# Gmail Hacked and Password Changed? How to Recover It

> Gmail hacked and the password changed? Start at Google's recovery page, then clear the forwarding, filters and delegates attackers leave behind. Malaysia tips.

- URL: https://www.awarexone.com/research/gmail-hacked-recovery
- Author: Md Shariar Shanaz Shuvon, Founder & CEO, AwareXone
- Published: 2026-09-29
- Topics: Google, Account security, Malaysia
- Related service: Account security: https://www.awarexone.com/services/account-security

## Short answer

Go to Google's account recovery page from the phone or computer you normally use, and answer every question as best you can. Wrong guesses will not lock you out. Once back in, remove any forwarding, filters and delegates the attacker added, then change passwords on accounts that reset through that inbox. Only Google decides whether to return it.

## Summary

- If someone changed your Gmail password, go to Google's account recovery page from the phone or computer you normally use and answer every question as best you can.
- Google says wrong guesses will not kick you out and there is no limit on attempts, so a failed try is a reason to retry carefully, not to give up.
- Once you are back in, check Gmail forwarding, filters, delegated access, POP and IMAP, because attackers use them to keep reading your mail after you change the password.
- Then change the password on every account that sends reset emails to that inbox, starting with your bank, social media and anything that stores payment details.
- You cannot call Google for sign-in help and Google does not work with recovery services, so anyone who offers to get your Gmail back or asks for your codes is not helping you.
- Only Google decides whether to return the account, and if recovery keeps failing its own advice is to create a new account with proper recovery options.

Your Gmail password stopped working this morning. There may be an email saying the password or recovery phone changed, and you did not change anything. That inbox also holds the keys to your bank alerts, Instagram, Shopee and photos.

The short answer: go to Google's recovery page (g.co/recover) from a device and place you normally use, answer every question, and reset the password. Then, before anything else, remove what the attacker left inside Gmail, because a forwarding rule or delegate can keep feeding them your mail after you are back in.

This guide covers the recovery steps, the Gmail settings hijackers change, the accounts linked to your inbox, and what to do in Malaysia if money was involved. Work and school accounts go through their administrator.

Last checked: 29 September 2026.

## How Do You Recover a Hacked Gmail Account?

Open [Google's account recovery page](https://accounts.google.com/signin/recovery) yourself (g.co/recover leads there) on the phone or computer you usually sign in with, in your usual browser, at home or at work. Answer every question with your best guess; Google's [recovery help page](https://support.google.com/accounts/answer/7682439?hl=en) says wrong guesses won't kick you out and there is no limit on attempts. Reset the password, then follow Google's [hacked account steps](https://support.google.com/accounts/answer/6294825?hl=en) and remove Gmail filters, forwarding and delegates you did not set up. There is no phone line, and nobody outside Google, including AwareXone, can approve the recovery for you.

## Where Are You Right Now? Pick Your Starting Point

A hacked Gmail can look different depending on how far the attacker got. Find the row that matches your screen. Wording varies by app version, language and region.

*Common signs of a hijacked Gmail and the first step for each, based on Google Account and Gmail Help pages at the time of writing.*

| What you see | What it usually means | What to do first |
| --- | --- | --- |
| Your password no longer works, and you did not change it | Someone else changed the password | Use the account recovery page from a familiar device and network |
| An alert about a sign-in or a change you do not recognise, but you can still sign in | Someone may have your password or session | Change the password now, then review security events and devices |
| A red bar in Gmail: "We've detected suspicious activity in your account." | Google has flagged unusual activity on the account | Follow the prompt from inside your account, not from an email link |
| A notice at the top of your inbox: "You are forwarding your email to [email address]" | A forwarding rule is sending copies of your mail elsewhere | If you did not set it up, change your password and disable forwarding |
| "Google couldn't verify this account belongs to you" | The recovery attempt did not collect enough proof this time | Retry with the tips below, or read our guide to that message |

## Locked Out: Using Google's Recovery Page the Right Way

Google's recovery flow compares your answers and your sign-in signals with what it knows about the account. Its [tips to complete account recovery steps](https://support.google.com/accounts/answer/7299973?hl=en) explain how to give it the strongest signal. Not every question below will appear for every account.

1. Use a phone, tablet or computer you often sign in from, the same browser you normally use, and a place you usually sign in, such as home or work. Turn off any VPN.
2. Type g.co/recover yourself rather than following a link from a message.
3. Answer every question. If unsure, guess rather than skip.
4. When asked for the last password you remember, enter the most recent one exactly, with the right capitals. If you cannot recall it, give an older one.
5. If asked for an email you can check now, give the recovery, alternate or contact email on the account. If you cannot reach a code sent to Gmail itself, select "Try another way".
6. Check the spam folder of that other address for an email titled "Your Google support inquiry".
7. Reset the password when prompted, using one you have never used on this account or anywhere else.

There is one piece of timing in your favour. Google's page on [recovery options](https://support.google.com/accounts/answer/183723?hl=en) says that when recovery info or other sign-in factors change, Google may send codes to your previous info for 7 days, so that the real owner can secure the account quickly. If the attacker changed your recovery phone yesterday, your old number may still receive a code, so start today.

If the attempt ends with "Google couldn't verify this account belongs to you", Google says you can try again. Our guide to [what that message means and how to retry](https://www.awarexone.com/research/google-couldnt-verify-account-belongs-to-you) goes through the dead ends and the 7-day wait in detail.

## Is the "Your Password Was Changed" Email Real?

It may be real, and it may be bait. Google's [security alerts page](https://support.google.com/accounts/answer/2590353?hl=en) says it emails or notifies you when someone signs in on a new device, when there is suspicious activity such as an unusual number of emails sent, and when it blocks a sensitive action. A real alert shows the device type, time and location, with a "No, secure account" option.

Phishing emails copy that look, so treat the email as a prompt, not a path. Close it, open myaccount.google.com in a browser yourself, and check the "Recent security events" panel. Google's [recovery tips](https://support.google.com/accounts/answer/7299973?hl=en) say to enter your password or codes only at accounts.google.com, and that Google never asks for them by email, phone call or message.

## Back In? Secure the Google Account in This Order

Changing the password is step one. Google's [hacked account page](https://support.google.com/accounts/answer/6294825?hl=en) lists the settings attackers change so they can return.

1. Review security events: in your Google Account, open "Security & sign-in", then "Review security events". Select "No, it wasn't me" on anything you did not do and follow the steps.
2. Sign out unknown devices: under "Your devices", select "Manage all devices". Google's [devices page](https://support.google.com/accounts/answer/3067630?hl=en) says one device can show several sessions, so sign out of every session you are not sure about.
3. Fix the recovery phone and recovery email. Google treats unfamiliar changes to these, to your name, and to 2-Step Verification as signs of a hack.
4. Remove third-party access: on the [linked apps page](https://support.google.com/accounts/answer/13533235?hl=en), open "Access to your Google Account" and select "Remove access" for anything you do not recognise.
5. Turn on 2-Step Verification. Google's [2-Step Verification page](https://support.google.com/accounts/answer/185839?hl=en) recommends passkeys or Google prompts over SMS codes, and says prompts help protect against SIM swap.
6. Check Google Pay, Play purchases, Chrome extensions, Drive activity, shared Photos albums and Location Sharing for anything you did not set up.

If you see a warning that a sign-in method was disabled, Google says it removes suspicious methods and gives you 30 days from the warning to confirm you added it. If you did not add it, leave it disabled.

## The Gmail Settings Attackers Change to Stay In

A new password stops new sign-ins, but some Gmail settings keep working without one. Google's [Gmail security tips](https://support.google.com/mail/answer/7036019?hl=en) tell you to check each tab below. Open Gmail on a computer, then "Settings" and "See all settings".

*Gmail settings to check after a takeover. Google's hacked account page lists each one as a setting to correct if it changed without you.*

| Setting and where to find it | How an attacker can use it | What to do |
| --- | --- | --- |
| Forwarding ("Forwarding and POP/IMAP" tab) | Copies of every new email, including reset codes, go to their address | Select "Disable forwarding" and "Save Changes" |
| Filters ("Filters and Blocked Addresses" tab) | A "Forward it" filter sends only bank or reset emails; a "Delete it" filter hides Google's alerts | Delete every filter you did not create |
| Delegates ("Accounts and Import", "Grant access to your account") | A delegate can read, send and delete your email | Delete unknown delegates; Google says to change your password if you find one |
| POP and IMAP ("Forwarding and POP/IMAP" tab) | A mail app elsewhere can keep downloading your messages | Turn off any access you do not use yourself |
| "Send mail as" and "Check mail from other accounts" ("Accounts and Import") | Mail can be sent as, or pulled from, an address that is not yours | Remove any address that does not belong to you |
| Signature and vacation responder ("General" tab) | Text or a link can be added to every email you send | Check the text looks correct and switch off an auto reply you did not set |

Delegates deserve a second look. Google's [delegation page](https://support.google.com/mail/answer/138350?hl=en) says a delegate can still reach an account even when its password has expired, and that to stop ongoing access you should reset the password or remove the delegate. Do both. Google's [forwarding page](https://support.google.com/mail/answer/10957?hl=en) gives the same instruction for a forwarding notice you never set up: change your password immediately, then turn forwarding off.

Finally, scroll to the bottom right of your inbox and select "Details". Google's [last account activity page](https://support.google.com/mail/answer/45938?hl=en) says this shows the last 10 IP addresses that used Gmail, plus the access type, including POP or IMAP. An access type you never use is a warning sign.

## Why Your Inbox Puts Every Other Account at Risk

Whoever controls your email can press "Forgot password" on nearly any site and read the reset link. That is why attackers take the inbox first. Google's hacked account page says to change passwords for apps and sites that use the same password, that contact you at that address, where you sign in with it, and where you saved passwords in your Google Account.

To see what the attacker may have touched, search your mail. Gmail's [search operators](https://support.google.com/mail/answer/7190?hl=en) help: in:anywhere includes Spam and Trash, and newer_than:7d limits results to the last week. Try in:anywhere password newer_than:7d, then check Sent for emails you never wrote.

- Online banking and e-wallets first, then any shopping account with a saved card.
- Instagram, Facebook, TikTok and WhatsApp, which usually send login codes or links to this inbox.
- Other email accounts that list this Gmail as their recovery address.

If a social account has already gone, our guide on [what to do when someone logged into your account](https://www.awarexone.com/research/someone-logged-into-my-account) covers the first response across platforms.

## Mistakes That Hand the Account Back to the Attacker

- Changing the password but leaving a forwarding rule, filter or delegate in place.
- Trying recovery on a borrowed phone, a new laptop or over a VPN, then giving up after one failure.
- Clicking the link in a "password changed" email instead of typing the address yourself.
- Reusing an old password, or the same password on your bank and your email.
- Waiting a week, so Google stops sending codes to the recovery details the attacker replaced.

> Warning: **Nobody can phone Google for you.** Google's recovery page says you cannot call Google for help signing in and that it does not work with any service claiming to provide account or password support. Its 2-Step Verification page adds that you will not get a call from Google to verify a code. So a "Google support" number found in an ad, or a seller offering to recover Gmail for a fee, is not connected to Google. Never share your password, a verification code or a backup code with anyone, and ignore anyone selling "Gmail hacking" or password cracking, whatever language the offer is in.

## If Money Moved or You Shared a Code in Malaysia

Deal with the money first. Google's hacked account page says to contact your bank if card details were saved in Google Pay or Chrome. The NSRC's [FAQ on the NFCC website](https://nfcc.jpm.gov.my/index.php/en/about-nsrc) says to call your bank's 24-hour hotline or the NSRC on 997 as soon as you see an unauthorised transaction, then make a police report at the nearest station, within 24 hours. It also says NSRC, PDRM, MCMC, BNM and banks will never ask for your password, PIN, TAC or OTP.

A fake Google sign-in page or phishing email can be reported to CyberSecurity Malaysia's [Cyber999 incident response centre](https://www.cybersecurity.my/portal-main/services/cyber999-overview), which takes reports by online form, email, phone and its app. If your phone suddenly shows "No service" while codes stop arriving, call your carrier from another phone and ask whether your SIM was replaced. If you lost that phone number for good, our guide to [Google 2-Step Verification after losing your phone](https://www.awarexone.com/research/google-2-step-verification-lost-phone) explains the backup routes.

## When Recovery Keeps Failing

Google's recovery help page says changes to recovery info may take up to 7 days to take effect, so try again in a few days. If you still cannot get in, Google's advice is to create a new Google Account and set up recovery options properly. Meanwhile, warn contacts from another channel and move your bank and social accounts to an email you control. If the account ran a YouTube channel, see our guide to [recovering a hacked YouTube channel](https://www.awarexone.com/research/youtube-channel-hacked-recovery).

## When a Case Review Makes Sense

Most people can recover Gmail alone with the steps above. A second opinion helps when the same attacker also took your social accounts or a business depends on that inbox. SocialSafe by AwareXone, our recovery service, looks at the case first and tells you honestly whether you already have what you need, and works only through official recovery processes. You can read how our [account security service](https://www.awarexone.com/services/account-security) works, and our [Trust Center](https://www.awarexone.com/trust) sets out what we never ask for, starting with your password and codes.

> Note: **Google makes the final decision.** Only Google can return a Google Account. Some accounts come back on the first attempt, some after several, and some are not recovered at all.

## Frequently Asked Questions

### Can I recover my Gmail if the hacker changed the recovery phone and email?

Often, yes. Google may keep sending codes to your previous recovery details for 7 days after a change, and the recovery page also weighs your device, location and past passwords, so start from a familiar device as soon as you can.

### Is there a Google phone number I can call to recover my account?

No. Google says you cannot call it for sign-in help, so any number claiming to be Google account support is not Google.

### Does changing my Gmail password log the hacker out?

It stops new sign-ins with the old password, but a delegate, forwarding rule or connected app can keep working. Sign out unknown devices and remove those settings as well.

### How can I tell if someone is still reading my Gmail?

Select "Details" at the bottom right of your inbox to see recent access types and IP addresses, and check your devices list and forwarding settings. Anything unfamiliar means it needs securing again.

## Official sources

- [Google Account Help: Secure a hacked or compromised Google Account (read 29 September 2026)](https://support.google.com/accounts/answer/6294825?hl=en)
- [Google Account Help: How to recover your Google Account or Gmail (read 29 September 2026)](https://support.google.com/accounts/answer/7682439?hl=en)
- [Google Account Help: Tips to complete account recovery steps (read 29 September 2026)](https://support.google.com/accounts/answer/7299973?hl=en)
- [Google Account Help: Set up recovery options (read 29 September 2026)](https://support.google.com/accounts/answer/183723?hl=en)
- [Google Account Help: Respond to security alerts (read 29 September 2026)](https://support.google.com/accounts/answer/2590353?hl=en)
- [Google Account Help: See devices with account access (read 29 September 2026)](https://support.google.com/accounts/answer/3067630?hl=en)
- [Google Account Help: Manage links between your Google Account and apps from other developers (read 29 September 2026)](https://support.google.com/accounts/answer/13533235?hl=en)
- [Google Account Help: Turn on 2-Step Verification (read 29 September 2026)](https://support.google.com/accounts/answer/185839?hl=en)
- [Gmail Help: Automatically forward Gmail messages to another account (read 29 September 2026)](https://support.google.com/mail/answer/10957?hl=en)
- [Gmail Help: Delegate and collaborate on email (read 29 September 2026)](https://support.google.com/mail/answer/138350?hl=en)
- [Gmail Help: Gmail security tips (read 29 September 2026)](https://support.google.com/mail/answer/7036019?hl=en)
- [Gmail Help: Last account activity (read 29 September 2026)](https://support.google.com/mail/answer/45938?hl=en)
- [Gmail Help: Refine searches in Gmail (read 29 September 2026)](https://support.google.com/mail/answer/7190?hl=en)
- [NFCC: National Scam Response Centre FAQ (read 29 September 2026)](https://nfcc.jpm.gov.my/index.php/en/about-nsrc)
- [CyberSecurity Malaysia: Cyber999 Cyber Incident Response Center (read 29 September 2026)](https://www.cybersecurity.my/portal-main/services/cyber999-overview)

---

AwareXone is an independent Malaysia-based provider, not affiliated with any platform. The platform makes the final decision on every account. AwareXone never asks for passwords, OTP codes, backup codes or session cookies.
