the concern is bigger than an embarrassing message. That inbox may be connected to client information, shared files, financial platforms, payroll systems, social media accounts, and password resets for nearly every service your business uses.

The good news? A compromised Gmail account is usually recoverable.

The important thing is to respond carefully. Don’t randomly click around. Don’t assume changing the password solved everything.

Here’s what you need to do and why each step matters.

1. Ask Someone Who Knows What They’re Doing for Help

If you’re reading this, you probably know someone you can ask: a trusted employee, a family member, your IT provider, or a cybersecurity professional.

Reach out before you do anything else if you can.

A compromised account rarely has one single point of failure. An attacker may have:

  • Changed your password

  • Added a forwarding address

  • Created filters that hide important messages

  • Altered your recovery phone number or email

  • Connected a third-party application

  • Left a device or session logged in

  • Created an app password

  • Accessed other accounts tied to your email address

Changing the password is important. It is not the whole fix.

Someone experienced can review these settings together instead of stopping after the first step and assuming the problem is over. That matters even more when the account belongs to your business.

If you can’t get help immediately, work through the steps below as carefully as possible.

2. Confirm That the Account Was Actually Compromised

Before you panic, determine whether someone accessed your account or simply made it look like they did.

There are two common possibilities:

  1. Your account was compromised. Someone signed in and sent messages through Gmail.

  2. Your address was spoofed. Someone forged your email address, but the messages never came from your account.

Start by checking your Sent folder and Trash folder.

If the suspicious messages are sitting in Sent or Trash, they were likely sent through your account. That is a strong sign someone had access.

If the messages aren’t there, spoofing is more likely. Your account may not have been breached, although you should still investigate if anything feels wrong.

Next, visit Google’s Security Checkup and account security settings. Review:

  • Recent security activity

  • Sign-in locations you don’t recognize

  • Devices you’ve never used

  • Timestamps that don’t match your activity

  • Recovery information that has changed

  • Connected apps you don’t recognize

A sign-in from a city or country you’ve never visited is an obvious warning. But don’t rely only on location. Attackers don’t always leave clear evidence.

If your Sent folder, filters, or forwarding settings look strange, keep going.

IT professional and business manager reviewing account security settings together

3. Change Your Password Immediately , If You Can Still Log In

If you still have access to the account, change the password now.

Use a long, unique password that you have never used anywhere else. Don’t use a variation of the old one. Adding a “1” or another exclamation mark isn’t enough.

A password manager can generate and store a strong password for you. That means you don’t have to depend on memory or reuse the same password across multiple business systems.

Google recommends changing a compromised account password through your Google Account security settings.

If the attacker changed your password and locked you out, skip ahead to step seven.

4. Turn On Two-Factor Authentication

Two-factor authentication, also called 2FA or two-step verification, is one of the most effective ways to prevent someone from using a stolen password.

The idea is simple. Your account requires:

  • Something you know, such as a password

  • Something you have, such as your phone, authenticator app, passkey, or security key

A criminal may steal or guess your password. They generally won’t have your phone or security key in hand.

If 2FA wasn’t enabled before the incident, turn it on after you regain control of the account. You can start from Google’s 2-Step Verification page.

An authenticator app or passkey is generally preferable to text-message codes when available. SMS can be exposed through SIM-swapping attacks.

For a business using Google Workspace, your administrator may also be able to apply stronger sign-in requirements across the organization.

5. Check and Remove Forwarding Rules

This is one of the most important steps, and it’s one people often skip.

Attackers may create a forwarding rule that silently sends copies of your email to them. That can include:

  • Password reset messages

  • Financial notifications

  • Client conversations

  • Vendor invoices

  • Security alerts

  • Messages containing sensitive attachments

Changing your password won’t necessarily tell you that forwarding was enabled.

In Gmail, open Settings, then See all settings. Review:

  • Forwarding and POP/IMAP

  • Filters and Blocked Addresses

Look for forwarding addresses you don’t recognize. Also look for filters that automatically:

  • Forward messages

  • Delete messages

  • Archive messages

  • Mark messages as read

  • Move messages into unfamiliar labels

Remove anything you didn’t create.

If this is a work account, be especially careful. A hidden rule can let an attacker continue collecting information after you believe the account is secure.

6. Check Connected Apps and Devices

A password change may not remove every existing session or connected application.

Go back to your Google Account security page and review Your devices. Sign out of anything you don’t recognize.

Then review third-party apps and services with account access. Revoke access for anything you:

  • Don’t recognize

  • Don’t actively use

  • Don’t remember authorizing

  • No longer need

Also look for unfamiliar app passwords.

A third-party application can act as a backdoor. In some cases, an attacker grants an application access to email or files, then continues using that access even after the main password changes.

For a Google Workspace account, your administrator may need to revoke OAuth tokens, remove app passwords, or temporarily suspend the affected account. Google provides additional guidance for identifying and securing compromised Workspace accounts.

This is why account recovery is more than a password reset.

Secure email account represented by a shield, lock, and connected digital security elements

7. If You’re Locked Out Completely

If the attacker changed your password, recovery phone number, or recovery email, use Google’s Account Recovery process.

You may be asked for:

  • The approximate date you created the account

  • Previous passwords you remember

  • Access to a recovery phone number

  • Access to a recovery email address

  • Other information that helps verify your identity

Be accurate and patient. Recovery may take more than one attempt.

Avoid guessing wildly. Use the information you know is correct, and try the process from a device or location you regularly use to access the account.

If this is a Google Workspace account, contact your Workspace administrator as soon as possible. Your administrator may have additional options to suspend the account, reset access, review activity, or protect other users.

8. Assess the Damage After You’re Back In

Getting back into the account is a major step. It is not the final step.

Review:

Sent mail

What did the attacker send? Which clients, vendors, employees, or contacts received it?

Drafts and Trash

Attackers sometimes stage phishing messages in Drafts or move evidence to Trash.

Linked accounts

Which services use this email address for password recovery? Check banking, payroll, social media, cloud storage, accounting software, and business applications.

Change those passwords, beginning with your most sensitive accounts.

Shared files and business tools

For work accounts, review Google Drive, shared drives, calendars, contacts, and connected business applications. Look for unexpected sharing settings, downloads, or account changes.

If your business handles health, financial, legal, or customer information, consider whether sensitive data may have been exposed. You may need to involve your attorney, insurer, compliance advisor, or other appropriate professional.

9. Notify the People Who Need to Know

If your account sent suspicious messages, let recipients know.

Keep it short:

> My email account was compromised. Please ignore anything unusual you received from me recently, and don’t click links or open attachments from those messages.

If the account belongs to your business, notify your employees and anyone responsible for IT, cybersecurity, finance, or compliance.

A quick warning can prevent one compromised inbox from becoming several compromised accounts.

Preventing the Next One

Once the account is secure, take a few minutes to reduce the chance of another incident.

  • Use a password manager

  • Use a different password for every account

  • Keep 2FA enabled everywhere it’s available

  • Review connected apps and devices periodically

  • Be cautious with urgent requests to click, log in, verify, or send money

  • Confirm unusual payment or password-reset requests through another channel

  • Keep your phone, computer, browser, and applications updated

  • Make sure recovery information belongs to you and is current

Attackers create urgency because urgency causes mistakes.

Pause before you click.

A Compromised Account Is Serious : and Usually Recoverable

A hacked Gmail account is stressful, especially when it’s tied to your business. But you can regain control if you work through the problem methodically.

Confirm the breach. Change the password. Turn on 2FA. Remove forwarding rules. Review connected apps and devices. Recover the account if necessary. Then assess what may have been exposed.

Don’t stop after the first fix.

If this is your work email and you’re not sure your business accounts are fully locked down, we’re happy to take a look. You can learn more about our cybersecurity services or request an initial conversation with no obligation.

GMailHackedStartHere
Back to Blog