Security
Suspect Your Google Account Was Accessed? A Recovery Playbook
If you see a sign-in you don't recognise, the next 30 minutes matter. Here's the order of operations.

By Adrián Vega
Published 22 December 2025 · Updated 24 June 2026 · 7 min read
There is a very specific kind of sinking feeling you get when you see a notification saying "New sign-in on a Linux device" when you don't even own a computer, let alone one running Linux. I had this happen about two years ago. I was sitting on my couch, my Pixel was in my hand, and someone in another country was currently looking through my Gmail. It's terrifying, but panicking makes you slow. You need a checklist. This is the exact playbook I used to boot the intruder and lock the door behind them.
Signs of a breach
Sometimes it’s a "Security Alert" email from Google, which is the most obvious sign. But often, it's subtler. You might notice "sent" emails you didn't write, or maybe you get a text message with a verification code you didn't request. On Android, a big red flag is seeing apps on your phone or in your Play Store "Library" that you never downloaded.
Check your Google Maps Timeline. If it shows you were at a shopping mall in a city you've never visited, someone else has your credentials. Another common sign is finding "Subscription Confirmed" emails for services you didn't join—hackers often use breached accounts to sign up for trials or premium services using saved payment methods. If anything feels off, even slightly, treat it as a breach. It’s better to be wrong and perform a 10-minute security check than to be right and lose your digital identity.
First 30 minutes
If you suspect a breach, the clock is ticking. Your first move is the Google Security Checkup. On your Android phone, go to Settings > Google > Manage your Google Account > Security. At the top, you'll see "Security recommendations." Tap that. It will show you a list of recent security events. If you see a device or a login location you don't recognize, that's your smoking gun.
Do not wait to get to a PC. Use your phone's browser or the settings menu to immediately remove the suspicious device. Tap the device name and select "Sign out." This kills their current session. However, if they have your password, they can just sign back in. This step is only about stopping the immediate bleeding while you prepare the local anesthetic.
Password rotation
Now, you have to change your password. This is the part everyone hates because it means updating it on every other device you own. Go back to the Security tab in your Google settings and tap Password. You’ll have to verify it's you—usually with your fingerprint or face scan on Android—and then pick something entirely new.
Do not just add a "1!" to the end of your old password. If a hacker got your old one through a phishing site or a data leak, they’ll guess your "new" one in seconds using a script. Use a password manager or let Chrome generate a long, random string. I use a 20-character mix of nonsense that I don't even try to memorize. This is also a good time to check if you’ve reused this password anywhere else. If you used the same password for Google and your bank, your bank is next on the attacker's list.
Killing active sessions
Changing your password doesn't always automatically log out every single device. You need to do a manual sweep. In the Security tab, look for the section Your devices and tap Manage all devices. You'll see a list of every phone, tablet, and computer currently logged into your account.
I found a "Windows Chrome" session from three states away when I did this. I tapped it and hit Sign Out. Then I did it for every single device that wasn't the phone currently in my hand. Yes, it’s annoying to have to sign back into your iPad and your work laptop, but it’s the only way to ensure the intruder doesn't have a "backdoor" session still running. Android makes this fairly easy, but it’s a manual process—you have to tap each one individually. Think of it as clearing each room in a house to make sure no one is hiding under the bed.
Locking down recovery
This is the step most people forget. A smart attacker, once they get into your account, will immediately change the Recovery Email or Recovery Phone Number to their own. That way, when you try to reset your password, the code goes to them instead of you.
Go to your Google Account Security tab again. Scroll down to Ways we can verify it’s you. Check the Recovery phone and Recovery email. If you see an email address you don't recognize—even if it's just one letter off from yours—change it immediately. Also, check your Trusted Devices for 2-step verification. If the hacker added their own phone as a trusted device, they can bypass your password change. It’s an extra layer of "account persistence" that attackers love to use.
The week after
Once you've changed the password and kicked everyone out, the work isn't quite done. For the next seven days, you need to be hyper-vigilant. Check your Gmail Filters (you usually need to do this in a mobile browser set to "Desktop Mode" or on a computer). Scammers often set up a filter that automatically deletes emails from banks or Google Security, so you won't see their activity. If you find a filter that says "Delete all mail from no-reply@google.com," you know someone was trying to hide their tracks.
Also, keep a close eye on your bank statements and your "My Activity" log on Google. It’s a lot of work, and it frankly sucks that one leaked password can cause this much stress. But after a week of no weird activity, you can breathe again. Just remember: technology is never perfectly secure. The best we can do is make our accounts such a pain to crack that the hackers move on to an easier target. Using a unique password and checking your "Your devices" list once a month is usually enough to keep you out of the crosshairs.
Key takeaways
- Signs of a breach is where you start — it's the fastest win.
- First 30 minutes: don't skip this — it's where most users leave settings at risky defaults.
- Password rotation: don't skip this — it's where most users leave settings at risky defaults.
- Killing active sessions: don't skip this — it's where most users leave settings at risky defaults.
- Recheck these settings quarterly; OEM updates can reset toggles.
Frequently asked questions
- Does changing these settings break apps?
- Almost never. Modern Android apps must handle a denied permission or restricted access gracefully — they either skip the feature or prompt again when needed.
- Will this drain my battery?
- No. If anything, restricting background access and disabling tracking pipelines reduces battery and data usage.
- Do these steps apply to Android 13, 14 and 15?
- Yes. The menu paths shift slightly between versions and OEM skins (Pixel/stock, Samsung One UI, Xiaomi HyperOS), but the underlying controls behave the same.
References & further reading
Continue reading
Related guides
Secure Your Google Account on Android: 2FA, Passkeys, and Recovery
Your Google account is the master key to everything on your Android phone. Here's the four-step lockdown.
7 min read · Updated 24 Jun 2026
Setting a Strong Screen Lock on Android (PIN, Pattern, Biometrics)
The lock screen is your phone's last line of defence. Most people get it wrong.
6 min read · Updated 24 Jun 2026
Set Up Find My Device on Android the Right Way
The new Find My Device network works offline using nearby Android phones. Here's how to enable everything.
7 min read · Updated 24 Jun 2026