How to Tell If Your Google Account Has Been Compromised

    Seven quick checks to confirm whether someone else has been inside the Google account that runs your phone — and how to shut every foothold behind them.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated July 2026 · 6 min read

    Your Google account is the master key to your phone, your inbox and years of photos and files — so a suspicion that someone else has been inside it deserves a real answer, not a guess. The checks below give you one. In a few minutes they show whether another person has actually signed in, and just as importantly they surface the quiet footholds an intruder plants for later — extra sign-in methods, connected apps, mail rules that hide the evidence — so each one can be shut behind them.

    Seven checks for unauthorised access

    1

    Start with Recent security activity

    From a device and browser that are yours, log in at accounts.google.com, open Security & sign-in from the left menu and find Recent security activity. Click Review security activity for the complete record of sign-ins and alerts across the last 28 days.
    Location comes from IP addresses, so a sign-in from a neighbouring city can easily be you. What deserves attention: hardware or operating systems you don't own, activity at hours you were asleep or offline, and events that don't line up with anything you did.

    One more wrinkle: browsing through a VPN or relay service (iCloud Private Relay included) can make your own sessions appear from odd or faraway places.
    accounts.google.com
    Google

    Welcome

    Aalex.taylor@gmail.com

    Forgot password?

    Next

    Google's Recent security activity list showing an unfamiliar new sign-in from another country

    2

    Act on anything unfamiliar

    Open the suspicious entry inside Recent security activity. Google displays the device and rough location and asks Do you recognize this activity? Answering No, secure account starts an immediate walkthrough — new password, that session ended — which throws the intruder out on the spot.
    Realise it was actually you — a fresh handset, travel, a VPN? Yes, it was me clears the alert.
    myaccount.google.com/notifications
    Google AccountA

    Recent security activity

    Security activity and alerts from the last 28 days. Learn more

    See unfamiliar activity?

    June 16, 2026

    2:47 AM

    New sign-in on Windows

    Frankfurt, Germany

    Windows

    June 15, 2026

    4:40 PM

    New sign-in on Android

    New
    Android

    Opening a suspicious sign-in from Recent security activity and choosing No, secure account

    3

    Read the full device list

    Scroll the Security & sign-in page to Your devices and open Manage all devices. Every active session on your account lives here — open anything you can't place and hit Sign out.
    This list matters more than the activity feed when access may have gone on for a while: Recent security activity stops at 28 days, but a session opened months ago can still be running here quietly, long after the sign-in that created it scrolled out of view.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Backup codes · 10 codes available

    Your devices

    Where you're signed in

    3 sessions on Windows computer(s)

    Windows, Windows, …

    1 session on Android phone

    Android

    Find a lost device

    Manage all devices

    4

    Security page Your devices section, then Manage all devices showing every active session

    4

    Audit every way into the account

    Intruders rarely leave without planting a spare key. Check the recovery options first: on Security & sign-in, confirm the recovery email and phone are yours and remove or reset anything unfamiliar — a recovery route they control means they can simply reset your password again next month.

    Next, open 2-Step Verification and go through the Second steps list item by item. An extra authenticator, phone or passkey you never added is a standing invitation — delete it.

    Last, the backup codes: if a set exists you don't remember creating, or you're simply unsure, hit Get new codes. The fresh set kills every old code instantly, including any the intruder wrote down.

    myaccount.google.com/security
    Google AccountA

    Security & sign-in

    Ways we can verify it's you

    Recovery info helps confirm it's really you — make sure none of it belongs to someone else.

    Recovery email

    a•••@mail.ru · don't recognise this?

    Remove

    Recovery phone

    •••• ••89

    2-Step Verification

    ● On

    2-Step Verification second steps with an unrecognised method, then regenerating backup codes to invalidate old ones

    5

    Inspect connected apps

    Return to Security & sign-in and find Your linked apps, then See all linked apps. Names reveal nothing on their own — open each app you don't recognise and read its actual permissions. Broad reach into Gmail, contacts or Drive that you never granted? Delete all revokes it. A connected app is a favourite way to keep reading your data straight through a password change.
    Judge apps by their permissions, never their branding — innocuous names can carry full mailbox rights.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Manage all devices

    4 ›

    Your linked apps

    Keep track of your Google Account data

    Bing Webmaster Tools

    Proton

    Inbox Cleaner

    See all linked apps

    3

    Security page Your linked apps section, then See all linked apps showing every app with access

    6

    Sweep the mail filters

    Your account's inbox deserves its own look. In Gmail on a computer, open Settings → See all settings → Filters and Blocked Addresses. Planting a filter that deletes, archives or marks-as-read incoming security alerts is a classic move — it silences the very emails that would have warned you. Remove every filter you didn't make.
    The Gmail app doesn't expose these settings — use a computer, or request the desktop site in your phone's browser.
    M
    Search mail
    GGoogleSecurity alert9:14 AM
    NNetflixYour receipt for AugustYesterday
    LLinkedInYou appeared in 4 searchesMon
    DDropboxYour files are ready to viewAug 2
    Quick settings
    See all settings

    Density

    ● Default

    ○ Comfortable

    ○ Compact

    Gmail inbox to Settings to See all settings to Filters and Blocked Addresses, revealing a malicious filter that deletes security alerts

    7

    Confirm nothing is being forwarded

    Move to the Forwarding and POP/IMAP tab, still in Settings. One quiet forwarding rule mirrors every message — password resets included — to an address the intruder owns, and it keeps working after every other fix. Strip out any forwarding destination that isn't yours, and disable forwarding altogether if you never use it.
    MSettings
    GeneralInboxAccounts and ImportFilters and Blocked AddressesForwarding and POP/IMAP

    The following filters are applied to all incoming mail:

    Matches: subject:(security alert OR password)

    Do this: Skip Inbox, Mark as read, Delete it

    A hidden Gmail forwarding rule sending mail to an unknown address

    Frequently asked questions

    Can someone be inside my Google account without any sign?
    Easily — with your password or a hidden forwarding rule, everything happens silently. That's exactly why the filters, forwarding and active-session checks matter even when the account feels normal.
    A security alert turned out to be me. Is that a problem?
    No — your own new phone, browser or travel triggers the same alerts. They only matter when the device, location or timing genuinely isn't yours.
    Is changing my password enough to force someone out?
    It's the fastest single move — a password change ends most other sessions immediately. Pair it with two-factor authentication straight after, so the next stolen password achieves nothing.
    What if I can't get into the account at all?
    Move on recovery immediately — every hour gives an attacker more time to dig in. Our Gmail recovery walkthrough covers it step by step; a Google account and its Gmail share the same recovery flow.

    What to do next

    If you found something

    The intruder is out and their footholds are gone — the last job is making sure the door doesn't open again. Harden the account: two-step verification, clean recovery details, a password used nowhere else.
    Secure your Google account

    If everything looks clean

    Good news — and the right moment to think a move ahead. The email under your Google account will always be a prime target. An end-to-end encrypted inbox like Proton Mail means nobody but you can ever read your messages — not the provider, not an intruder. It's the strongest single upgrade available for your email.
    Why switch to Proton Mail

    Worried about the phone itself?

    An account can be clean while the handset isn't. If something still feels off, sweep the phone itself for tracking — location shares, monitoring apps and settings someone else may have touched.
    Check if your phone is tracked

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Device Security