Above the Fold

Cutting Through the Noise on Websites, SEO, and Digital Strategy

6

Min Read

The New Way Hackers Are Locking People Out of Their Own Google Account

Carrie Drephal, Creative Director

At JCD Promotions, most of what we talk about is websites — building them, improving them, making sure they bring in business. So why are we writing about a Google account attack? Because for most small business owners, a Google account isn’t just email anymore. It’s the single sign-on behind your website’s hosting, your domain registrar, your analytics, and often half the other accounts your business runs on. If that one account gets compromised, the damage doesn’t stop at your inbox — it can reach the website and systems we help you protect. This is a timely warning we wanted to get in front of you, not a shift in what we normally write about.

You’ve probably heard “use a strong password” so many times that it doesn’t mean much anymore. Here’s the problem: a strong password isn’t enough to stop what’s happening right now. Hackers have found a way to break into a Google account, lock the real owner out, and stay in — even after the owner changes their password.

This isn’t rare or far-fetched. It’s happening to regular people, including small business owners who store client information, banking details, and years of work in their Google accounts. Here’s how it works, and the exact steps you can take to check your own account right now.

How The Attack Works

It usually starts the same way every account takeover starts: a hacker gets your password. Some of the most common methods an account may be compromised are:

  • Your password was leaked in a data breach from some other website, and you used the same (or similar) password for your Google account
  • You clicked a fake “sign in” link that looked like a real Google page, and typed your password into it
  • Malware on a device quietly copied your saved passwords without you noticing

Once a hacker has your password, here’s the part that’s new and worth understanding: they don’t just read your email and leave. They take two extra steps designed to lock you out for good:

  1. They add a passkey. A passkey is a newer, more secure way to sign in without typing a password — usually by using your fingerprint, your face, or a small security key. It’s a great security tool when you set it up. But if a hacker adds one to your account, they’ve just created a way back in that doesn’t need your password at all.
  2. They delete your recovery phone number. Your recovery phone is what Google uses to confirm “yes, this is really the account owner” if something goes wrong. If a hacker deletes it, you lose your easiest way to prove the account is yours and get back in.

Put those two things together, and a hacker can end up with a backdoor into your account that survives even after you realize something is wrong and change your password.

The One Thing That Can Stop This: Paying Attention to Security Alerts

Google sends you an email and/or a notification almost every time something changes on your account — a new sign-in, a password change, a new device, a new passkey. Most people glance at these and ignore them, especially if they look routine.

Don’t ignore them. If you ever get an alert for something you didn’t do — a sign-in from a device you don’t recognize, a passkey you didn’t create, a password change you didn’t make — treat it as urgent. Go check your account immediately, even if it’s late at night or you’re busy. Acting fast doesn’t guarantee there’s no damage, but waiting gives a hacker more time to dig in, and that’s a risk you don’t want to take.

A good rule of thumb: if the alert describes an action, ask yourself one question — “Did I just do that?” If the answer is no, stop what you’re doing and go check your account.

How to Check Your Google Account Right Now

Here’s exactly where to look. This takes about five minutes and is worth doing today, even if nothing seems wrong.

  1. Check your recent account activity
    • Go to myaccount.google.com/security
    • Look for the section called “Recent security activity” or “Recent security events
    • Click through and look at each entry — does the device, location, and time match something you actually did? If anything looks unfamiliar, that’s your sign that something is wrong.
  1. Check which devices are signed in
    • Still on the Security page, find the section called “Your devices”
    • This shows every device currently signed into your Google account
    • If you see a device you don’t recognize, click it and select “Sign out” or “Don’t recognize this device? Secure your account”
  1. Check your passkeys for one you didn’t create
    • Go to myaccount.google.com/signinoptions/passkeys
    • You’ll see a list of every passkey on your account, along with the device or key it’s tied to
    • If you see one you don’t recognize, or one tied to a device you’ve never used, remove it immediately by clicking the three dots next to it and selecting “Remove”
  1. Check and set your recovery phone and email
    • Go back to myaccount.google.com/security
    • Look for “Ways we can verify it’s you”
    • Confirm your recovery phone number and recovery email are both current and actually belong to you (or a trusted representative)
    • If either one is missing, outdated, or unfamiliar, update it right away — this is your safety net if you ever do get locked out

How to Make Your Account a lot Harder to Break Into

Once you’ve checked the above, here are the changes that actually make a difference — not just “use a stronger password,” but the things that stop this specific kind of attack.

Use a physical security key, not just your phone. A security key is a small physical device (often shaped like a little USB stick) that you plug in or tap to confirm it’s really you. Because it’s a separate physical object, a hacker sitting in another country can’t fake it — they’d need to actually have it in their hand. This is one of the strongest protections available right now.

Turn off “push notification” approval as your only second step. Many people use Google’s “tap yes on your phone to confirm” prompt as their two-factor verification. The problem: if you’re juggling multiple login attempts (like setting up a new device) and a hacker is also trying to log in at the same time, it’s easy to accidentally approve the wrong one. A security key doesn’t have this problem.

Check your passkeys and devices every few months, not just when something feels wrong. Make it a habit — same as checking your bank statement.

Never reuse passwords. If one site you use gets hacked and you used that same password for your Google account, you’ve effectively handed over the keys. Use a different password for every important account, and consider a password manager to keep track of them.

Be suspicious of any login page that arrives through a link. If an email or text tells you to “verify your account” with a link, don’t click it. Open a new browser tab and type google.com yourself instead. Real account problems can always be checked this way — you never have to click a link to find out.

The Bottom Line

Hackers have gotten better at staying in an account after they break in, not just stealing what they can and leaving. The good news is that the same tools Google gives you — security alerts, activity logs, passkey lists, and physical security keys — are exactly what you need to catch this fast and cut off a hacker’s access — but catching it quickly doesn’t mean you can skip checking for damage afterward.

Five minutes spent checking your account today is a small price compared to the time it takes to recover from a real account takeover — especially when that account is also the front door to your website, hosting, and domain. If you haven’t looked at your Google account’s security settings in a while, now is a good time.

Have questions about securing your business’s accounts, website, or digital tools? Contact us — we’re happy to talk through what makes sense for your situation.

Carrie Drephal is the Founder and Creative Director of JCD Promotions, where she's spent the majority of her career helping small businesses find innovative solutions to promote their businesses, including websites that actually work for them — not just look good. Her approach blends strategy, structure, and plain-spoken advice, informed by two decades of watching what separates a website that generates real business from one that just sits there. When she's not working, she's usually playing with her pups, Blu and Sierra.