Why Google just texted you a verification code

Of all the codes you can receive without asking, this is the one to handle first.

Your Google account is where password resets for everything else are delivered. Someone who controls it doesn't need to attack your bank, your shopping accounts, or your social profiles individually. They can reset them one at a time from your inbox.

What to do

1. Change your password now, from google.com

Type the address yourself. Change the password in your Google Account under Security. Choose something you use nowhere else.

2. Check for email forwarding and filters

This is the step that matters most, and almost nobody does it.

An attacker with even brief access to a Gmail account will often set up a forwarding address or a filter before doing anything else. The filter typically forwards messages containing words like "password," "verification," or a bank's name to an address they control, then marks them read and archives them so you never see them.

Changing your password does not remove a forwarding rule or a filter. Go to Gmail settings, open the Forwarding and POP/IMAP tab and the Filters and Blocked Addresses tab, and delete anything you didn't create.

3. Review app passwords and third-party access

Under Security, check app passwords and the list of third-party apps with account access. App passwords bypass two-factor authentication by design, which makes them a durable way back in. Revoke anything unfamiliar or unused.

4. Sign out of other sessions and check recent activity

Look at "Your devices" and sign out of anything you don't recognize. Then check recent security activity for sign-ins from unfamiliar locations, changed recovery options, or new sign-in methods.

5. Confirm your recovery email and phone are still yours

An attacker who gets in will try to change these, because whoever controls recovery controls the account. Check both and correct anything that isn't yours.

6. Run Google's Security Checkup, then upgrade the second factor

The Security Checkup walks the account's exposure in one pass. While you're there, move from SMS codes to an authenticator app, a passkey, or a hardware key. If your account is high-value, Google's Advanced Protection Program is the strongest option available.

Why this account gets attacked

Because of what it reaches. A Google account is the recovery root for most people's digital lives, so a working password is worth more here than almost anywhere else. Bots replay credentials leaked from unrelated breaches against Google in enormous volume for exactly that reason.

Beyond the bulk pass, targeting requires knowing who you are and how to reach you. A current phone number, an email address, a home address, and family names are enough to answer a recovery question, or to write a message convincing enough to get you to approve a prompt.

Data brokers and people-search sites publish that material openly, compiled from public records and commercial data and sold cheaply. That's how a stale password becomes an attempt aimed specifically at you.

Delist finds those listings, files the removals, and re-checks them, because a profile that comes down frequently reappears. Run a free scan to see what's published about you today.

For the pattern behind codes like this, see why you're suddenly getting 2FA codes you didn't request.

Frequently asked questions

Does this mean someone has my Google password?

Yes, in most cases. The verification step comes after the password is accepted. Change it here, and change it anywhere you reused it, starting with anything financial.

I got a "someone has your password" alert from Google. Is that a phishing email?

Google does send real alerts of that kind, and phishing imitates them closely. Don't use links in the message. Go to your Google Account security page directly and read the alerts there.

Why check filters if I've already changed my password?

Because a forwarding rule or filter survives a password change. It's the most common form of persistent access, and it's invisible unless you look for it specifically.

What is an app password and why does it matter?

It's a credential that lets an older app sign in without going through two-factor authentication. That makes it a bypass. If one exists that you didn't create, revoke it.

Should I use Advanced Protection?

If you're a plausible target for a determined attacker, yes. It enforces hardware security keys and restricts third-party access. For most people, a passkey or authenticator app plus a clean filter list is a reasonable place to land.

Find out what data brokers know about you

Run a free scan to see which sites are exposing your personal information — name, phone, address, email, and more.

Start your free scan