Did Google detect suspicious activity? Tell a real security alert from phishing
From a different, trusted device, change your Google password first, then update any other passwords you'd reused elsewhere.
Google really does send these alerts, which is exactly why fake ones are so convincing.
Google does send legitimate alerts when it detects an unusual sign-in or a security change on your account, and criminals copy the look of those exact warnings to lead you to a credential-stealing page. A fake message might say "unusual activity detected," "suspicious sign-in blocked," or "your account will be suspended", and the visual difference from a real alert can be almost nothing. Google recommends checking your account directly and reviewing your recent security activity rather than trusting the email, and provides a dedicated channel for reporting phishing emails in Gmail.
The reason this particular scam works so well is structural: Google account alerts are one of the very few automated emails most people are trained to take seriously and act on quickly, since a real one really can mean someone else is trying to get into your inbox, your photos, and often your recovery path for every other account tied to that email address. Attackers know that urgency plus a security framing tends to override the skepticism people apply to more obviously commercial phishing emails. The fix isn't to distrust every Google email by default – it's to consistently route around the email entirely and check the same information at the source, every single time, regardless of how convincing or plain the message looks.
How to verify the alert
Don't use the button inside the message. Instead, type myaccount.google.com into your browser directly, or open account settings from within Gmail itself. Review your recent security activity, the list of your devices, any third-party app access, your recovery methods, and Gmail's forwarding rules and filters, then look for sessions you don't recognize. If the flagged event actually appears, confirm whether it was really you; if it doesn't appear at all, that's a strong sign the email itself was the attack.
Warning signs of a phishing version
- The link doesn't actually lead to a Google-owned domain
- A third-party page asks for both your password and a verification code together
- The message threatens account closure within just a few hours
- It asks you to install an app or a certificate
- It requests payment for "account security"
- The display name says Google but the real sending address is different
- A password manager doesn't recognize the domain as a saved login
- The flagged activity is absent when you check the account directly
Never send a Google verification code to anyone, even someone claiming to be support: a criminal can start a real sign-in attempt with your password, then call you afterward asking for the code under the pretense of "canceling" the suspicious login. Sharing that code hands them access.
It also helps to understand why the phone-call version of this scam specifically targets a verification code rather than just a password. A password alone is often not enough to get into an account protected by two-step verification, so an attacker who already has your password from an unrelated breach still needs the second factor to finish signing in. That's the entire purpose of the follow-up call: to get you, in the moment, to hand over the one piece of information that would otherwise have stopped them. Recognizing that a code request is the actual goal – not a side detail – makes it much easier to refuse on the spot, no matter how the caller frames the request.
Variants you'll run into
The email version is only the most common shape. The same bait arrives through several other channels, and each one borrows a different kind of credibility. A text message claims a sign-in was blocked and gives you a shortened link "to secure your account." A browser notification – one you accidentally allowed from a spam site weeks earlier – pops up on your desktop looking like a system security warning. A calendar invite appears in your schedule with a phishing link in the event description, exploiting the fact that invitations can insert themselves into your calendar without you accepting anything.
Then there's the phone version, which is the most dangerous. Someone calls claiming to be "Google support" responding to the suspicious activity, sometimes moments after you received a genuine verification code they themselves triggered by attempting to sign in with a leaked password. Google does not cold-call account holders about security alerts, so the call itself is the giveaway. A quieter variant targets your recovery email instead: compromise the older, forgotten account you use for recovery, and your main account falls with it. Whatever the channel, the response is identical – close it, and check your account by typing the address yourself.
A walkthrough: ninety seconds from alert to takeover
Mark, a small-business owner, is answering messages between jobs when an email arrives: "Suspicious sign-in blocked – verify your identity within 24 hours or your account will be suspended." His whole business runs through that inbox – invoices, client contacts, the recovery address for his bank login. He taps the blue button, lands on a sign-in page that looks exactly right, and enters his password. The page then asks for the verification code that has just arrived by text, and he types that in too. The site thanks him and redirects to the real Google homepage.
Nothing seems wrong until the next morning, when clients start asking about strange invoices they've received from his address. Inside his Gmail settings he finds a forwarding rule he never created, quietly copying every incoming message to an address he doesn't recognize. From his laptop he changes his password, signs out all sessions, deletes the rule, and turns on two-step verification with an authenticator app. The lesson: the fake page didn't just steal his password: it relayed his real verification code in real time, and the only step that would have broken the chain was typing myaccount.google.com himself instead of tapping the button.
If the activity is real and wasn't you
Change your password immediately to a strong, unique one you haven't used elsewhere. Sign out of any sessions you don't recognize. Remove unfamiliar devices and third-party app access. Enable two-step verification if it isn't already on. Inspect Gmail specifically for forwarding rules or filters that might be silently hiding incoming messages from you – a common tactic once an account is compromised.
The same logic applies well beyond Google specifically – any account offering two-step verification is protected by the same principle, and any message asking you to read out or type in a code somewhere other than the service you're actually signing into should be treated the same way, regardless of which brand's name or logo appears on it. Learning to recognize the shape of this specific attack, rather than memorizing one company's version of it, is what actually transfers to the next platform that gets targeted.
If you already entered information on the fake page
From a different, trusted device, change your Google password first, then update any other passwords you'd reused elsewhere. Review your account's security activity, active sessions, recovery methods, and Gmail settings for anything unfamiliar. If you also entered payment information, contact your bank or card issuer right away. Report the original email as phishing directly inside Gmail.
Settings that make the next fake alert harmless
You can change your account so that this entire category of phishing has much less to steal. Switch your second factor from text-message codes to an authenticator app or, better, a passkey. Text codes can be relayed by a fake page the way Mark's was; a passkey is bound to the real domain and simply won't work on an impostor site, no matter how convincing it looks. While you're in the security settings, run Google's built-in Security Checkup and make it a habit a few times a year: it walks you through devices, third-party access, and recovery methods in a few minutes.
Two quieter settings matter more than most people realize. First, make sure your recovery email and phone number are current and belong to accounts you actively protect: an abandoned recovery inbox is an open back door. Second, let a password manager fill your Google password instead of typing it: the manager matches the domain exactly, so on a lookalike page it will refuse to autofill, which is itself a loud warning that something is wrong.
Finally, spread the habit to the people who share your digital life. Anyone whose email is the recovery address for your accounts – a spouse, a parent, a business partner – is part of your security whether they know it or not. Agree on one family rule: no one ever acts on a security email directly; everyone checks by typing the address themselves. It takes ten seconds longer and defeats the entire attack.
Quick checklist
- Never click the button inside an unexpected security alert email
- Check activity by typing myaccount.google.com yourself
- Never share a verification code with anyone, ever
- Enable two-step verification if you haven't already
- Review Gmail forwarding rules and filters after any suspicious activity
- Report phishing emails directly through Gmail's built-in tool
Frequently asked questions
Does Google actually send real security alerts by email?
Where can I see which devices are signed into my account?
What should I do if I receive an unexpected verification code?
Daniel A. and Óscar S. run Breachfolio, a small independent site about security and AI. This article was drafted with AI assistance and reviewed by a person before it went live. We write from documentation, vendor sources and published research rather than from original lab benchmarks, and we link a source in the sentence that relies on it. How we work · About us
