July 28, 2026
How to Help Your Friend Whose Gmail Account was Just Compromised
Have you seen an email like this before?

By Reid Bauer
7 min read
I got one of these last week: an email from someone I knew that seemed a little sus. In my case, it was an electronic invitation to an event with basically no description. I hovered over the links in the message and none of them appeared to go to Punchbowl, Evite, or any other online event service I'd ever heard of.
Previewing the invite in a secure virtual machine, I could see that it led to a (pretty good) phishing page impersonating a Google login. Besides the non-Google URL, the only other obvious indication that this might be fake were the links ("forgot email?", "Create account") that didn't go anywhere.
So the message was, sadly, not a real party invitation. If you're like me, your next thought would be: did this actually come from my friend's account? I looked at message headers and verified that this message passed SPF, DKIM, and DMARC tests. So it's highly likely that the message really did come from their account.
I contacted my friend and she was able to verify that the message had indeed originated from her account. She had clicked on a similar fake event invite from a co-worker and entered her credentials into the phishing page. There was a pause in our text conversation, then she asked,
"Do you think I need to do anything at this point?"
Holy shit, yes.
This led me to create this guide. You, the responsible and savvy internet user, know better than to click on a shady invitation to "Steve's Extra-Special Event". But what advice do you give to your uncle or neighbor or dental hygienist when you see signs that their Gmail account has been compromised?
Evicting a Trespasser
Before you even start dispensing your wise advice, remember: the attacker still has access to your friend's Gmail account, so you want to pick a different communication channel to walk them through this process: WhatsApp, text, phone call, or Signal are all fine, but don't use their email address to send these instructions.
You can frame this process like evicting an actual intruder in a physical house. The first order of business is, of course, to get the villain out of the house.
But maybe less obviously, our next move is to check all the doors and windows to make sure the intruder can't easily slip back inside. We need to make sure they didn't leave the basement door unlocked or prop a bedroom window open.
Once we're satisfied that the house is secure, we need to do a survey and assess the damage. Is anything missing? Is anything broken?
Finally, last but not least, it's worth making some upgrades to our security. This intruder got inside somehow; we want to take measures to try and prevent future trespassing.
Kick the Intruder Out
The very first thing your friend needs to do is change their Google Account password. Have them visit myaccount.google.com → Sign in and Security → Password, then change their password to a unique new password, one they've never used before.
This does a bunch of things for them: besides changing the password from one the attacker knows to one they don't, it will instantly end all session cookies, logging the attacker out of any active sessions. It will also reset any app-specific passwords that the attacker may have set up.
In other words, simply changing the victim's Google account password will kick the attacker out of the house, lock the front door, and eliminate many of their routes to get back in. And your friend should treat it with the same urgency that they would if they found an actual intruder in their physical home.
This isn't a "wait until the weekend" or a "do this when I get home from work". Do this right away.
Check the Other Doors and Windows
Next up, the victim should run a Google security check. They can do this by visiting https://myaccount.google.com/security-checkup, or by clicking on the Security Check button found under the security settings of their Google Account:
The Security Checkup will walk them through a helpful checklist . The most significant, for our purposes, are the Signed-In Devices and the Linked Apps. If they see an app or device they don't recognize, they should delete it.
In addition, have them visit the "How you sign in to Google" section of the Security & Sign In page. Your friend should verify that their recovery phone and recovery email are correct and have not been changed.
There are a few other places where the attacker might have a fingerhold on the account. Have your friend visit their Gmail settings, then click on Accounts and Import. They need to look at the Send mail as and Grant access to your account sections. If they see any email addresses they don't recognize, delete them.
Lastly, they should visit the Forwarding and POP/IMAP section of settings and delete any forwarding rules they didn't create themselves.
Did They Take Anything?
Let's take a breath; we've booted the trespasser out of the house and made sure they can't sneak back in through an open window. Our next step is to actually look around the house to see if anything was taken.
Two places to look right away are Gmail Sent messages and Gmail Trash. In the Sent folder, we're looking for any further phishing emails sent by the attacker. We want to see who these went to, then send a follow-up message to these folks warning them not to open them. We're also looking for basically any other message sent by the attacker; did they try and impersonate the victim?
In the Trash folder, we're looking for any suspicious emails, but in particular we want to be on the lookout for confirmation of password changes. Did the attacker use the "I forgot my password" link to reset any passwords of the victim's other accounts? If so, we'll need to regain access to these accounts and change the passwords right away.
It's worth noting that it's possible the attacker really covered their tracks by both trashing AND deleting messages that revealed their activity. So just because you don't see a "your Amazon password has been reset" email in the inbox or trash, that doesn't mean it didn't happen.
Were There Other Keys In the House?
In the case of a physical break-in, think about all the keys you might store in your house: keys that unlock vehicles, bike locks, safety deposit boxes, or storage units. Is there a paper copy of your passwords sitting next to your computer? The intruder had a chance to steal or copy these keys, so you need to make sure all of these secondary locks are still secure.
In the digital world, the equivalent threat model is that the attacker could have used the "I forgot my password" feature to change passwords for connected accounts.
To address this threat, your friend will need to log into their other high-value accounts. In my mind, this means: other email accounts, financial/cryptocurrency accounts, social media, and e-commerce sites. Anything to do with money or identity, in other words. The victim needs to confirm that their existing password still works and look for activity they don't recognize.
This raises the question: does your friend need to change their passwords on other accounts? Here's my take:
- If they reused their Google password (the one the attacker now has) for other accounts, then the answer for those accounts is ABSOLUTELY YES, as soon as possible.
- If they use Chrome's built-in password manager (they can visit passwords.google.com if unsure), ANY and ALL of the listed passwords need to be changed.
- For those high-value accounts, even if there's no sign of account compromise, I think it's still a good idea to change those passwords too, but it's maybe a little less urgent.
- For a password that's not stored in Chrome, one that's unique and different from anything else, and that doesn't guard a high-value account…those are probably OK.
Oh, and one more thing: do they use Google Authenticator? If so, then it's possible the attackers exported their vault of time-based one-time password (TOTP) seed tokens. This isn't theoretical and has actually happened. The solution [cue the sad trombone] is to work down the list in Google Authenticator, log into each account, reset the TOTP code, verify it works, then delete the old one.
Beefing Up Security
We've done a lot of work to try and mitigate the damage from this intruder into your friend's accounts. Our last task is to help them beef up their security so that this doesn't happen again.
Unfortunately, your friend is now a prime target for identity theft. Their email history and documents (which the attacker was able to read) are rich with all the information they would need to open a new credit line: their social security number, birthdate, address, and phone number.
To mitigate this threat, advise your friend to freeze their credit at the big three credit bureaus. It's free, it's not hard to do, and it's a good idea for most people to do this anyway. Here are the details:
To better secure their Google account, if your friend hasn't done this already, they need to enable two-step verification on their Google account. This can be done from myaccount.google.com → Security & Sign-In → Turn on 2-Step Verification. Ideally, they should opt for a passkey or a physical security key, as both methods are resistant to attacks like this fake evite scam. But using app-based codes or SMS codes would still be better than nothing.
If they really want to commit to locking down their email, steer them towards Google's Advanced Protection Program. While it does require that they purchase two physical security keys and comes with a few trade-offs, I still think it's one of the best things you can do for your security. I've had APP enabled on my account for 7 years and I'm never turning it off.
Final Thoughts
This all sounds like a lot of work, and it is. Having your email account compromised just sucks, full stop.
But it's a big deal and your friend needs to treat it like one. I think your hardest job, as the responsible friend, is to impress upon the victim that this is a massive, urgent problem while still urging calm, deliberate action.
They need to understand that their primary email account is the master key to their entire life. It unlocks their finances, their relationships, their online purchases. And that means treating this compromise with the same level of urgency that you'd apply to an intruder in your home.
Good luck, and stay safe out there!