Use Google’s official recovery route from a trusted device, then remove attacker access and protect every account that depends on the email address.
Step-by-step checks
1. Use the official recovery route
If you cannot sign in, manually open Google Account Recovery. Do not use a recovery link sent by an unknown person or advertised support service.
2. Review security events
In Google Account, review recent security events and mark activity that was not yours. Check signed-in devices and remove devices you do not recognise.
3. Change access safely
Set a new unique password and enable 2-Step Verification. Store recovery codes separately and never read a verification code to a caller.
4. Remove persistence
Review Gmail forwarding, filters, labels, delegates, recovery details and connected applications. An attacker may leave access in place after a password change.
5. Protect linked accounts
Change reused passwords and review financial, shopping, cloud and social accounts that use Gmail for password recovery. Preserve evidence of suspicious activity.
When to stop
Contact financial providers or relevant authorities immediately if payment data, identity documents or impersonation may be involved.
What to tell an expert
Share the device model, operating system, exact symptom or error, when it began, what changed beforehand, and which checks you completed. Do not send passwords, one-time codes, encryption recovery keys, or unnecessary personal files.
Official reference
This Supportia guide was prepared with current official guidance as a factual baseline. Interface names can still vary by device and version. Open the official reference.
Did this solve your problem?
Your answer helps Supportia prioritize updates. No account or email is required.
