Security

Suspect Your Google Account Was Accessed? A Recovery Playbook

If you see a sign-in you don't recognise, the next 30 minutes matter. Here's the order of operations.

Adrián Vega

By Adrián Vega

Published 22 December 2025 · Updated 24 June 2026 · 7 min read

Person looking concerned at phone

There is a very specific kind of sinking feeling you get when you see a notification saying "New sign-in on a Linux device" when you don't even own a computer, let alone one running Linux. I had this happen about two years ago. I was sitting on my couch, my Pixel was in my hand, and someone in another country was currently looking through my Gmail. It's terrifying, but panicking makes you slow. You need a checklist. This is the exact playbook I used to boot the intruder and lock the door behind them.

Signs of a breach

Signs of a breach
Illustration — Signs of a breach. Stock photograph, not an actual device screenshot.

Sometimes it’s a "Security Alert" email from Google, which is the most obvious sign. But often, it's subtler. You might notice "sent" emails you didn't write, or maybe you get a text message with a verification code you didn't request. On Android, a big red flag is seeing apps on your phone or in your Play Store "Library" that you never downloaded.

Check your Google Maps Timeline. If it shows you were at a shopping mall in a city you've never visited, someone else has your credentials. Another common sign is finding "Subscription Confirmed" emails for services you didn't join—hackers often use breached accounts to sign up for trials or premium services using saved payment methods. If anything feels off, even slightly, treat it as a breach. It’s better to be wrong and perform a 10-minute security check than to be right and lose your digital identity.

First 30 minutes

If you suspect a breach, the clock is ticking. Your first move is the Google Security Checkup. On your Android phone, go to Settings > Google > Manage your Google Account > Security. At the top, you'll see "Security recommendations." Tap that. It will show you a list of recent security events. If you see a device or a login location you don't recognize, that's your smoking gun.

Do not wait to get to a PC. Use your phone's browser or the settings menu to immediately remove the suspicious device. Tap the device name and select "Sign out." This kills their current session. However, if they have your password, they can just sign back in. This step is only about stopping the immediate bleeding while you prepare the local anesthetic.

Password rotation

Now, you have to change your password. This is the part everyone hates because it means updating it on every other device you own. Go back to the Security tab in your Google settings and tap Password. You’ll have to verify it's you—usually with your fingerprint or face scan on Android—and then pick something entirely new.

Do not just add a "1!" to the end of your old password. If a hacker got your old one through a phishing site or a data leak, they’ll guess your "new" one in seconds using a script. Use a password manager or let Chrome generate a long, random string. I use a 20-character mix of nonsense that I don't even try to memorize. This is also a good time to check if you’ve reused this password anywhere else. If you used the same password for Google and your bank, your bank is next on the attacker's list.

Killing active sessions

Killing active sessions
Illustration — Killing active sessions. Stock photograph, not an actual device screenshot.

Changing your password doesn't always automatically log out every single device. You need to do a manual sweep. In the Security tab, look for the section Your devices and tap Manage all devices. You'll see a list of every phone, tablet, and computer currently logged into your account.

I found a "Windows Chrome" session from three states away when I did this. I tapped it and hit Sign Out. Then I did it for every single device that wasn't the phone currently in my hand. Yes, it’s annoying to have to sign back into your iPad and your work laptop, but it’s the only way to ensure the intruder doesn't have a "backdoor" session still running. Android makes this fairly easy, but it’s a manual process—you have to tap each one individually. Think of it as clearing each room in a house to make sure no one is hiding under the bed.

Locking down recovery

This is the step most people forget. A smart attacker, once they get into your account, will immediately change the Recovery Email or Recovery Phone Number to their own. That way, when you try to reset your password, the code goes to them instead of you.

Go to your Google Account Security tab again. Scroll down to Ways we can verify it’s you. Check the Recovery phone and Recovery email. If you see an email address you don't recognize—even if it's just one letter off from yours—change it immediately. Also, check your Trusted Devices for 2-step verification. If the hacker added their own phone as a trusted device, they can bypass your password change. It’s an extra layer of "account persistence" that attackers love to use.

The week after

Once you've changed the password and kicked everyone out, the work isn't quite done. For the next seven days, you need to be hyper-vigilant. Check your Gmail Filters (you usually need to do this in a mobile browser set to "Desktop Mode" or on a computer). Scammers often set up a filter that automatically deletes emails from banks or Google Security, so you won't see their activity. If you find a filter that says "Delete all mail from no-reply@google.com," you know someone was trying to hide their tracks.

Also, keep a close eye on your bank statements and your "My Activity" log on Google. It’s a lot of work, and it frankly sucks that one leaked password can cause this much stress. But after a week of no weird activity, you can breathe again. Just remember: technology is never perfectly secure. The best we can do is make our accounts such a pain to crack that the hackers move on to an easier target. Using a unique password and checking your "Your devices" list once a month is usually enough to keep you out of the crosshairs.

Key takeaways

  • Signs of a breach is where you start — it's the fastest win.
  • First 30 minutes: don't skip this — it's where most users leave settings at risky defaults.
  • Password rotation: don't skip this — it's where most users leave settings at risky defaults.
  • Killing active sessions: don't skip this — it's where most users leave settings at risky defaults.
  • Recheck these settings quarterly; OEM updates can reset toggles.

Frequently asked questions

Does changing these settings break apps?
Almost never. Modern Android apps must handle a denied permission or restricted access gracefully — they either skip the feature or prompt again when needed.
Will this drain my battery?
No. If anything, restricting background access and disabling tracking pipelines reduces battery and data usage.
Do these steps apply to Android 13, 14 and 15?
Yes. The menu paths shift slightly between versions and OEM skins (Pixel/stock, Samsung One UI, Xiaomi HyperOS), but the underlying controls behave the same.

References & further reading

Continue reading

Related guides