SecurCheckCyber Centre

GMAIL · GOOGLE WORKSPACE

How to check a hacked Gmail account: a practical assessment guide

Secur Cloud ·

A personal or business Gmail mailbox holds conversations, documents and account recovery links. Unauthorised access can expose data and enable fraudulent payment requests to your contacts.

This guide helps you perform a Gmail account assessment and prioritise action. If you observe clearly unauthorised activity, secure the account immediately from a trusted device and alert your IT team without waiting to finish reading.

1. Warning signs of a Gmail intrusion

  1. Messages sent without your knowledge

    Contacts report suspicious links, unexpected attachments or requests for money apparently coming from you. Check sent messages and account activity: a sender address can also be spoofed without mailbox access.

  2. Alerts and unfamiliar devices

    Review a sign-in alert by opening your Google Account directly, without following the message link. Approximate locations or multiple sessions on the same device do not alone prove an intrusion. Check the context and report activity you do not recognise.

  3. Changed account settings

    A rejected password or recovery details changed without your approval are important warning signs. Also check recently added sign-in methods.

  4. Disappearing emails

    Notifications or invoices are archived, deleted or missing. A legitimate rule may explain this, but an unauthorised filter can also conceal fraud.

2. How to assess your Gmail account

Never share your password, an MFA code or a recovery code with an assessment tool. Perform the following checks in Google’s official interfaces.

  1. Activity and devices

    In your Google Account, open “Security & sign-in”, then recent activity and “Your devices”. Review relevant sessions, dates and context. Follow Google’s security flow if you do not recognise an activity.

  2. Gmail forwarding, filters and delegation

    On a computer, open Gmail and “See all settings”. Check automatic forwarding, filters and blocked addresses, and delegated accounts. Look for unknown destinations or rules that forward, archive or delete messages. Record findings useful to IT before correcting them, without delaying containment.

  3. Authorised apps and extensions

    Review third-party connections in your Google Account. Remove permissions you did not grant. Check browser extensions separately: not all appear in this list. At work, ask your administrator to verify business applications.

3. Immediate steps to regain control

  1. Change your password immediately

    From a trusted device, open Google directly and choose a long, unique password stored in a password manager. Change it on services where you reused it. Do not wait to finish an assessment if you observe unauthorised activity.

  2. Sign out sessions and review access

    Sign out unfamiliar devices and sessions, including multiple sessions for the same suspicious device. Password changes and sign-outs do not replace reviewing authorised apps and sign-in methods. For Google Workspace, alert your administrator immediately so they can address access and investigate logs.

  3. Restore recovery details and settings

    Correct altered recovery details, remove unknown sign-in methods, and delete unauthorised forwarding, filters or delegation. If you cannot sign in, use Google’s official recovery process; for a managed account, contact your administrator.

  4. Strengthen two-step verification

    Enable two-step verification and review registered methods. Prefer phishing-resistant security keys and passkeys where available. An authenticator app improves protection but does not guarantee immunity to phishing or session theft.

Open Google’s official account recovery

4. Build regular security checks into team habits

After securing the account, monitor activity and warn affected contacts if fraudulent messages were sent. Ask finance staff to verify bank-detail changes and payment requests received during the incident. Your administrator should also assess potentially exposed data and services.

Checking a suspicious Gmail account is a useful habit alongside unique passwords, stronger authentication and prompt reporting. A self-reported assessment cannot certify that a mailbox is safe.

Read also: has my account been hacked?

Deploy SecurCheck Business to support your teams

Official Google references