An envelope merged with a padlock drawn in blue binary digits on a dark background, beside the headline Gmail Hacked? Get It Back.

Gmail Hacked and Password Changed? How to Recover It

Gmail hacked and the password changed? Start at Google's recovery page, then clear the forwarding, filters and delegates attackers leave behind. Malaysia tips.

11 min read
Short answer

Go to Google's account recovery page from the phone or computer you normally use, and answer every question as best you can. Wrong guesses will not lock you out. Once back in, remove any forwarding, filters and delegates the attacker added, then change passwords on accounts that reset through that inbox. Only Google decides whether to return it.

Summary
  • If someone changed your Gmail password, go to Google's account recovery page from the phone or computer you normally use and answer every question as best you can.
  • Google says wrong guesses will not kick you out and there is no limit on attempts, so a failed try is a reason to retry carefully, not to give up.
  • Once you are back in, check Gmail forwarding, filters, delegated access, POP and IMAP, because attackers use them to keep reading your mail after you change the password.
  • Then change the password on every account that sends reset emails to that inbox, starting with your bank, social media and anything that stores payment details.
  • You cannot call Google for sign-in help and Google does not work with recovery services, so anyone who offers to get your Gmail back or asks for your codes is not helping you.
  • Only Google decides whether to return the account, and if recovery keeps failing its own advice is to create a new account with proper recovery options.
Table of contents12 sections
  1. 01How Do You Recover a Hacked Gmail Account?
  2. 02Where Are You Right Now? Pick Your Starting Point
  3. 03Locked Out: Using Google's Recovery Page the Right Way
  4. 04Is the "Your Password Was Changed" Email Real?
  5. 05Back In? Secure the Google Account in This Order
  6. 06The Gmail Settings Attackers Change to Stay In
  7. 07Why Your Inbox Puts Every Other Account at Risk
  8. 08Mistakes That Hand the Account Back to the Attacker
  9. 09If Money Moved or You Shared a Code in Malaysia
  10. 10When Recovery Keeps Failing
  11. 11When a Case Review Makes Sense
  12. 12Frequently Asked Questions

Your Gmail password stopped working this morning. There may be an email saying the password or recovery phone changed, and you did not change anything. That inbox also holds the keys to your bank alerts, Instagram, Shopee and photos.

The short answer: go to Google's recovery page (g.co/recover) from a device and place you normally use, answer every question, and reset the password. Then, before anything else, remove what the attacker left inside Gmail, because a forwarding rule or delegate can keep feeding them your mail after you are back in.

This guide covers the recovery steps, the Gmail settings hijackers change, the accounts linked to your inbox, and what to do in Malaysia if money was involved. Work and school accounts go through their administrator.

Last checked: 29 September 2026.

#How Do You Recover a Hacked Gmail Account?

Open Google's account recovery page yourself (g.co/recover leads there) on the phone or computer you usually sign in with, in your usual browser, at home or at work. Answer every question with your best guess; Google's recovery help page says wrong guesses won't kick you out and there is no limit on attempts. Reset the password, then follow Google's hacked account steps and remove Gmail filters, forwarding and delegates you did not set up. There is no phone line, and nobody outside Google, including AwareXone, can approve the recovery for you.

#Where Are You Right Now? Pick Your Starting Point

A hacked Gmail can look different depending on how far the attacker got. Find the row that matches your screen. Wording varies by app version, language and region.

Common signs of a hijacked Gmail and the first step for each, based on Google Account and Gmail Help pages at the time of writing.
What you seeWhat it usually meansWhat to do first
Your password no longer works, and you did not change itSomeone else changed the passwordUse the account recovery page from a familiar device and network
An alert about a sign-in or a change you do not recognise, but you can still sign inSomeone may have your password or sessionChange the password now, then review security events and devices
A red bar in Gmail: "We've detected suspicious activity in your account."Google has flagged unusual activity on the accountFollow the prompt from inside your account, not from an email link
A notice at the top of your inbox: "You are forwarding your email to [email address]"A forwarding rule is sending copies of your mail elsewhereIf you did not set it up, change your password and disable forwarding
"Google couldn't verify this account belongs to you"The recovery attempt did not collect enough proof this timeRetry with the tips below, or read our guide to that message

#Locked Out: Using Google's Recovery Page the Right Way

Google's recovery flow compares your answers and your sign-in signals with what it knows about the account. Its tips to complete account recovery steps explain how to give it the strongest signal. Not every question below will appear for every account.

  1. Use a phone, tablet or computer you often sign in from, the same browser you normally use, and a place you usually sign in, such as home or work. Turn off any VPN.
  2. Type g.co/recover yourself rather than following a link from a message.
  3. Answer every question. If unsure, guess rather than skip.
  4. When asked for the last password you remember, enter the most recent one exactly, with the right capitals. If you cannot recall it, give an older one.
  5. If asked for an email you can check now, give the recovery, alternate or contact email on the account. If you cannot reach a code sent to Gmail itself, select "Try another way".
  6. Check the spam folder of that other address for an email titled "Your Google support inquiry".
  7. Reset the password when prompted, using one you have never used on this account or anywhere else.

There is one piece of timing in your favour. Google's page on recovery options says that when recovery info or other sign-in factors change, Google may send codes to your previous info for 7 days, so that the real owner can secure the account quickly. If the attacker changed your recovery phone yesterday, your old number may still receive a code, so start today.

If the attempt ends with "Google couldn't verify this account belongs to you", Google says you can try again. Our guide to what that message means and how to retry goes through the dead ends and the 7-day wait in detail.

#Is the "Your Password Was Changed" Email Real?

It may be real, and it may be bait. Google's security alerts page says it emails or notifies you when someone signs in on a new device, when there is suspicious activity such as an unusual number of emails sent, and when it blocks a sensitive action. A real alert shows the device type, time and location, with a "No, secure account" option.

Phishing emails copy that look, so treat the email as a prompt, not a path. Close it, open myaccount.google.com in a browser yourself, and check the "Recent security events" panel. Google's recovery tips say to enter your password or codes only at accounts.google.com, and that Google never asks for them by email, phone call or message.

#Back In? Secure the Google Account in This Order

Changing the password is step one. Google's hacked account page lists the settings attackers change so they can return.

  1. Review security events: in your Google Account, open "Security & sign-in", then "Review security events". Select "No, it wasn't me" on anything you did not do and follow the steps.
  2. Sign out unknown devices: under "Your devices", select "Manage all devices". Google's devices page says one device can show several sessions, so sign out of every session you are not sure about.
  3. Fix the recovery phone and recovery email. Google treats unfamiliar changes to these, to your name, and to 2-Step Verification as signs of a hack.
  4. Remove third-party access: on the linked apps page, open "Access to your Google Account" and select "Remove access" for anything you do not recognise.
  5. Turn on 2-Step Verification. Google's 2-Step Verification page recommends passkeys or Google prompts over SMS codes, and says prompts help protect against SIM swap.
  6. Check Google Pay, Play purchases, Chrome extensions, Drive activity, shared Photos albums and Location Sharing for anything you did not set up.

If you see a warning that a sign-in method was disabled, Google says it removes suspicious methods and gives you 30 days from the warning to confirm you added it. If you did not add it, leave it disabled.

#The Gmail Settings Attackers Change to Stay In

A new password stops new sign-ins, but some Gmail settings keep working without one. Google's Gmail security tips tell you to check each tab below. Open Gmail on a computer, then "Settings" and "See all settings".

Gmail settings to check after a takeover. Google's hacked account page lists each one as a setting to correct if it changed without you.
Setting and where to find itHow an attacker can use itWhat to do
Forwarding ("Forwarding and POP/IMAP" tab)Copies of every new email, including reset codes, go to their addressSelect "Disable forwarding" and "Save Changes"
Filters ("Filters and Blocked Addresses" tab)A "Forward it" filter sends only bank or reset emails; a "Delete it" filter hides Google's alertsDelete every filter you did not create
Delegates ("Accounts and Import", "Grant access to your account")A delegate can read, send and delete your emailDelete unknown delegates; Google says to change your password if you find one
POP and IMAP ("Forwarding and POP/IMAP" tab)A mail app elsewhere can keep downloading your messagesTurn off any access you do not use yourself
"Send mail as" and "Check mail from other accounts" ("Accounts and Import")Mail can be sent as, or pulled from, an address that is not yoursRemove any address that does not belong to you
Signature and vacation responder ("General" tab)Text or a link can be added to every email you sendCheck the text looks correct and switch off an auto reply you did not set

Delegates deserve a second look. Google's delegation page says a delegate can still reach an account even when its password has expired, and that to stop ongoing access you should reset the password or remove the delegate. Do both. Google's forwarding page gives the same instruction for a forwarding notice you never set up: change your password immediately, then turn forwarding off.

Finally, scroll to the bottom right of your inbox and select "Details". Google's last account activity page says this shows the last 10 IP addresses that used Gmail, plus the access type, including POP or IMAP. An access type you never use is a warning sign.

#Why Your Inbox Puts Every Other Account at Risk

Whoever controls your email can press "Forgot password" on nearly any site and read the reset link. That is why attackers take the inbox first. Google's hacked account page says to change passwords for apps and sites that use the same password, that contact you at that address, where you sign in with it, and where you saved passwords in your Google Account.

To see what the attacker may have touched, search your mail. Gmail's search operators help: in:anywhere includes Spam and Trash, and newer_than:7d limits results to the last week. Try in:anywhere password newer_than:7d, then check Sent for emails you never wrote.

  • Online banking and e-wallets first, then any shopping account with a saved card.
  • Instagram, Facebook, TikTok and WhatsApp, which usually send login codes or links to this inbox.
  • Other email accounts that list this Gmail as their recovery address.

If a social account has already gone, our guide on what to do when someone logged into your account covers the first response across platforms.

#Mistakes That Hand the Account Back to the Attacker

  • Changing the password but leaving a forwarding rule, filter or delegate in place.
  • Trying recovery on a borrowed phone, a new laptop or over a VPN, then giving up after one failure.
  • Clicking the link in a "password changed" email instead of typing the address yourself.
  • Reusing an old password, or the same password on your bank and your email.
  • Waiting a week, so Google stops sending codes to the recovery details the attacker replaced.

#If Money Moved or You Shared a Code in Malaysia

Deal with the money first. Google's hacked account page says to contact your bank if card details were saved in Google Pay or Chrome. The NSRC's FAQ on the NFCC website says to call your bank's 24-hour hotline or the NSRC on 997 as soon as you see an unauthorised transaction, then make a police report at the nearest station, within 24 hours. It also says NSRC, PDRM, MCMC, BNM and banks will never ask for your password, PIN, TAC or OTP.

A fake Google sign-in page or phishing email can be reported to CyberSecurity Malaysia's Cyber999 incident response centre, which takes reports by online form, email, phone and its app. If your phone suddenly shows "No service" while codes stop arriving, call your carrier from another phone and ask whether your SIM was replaced. If you lost that phone number for good, our guide to Google 2-Step Verification after losing your phone explains the backup routes.

#When Recovery Keeps Failing

Google's recovery help page says changes to recovery info may take up to 7 days to take effect, so try again in a few days. If you still cannot get in, Google's advice is to create a new Google Account and set up recovery options properly. Meanwhile, warn contacts from another channel and move your bank and social accounts to an email you control. If the account ran a YouTube channel, see our guide to recovering a hacked YouTube channel.

#When a Case Review Makes Sense

Most people can recover Gmail alone with the steps above. A second opinion helps when the same attacker also took your social accounts or a business depends on that inbox. SocialSafe by AwareXone, our recovery service, looks at the case first and tells you honestly whether you already have what you need, and works only through official recovery processes. You can read how our account security service works, and our Trust Center sets out what we never ask for, starting with your password and codes.

#Frequently Asked Questions

Can I recover my Gmail if the hacker changed the recovery phone and email?
Often, yes. Google may keep sending codes to your previous recovery details for 7 days after a change, and the recovery page also weighs your device, location and past passwords, so start from a familiar device as soon as you can.
Is there a Google phone number I can call to recover my account?
No. Google says you cannot call it for sign-in help, so any number claiming to be Google account support is not Google.
Does changing my Gmail password log the hacker out?
It stops new sign-ins with the old password, but a delegate, forwarding rule or connected app can keep working. Sign out unknown devices and remove those settings as well.
How can I tell if someone is still reading my Gmail?
Select "Details" at the bottom right of your inbox to see recent access types and IP addresses, and check your devices list and forwarding settings. Anything unfamiliar means it needs securing again.

Official sources

Need help with your account?

Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: Account security.