Tuesday, November 28, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

How to Check If Someone Else Accessed Your Google Account

Researcher by Researcher
July 16, 2023
in Cybersecurity
0
How to Check If Someone Else Accessed Your Google Account
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Review your recent Gmail access, browser sign-in history and Google account activity to make sure no one other than you has used your account.

Illustration: Andy Wolber/TechRepublic

Whenever a computer is out of your direct view and control, there’s always a chance that someone other than you can gain access. A person who returns from a trip might wonder if their computer and accounts have been accessed during their absence. A person might notice odd activity in Gmail, not aware that their password has been made public (or “pwned“). Or, in some cases, a person might be surveilled by a partner, a family member, a colleague or even an unknown party.

SEE: Discover how to regain access to your Google account

Related articles

Sentra Raises $30 Million for DSPM Technology

Northern Ireland’s Top Police Officer Apologizes for ‘Industrial Scale’ Data Breach

August 13, 2023
Minimizing Risk Through Proactive Apple Device Management: Addigy

Minimizing Risk Through Proactive Apple Device Management: Addigy

August 12, 2023

To secure an account, you might first change your password, enable two-factor authentication or even enroll in Google’s Advanced Protection Program. Those steps will help you secure your account.

The following steps can help you figure out if someone other than you is accessing your Gmail or Google account.

Jump to:

Did someone access my Gmail account?

In a desktop web browser, Gmail allows you to review recent email access activity. Select Details in the lower-right area below displayed emails, below Last Account Activity (Figure A).

Figure A

Select Details in the lower-right area below displayed emails, below Last Account Activity.
Select Details in the lower-right area below displayed emails, below Last Account Activity.

If your Gmail account has been accessed in other locations or on other devices, you may display recent activity while signed in to Gmail from a desktop-class web browser.

The system will show you information about the last 10 times your Gmail account has been accessed, along with the access type (browser, POP, mobile), location (IP address), and the date and time of access. This can help you identify if any of this access is from an unexpected device, place or time.

Note: If you use a virtual private network or a hosted desktop, the location data may reflect information related to your service provider, instead of your physical address.

In a few cases, I’ve had clients concerned about access in an expected location, but at an unexpected time. Sometimes, this was simply because they’d left a computer on, with their browser or mail client open. The system could be configured to auto-check mail periodically. In one case, access occurred after a power outage. They’d configure the system to automatically power on after an outage, so it signed in and downloaded new mail shortly after power was restored.

Did someone access my browser?

In the Chrome browser — and on any Chromebook or Chrome OS device — press Ctrl + H to display browser history. Alternatively, type chrome://history in the omnibox, or select the three-vertical dot menu in the upper-right, then choose History | History. On macOS, press Command + Y. You may scroll through all available sites visited. Review these to see if any sites displayed are unexpected.

SEE: Lock down your Google account on iOS with Google Smart Lock

Additionally, you may enter search terms in the box displayed above the historical URLs listed. For example, search for “sign in,” or copy and paste this link into your browser omnibox: chrome://history/?q=sign%20in to display most site login pages (Figure B). Again, review the results for any sites you don’t expect. You might search for “gmail.com” as well.

Figure B

v
Use Ctrl + H or Command + Y to display your browser history. You may also search history for terms, such as “login” or “sign in,” as shown.

Did someone access my Google account?

Go to https://myactivity.google.com/ to access your Google account history across all devices and Google services, such as YouTube, Google Maps and Google Play (Figure C). Depending on your security settings, you may need to reauthenticate when you attempt to access this information. Again, review any recorded data to make sure it corresponds with your usage.

Figure C

Go to https://myactivity.google.com/ to access your Google account history across all devices and Google services, such as YouTube, Google Maps and Google Play.
The My Google Activity page displays any recorded access of web sites, apps, location and YouTube.

Similarly, go to https://myaccount.google.com/device-activity to review a list of devices to which you’ve signed in with your Google account (Figure D). You may select the arrow to the right of any displayed device session, then choose Sign Out to prevent any future access without reauthentication on a device.

Figure D

Review a list of devices to which you've signed in with your Google account.
You may also review the devices where you’re signed in to your Google account. Select the three-dot menu in the upper-right corner of the box for each device to sign out of any device.

Go through Google’s Security Checkup for a step-by-step review of every item Google’s system identifies as a potential security issue (Figure E).

Figure E

Go through Google's Security Checkup for a step-by-step review of every item Google's system identifies as a potential security issue.
Google’s Security Checkup helps you review the security of your account, step-by-step.

Use Google Workspace? Ask an administrator for help

If you use Gmail and Google Workspace as part of an organization (e.g., work or school), an administrator may be able to do an additional review of your account access data. To do this, the administrator will need to sign in to the admin console. From the Admin console, they might go to https://admin.google.com/ac/, select your account, then review security settings as well as connected apps and devices (Figure F).

Figure F

From the Admin console, they might go to https://admin.google.com/ac/, select your account, then review security settings as well as connected apps and devices.
A Google Workspace administrator may review user account security settings and device access details.

Next, admins might review all login information by going to the Investigation Tool, then filtering by user log events and your account email address (Figure G). Because this information is centrally logged by the system, access records will remain, even if the person accessing your account attempts to cover their tracks, such as by locally deleting browser history.

Figure G

An admin filtering by user log events and your account email address.
For organizational accounts, a Google Workspace administrator may review audit logs for account sign ins.

What’s your experience?

If you’ve wondered whether someone else has accessed your Google account, what steps have you taken? What did you learn when you completed the above access review of your Google account? Mention or message me on Mastodon (@awolber) to let me know any additional steps you suggest.



Source link

Tags: AccessedaccountcheckGoogle
Share76Tweet47

Related Posts

Sentra Raises $30 Million for DSPM Technology

Northern Ireland’s Top Police Officer Apologizes for ‘Industrial Scale’ Data Breach

August 13, 2023
0

Northern Ireland’s top police officer apologized Thursday for what he described as an “industrial scale” data breach in which the...

Minimizing Risk Through Proactive Apple Device Management: Addigy

Minimizing Risk Through Proactive Apple Device Management: Addigy

August 12, 2023
0

Enterprise IT teams are struggling to cope with three major forces of change: the evolving regulatory environment, a globally dispersed...

Decipher Podcast: Katelyn Bowden and TC Johnson

Decipher Podcast: Katelyn Bowden and TC Johnson

August 12, 2023
0

Veilid main site: https://veilid.com/ Cult of the Dead Cow site: https://cultdeadcow.com/ Source link

In Other News: Government Use of Spyware, New Industrial Security Tools, Japan Router Hack 

In Other News: macOS Security Reports, Keyboard Spying, VPN Vulnerabilities

August 12, 2023
0

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under...

Used Correctly, Generative AI is a Boon for Cybersecurity

Used Correctly, Generative AI is a Boon for Cybersecurity

August 12, 2023
0

Adobe stock, by Busra At the Black Hat kickoff keynote on Wednesday, Jeff Moss (AKA Dark Tangent), the founder of...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
Microsoft to Block Macros by Default in Office Apps

Qakbot Email Thread Hijacking Attacks Drop Multiple Payloads

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
North Korean Hackers Exploiting Zero-day Vulnerabilities

North Korean Hackers Exploiting Zero-day Vulnerabilities

November 28, 2023
North Korean Hackers Exploit MagicLine4NX Zero-day

North Korean Hackers Exploit MagicLine4NX Zero-day

November 28, 2023
NukeSped Malware Exploiting Apache ActiveMQ Vulnerability

NukeSped Malware Exploiting Apache ActiveMQ Vulnerability

November 28, 2023
A New Telekopye Bots That Tricks Users to Steal Payment Details

A New Telekopye Bots That Tricks Users to Steal Payment Details

November 27, 2023

Recent Posts

North Korean Hackers Exploiting Zero-day Vulnerabilities

North Korean Hackers Exploiting Zero-day Vulnerabilities

November 28, 2023
North Korean Hackers Exploit MagicLine4NX Zero-day

North Korean Hackers Exploit MagicLine4NX Zero-day

November 28, 2023
NukeSped Malware Exploiting Apache ActiveMQ Vulnerability

NukeSped Malware Exploiting Apache ActiveMQ Vulnerability

November 28, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • LetsAskBinuBlogs
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cyber Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches platform Ransomware RoundUp security Software Stories TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved