SecurCheckCyber Centre

GOOGLE WORKSPACE · DRIVE · CLOUD · YOUTUBE

Google account hacked: what to do? A recovery and security guide

Secur Cloud ·

A Google Account may provide access to more than Gmail: Drive documents, a YouTube channel, synced data and Cloud resources depending on its permissions. An intrusion can expose sensitive information, alter content or generate unauthorised charges.

Here is how to perform a Google account security assessment and organise your response. Do not delay securing clearly unauthorised activity to finish a checklist; at work, alert IT immediately.

1. Identify signs of a compromised Google Account

  1. Unusual security alerts

    Review an unfamiliar device or unrecognised activity by opening your Google Account directly. Location can be approximate and several sessions can belong to one device: compare dates and your own activity before drawing conclusions.

  2. Changed or shared documents

    Drive files are deleted, changed or shared with unexpected people. Review available activity and versions. Downloads are not always visible in your interface: a missing trace does not prove no copy was made.

  3. Unknown resources or spending

    Unauthorised Cloud projects, resources or Ads campaigns should trigger an alert. A billing increase alone may have a legitimate cause; compare it with recent changes and available logs.

  4. Anomalies in connected services

    Check changes to your YouTube channel and services using “Sign in with Google”. This sign-in method does not automatically grant access to every third-party account, but each permission and session needs review.

2. Assess your Google Account without exposing access

  1. Recent activity and sessions

    From a trusted device, open myaccount.google.com directly, then “Security & sign-in”. Record unrecognised events, times and affected devices. At work, send this context to your administrator without waiting to finish the assessment.

  2. Third-party apps and OAuth

    Review connected apps and their data permissions. Remove unknown authorisations and have IT verify business apps. Also review sessions within third-party services: removing a Google connection does not delete data already copied.

  3. Recovery, passkeys and backup codes

    Review recovery email and phone, security keys, passkeys and other registered methods. Remove unauthorised additions. If backup codes may have been exposed, generate a new set in Google: the old set becomes inactive. Never share a code with an assessment tool.

3. A response checklist to secure the account

  1. Change your password promptly

    If you observe unauthorised activity, use a trusted device to choose a long, unique password stored in a password manager. Change it wherever you reused it. If locked out, use Google’s official recovery flow or contact the administrator of your managed account.

  2. Sign out sessions and address other access

    Under “Your devices”, review and sign out unfamiliar sessions, including those sharing a device name. Do not assume one button instantly invalidates every access path: authorised apps and Cloud credentials require separate checks.

  3. Restore recovery methods

    Correct altered recovery details and remove unauthorised sign-in methods. Make sure you retain a safe way to regain access. For a work account, coordinate changes with IT.

  4. Review sharing and permissions

    Remove unauthorised external access to sensitive files and have administrative roles reviewed across affected services. Preserve useful evidence without delaying containment. Revoking a share does not retrieve an already downloaded copy.

Open Google’s official account recovery

4. Review each exposed service

  1. Google Drive and Workspace

    Review sharing, activity and versions of affected documents. Administrators can investigate available logs depending on edition and configuration. Also check email forwarding, filters and delegation, which can sustain a leak.

  2. Google Cloud and Ads

    Have an authorised administrator review IAM roles, service-account keys, exposed credentials, created resources and billing. Changing a Google password does not delete a service-account key. Response must address persistent keys and issued tokens using the appropriate Cloud procedure. For Ads, review unauthorised users, campaigns and spending.

  3. YouTube

    Recover the associated Google Account first, then review channel permissions, videos, streams and configuration changes. Use official YouTube support for channel recovery and cleanup.

Strengthen authentication and monitor access

Phishing-resistant passkeys and security keys reduce the risk of entering credentials on a fake site. They do not make theft of an existing session or device compromise impossible. Combine them with permission reviews, endpoint security and monitoring after the incident.

Checking a suspicious Google account helps organise the investigation; a self-reported assessment cannot certify that every service is safe.

Read also: the Gmail assessment guide

Deploy SecurCheck Business to support administrators and staff

Official references