Resource icon

A Google Account shows a device I don't recognize. What should I check?

An unfamiliar device name or city is a reason to investigate, not proof of a hack. A browser, app, private window or recent phone reset can create another session. Location and last-active time may be approximate or reflect background syncing.

Check the evidence​

  1. Open Google's device list by typing that address yourself. Select the unfamiliar device or session and compare its browser, time and location with what you actually used.
  2. In your Google Account's Security & sign-in area, review recent security events and any changes to password, recovery details, passkeys or two-step verification.
  3. Check Gmail forwarding and filters if you use Gmail. An attacker may leave mail forwarding behind even after a password change.

Decide what to do​

Clearly yours? You can leave it alone. Not sure? Sign out that session, or all sessions with the same device name, then sign in again on your own devices. Unfamiliar activity or security-setting changes? Follow Google's compromised-account steps, change your password, remove unknown access and review recovery methods.

A recent location alone is weak evidence. A security event you did not initiate, unknown recovery address or sent message you did not write is much stronger evidence. If you are locked out, use Google's account-recovery flow rather than a number found in an unsolicited message.

One final check​

After signing out a suspicious session, revisit the device list and recent security events. Check that recovery phone and email still belong to you. If the same session reappears, compare it with your own devices and connected apps before assuming a second break-in.
Posted by
Jack
Views
8
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack