An unfamiliar device name or city is a reason to investigate, not proof of a hack. A browser, app, private window or recent phone reset can create another session. Location and last-active time may be approximate or reflect background syncing.
A recent location alone is weak evidence. A security event you did not initiate, unknown recovery address or sent message you did not write is much stronger evidence. If you are locked out, use Google's account-recovery flow rather than a number found in an unsolicited message.
Check the evidence
- Open Google's device list by typing that address yourself. Select the unfamiliar device or session and compare its browser, time and location with what you actually used.
- In your Google Account's Security & sign-in area, review recent security events and any changes to password, recovery details, passkeys or two-step verification.
- Check Gmail forwarding and filters if you use Gmail. An attacker may leave mail forwarding behind even after a password change.
Decide what to do
Clearly yours? You can leave it alone. Not sure? Sign out that session, or all sessions with the same device name, then sign in again on your own devices. Unfamiliar activity or security-setting changes? Follow Google's compromised-account steps, change your password, remove unknown access and review recovery methods.A recent location alone is weak evidence. A security event you did not initiate, unknown recovery address or sent message you did not write is much stronger evidence. If you are locked out, use Google's account-recovery flow rather than a number found in an unsolicited message.