SEO Title

Google Account sign-in alert: what to check before changing your password

Got a Google Account sign-in alert? What to check before you change your password

If you get a Google Account sign-in alert, the safest order is not to change your password on instinct. The better move is to review the device, time, approximate location, and recent account changes first, because Google explicitly tells you to confirm whether the activity was yours before you decide how to secure the account [F1][F2]. If it was not you, then it makes sense to choose No, secure account, review the security settings, and change the password when there is actual account risk [F1][F2].

The most useful current signal around this topic is that Google now keeps a dedicated help page warning that unsolicited "account security" phone calls are scams, and tells users to open Google Security Checkup manually instead of interacting with the caller [F3]. The practical takeaway is clear: a real sign-in alert should be reviewed inside your own account, not through a phone call, a shortened link, or a rushed prompt approval.

Quick answer

  1. Open the alert and check the device type, time, and location [F2].
  2. If the activity was not yours, tap No, secure account and follow the official flow [F2].
  3. Then open your Google Account and review Recent security activity, Your devices, apps with access, recovery phone/email, and passkeys/security keys [F1][F4].
  4. Change your password if there was unfamiliar access, an important setting change you did not make, or password reuse across other services [F1][F2].
  5. Keep 2-Step Verification, backup codes, and passkeys on personal devices so you do not lock yourself out while cleaning up the account [F4][F5].

If you want the rest of the same security path, continue with How to check Google Account devices and sign out suspicious access, Google prompt not showing on Android? How to fix it, How to Turn On Google Two-Step Verification on Android Without Losing Access, How to Generate Google Account Backup Codes and Recover Access Without Your Phone, and How to create a Google Account passkey on Android.

When you should not change the password immediately

Not every alert means your account was compromised.

If you were the one signing in on a new device, a different browser, a VPN, or an unusual network, Google's official flow lets you mark the activity as Yes after you review the details [F2]. In those cases, changing the password before you understand what happened only adds friction and can force sign-outs everywhere for no good reason.

My editorial inference from the primary sources is this: a sign-in alert works best as a triage trigger. First decide whether the activity was yours. Then fix the real risk surface. That reduces both panic and false confidence.

The correct review order before changing any credential

1. Read the alert carefully

Google says the security alert shows:

  • device type;
  • time of the attempt;
  • approximate location [F2].

If all three line up with your recent activity, the odds of a legitimate sign-in go up. If they do not, treat it as an incident.

2. Open recent security activity

Google points to Recent security activity as one of the main places to investigate what changed [F1]. Review whether there was:

  • a new sign-in;
  • a password change;
  • a change to your recovery phone or recovery email;
  • 2-Step Verification turned on or off;
  • a new app with account access [F1].

If the alert is tied to Gmail, also review forwarding, filters, delegation, and auto-replies. Google's suspicious-activity guidance lists those among the classic signs of account tampering [F1].

3. Review connected devices

Go to Your devices and open Manage all devices [F1]. The goal is not only to sign out a suspicious session. It is also to confirm:

  • which phone is still your main trusted device;
  • whether an old, sold, or lost phone is still attached;
  • whether a browser session on a shared computer is still signed in.

If the alert showed up right after you switched devices, this step often explains more than a rushed password reset.

4. Review sign-in and recovery methods

Before you touch the password, make sure your recovery path is intact. Google lists these as critical settings:

  • recovery phone number;
  • recovery email address;
  • 2-Step Verification methods;
  • apps with account access [F1].

It is also worth opening Passkeys and security keys. Google's documentation says passkeys do not remove older factors, but they do affect sign-in behavior and can bypass the second step when the account already uses 2-Step Verification or Advanced Protection [F4]. If you see a passkey or security key you do not recognize, remove it.

5. Change the password only after that

Changing the password is still the correct move when:

  • the sign-in was not yours;
  • a sensitive setting changed;
  • you reused the same password on other apps or sites;
  • the alert came with phishing or malware risk [F1][F2].

Google's suspicious-activity guidance says to change the password immediately if you think someone else is signed in, including on apps or sites where you reused that same password [F1].

What to review besides the password

Many people change the password and stop there. That is incomplete.

After the incident, also review:

Recovery phone and email

If these were changed, an attacker may try to regain access later [F1].

Connected apps and sites

An app with improper access may still retain useful access or account data depending on the case [F1].

Passkeys and physical security keys

Google says suspicious passkeys can be disabled and may require confirmation that you actually added them [F1][F4]. So a password-only review is not enough.

Future protection

In the official World Password Day 2026 post, Google pushes two directions at once: passkeys for stronger phishing resistance and 2-Step Verification as an added safeguard [F5]. In practical terms:

  • passkeys improve daily sign-in;
  • 2FA raises the bar against account takeover;
  • backup codes reduce lockout risk;
  • device review cuts off forgotten sessions.

If the alert arrived through a phone call, text, or strange email

The rule here is simple: do not use the incoming contact as your source of truth.

Google's scam warning says the company never calls you to discuss account security, ask for your password, ask you to read a verification code, or tell you to approve a device prompt over the phone [F3]. The safer path is:

  1. end the call or ignore the message;
  2. open myaccount.google.com yourself;
  3. run Security Checkup;
  4. review recent activity inside the account [F3].

If you already approved something in one of those flows, treat the situation as a real incident even if you are not fully certain yet.

Short checklist to avoid locking yourself out

  • [ ] I reviewed the device, time, and location in the alert.
  • [ ] I confirmed whether the attempt was mine or not.
  • [ ] I opened Recent security activity and Your devices.
  • [ ] I checked recovery phone/email, 2FA, connected apps, and passkeys.
  • [ ] I changed the password only after understanding what had to be signed out or corrected.

Quick FAQ

Does every sign-in alert require an immediate password change?

No. If the sign-in was yours and the details match, you may only need to confirm the activity [F2]. Immediate password changes matter when the sign-in was not yours or when a critical setting changed [F1][F2].

Can I trust a phone call claiming to be from Google?

No. Google's official guidance says unsolicited account-security phone calls are scams [F3].

Does a passkey replace this review?

No. A passkey improves phishing resistance, but you still need to review devices, recovery, and 2FA when an alert appears [F4][F5].

Does changing the password shut everything down by itself?

Not always. You should also review sessions, connected apps, recovery data, and sign-in methods [F1].

Review app permissions too

If a sign-in alert prompted your review, also check how to remove app access to your Google Account. Device sessions and permissions granted to services are separate checks.

Sources

  • [F1] Google Account Help - Investigate suspicious activity on your account, verified September 1, 2026: https://support.google.com/accounts/answer/140921?hl=en
  • [F2] Google Account Help - Respond to security alerts, verified September 1, 2026: https://support.google.com/accounts/answer/2590353?hl=en
  • [F3] Google Help - Google Account Security Scam via Phone Call, verified September 1, 2026: https://support.google.com/faqs/answer/17170932?hl=en
  • [F4] Google Account Help - Sign in with a passkey instead of a password, verified September 1, 2026: https://support.google.com/accounts/answer/13548313?hl=en
  • [F5] Google Blog - 5 helpful tools from Google to keep your accounts safe, published May 1, 2026 and verified September 1, 2026: https://blog.google/innovation-and-ai/technology/safety-security/world-password-day-2026/

Editorial notes

  • Last editorial verification: September 1, 2026.
  • Menu names can vary by language, browser, and personal versus Workspace account.
  • This article combines official Google documentation with explicit editorial inference about incident triage and recovery order.