Open your Google Account, go to Security & sign-in, and find the section for signing in to Google. Select the option to turn on 2-Step Verification and follow the setup prompts. Add a recovery method or backup option while you still have access. Work or school accounts may use administrator-controlled settings. The second step helps protect password-based sign-ins, while a passkey can use a different sign-in flow.
Open your Google Account and review the contact information in Personal info. Add a recovery email you can access separately from this account, and a phone number you regularly use that can receive messages. Follow any verification prompts. Revisit these details after changing your phone number or email address. Recovery information can help with access problems, but it should remain current before you need it.
Use a long password that is unique to that account; Google recommends at least 12 characters. A memorable phrase can help, but avoid personal details, predictable patterns, or a password already used elsewhere. A password manager can help create and keep track of different passwords. If one reused password is exposed, other accounts using it are also at risk, so replace reuse with separate passwords.
Open your Google Account, choose Security & sign-in, then find Your devices and Manage all devices. Select the device or session and choose Sign out. A device can have several sessions, so review and sign out of each relevant one if you want to remove all its access. Recent activity times can include background synchronization, so a timestamp alone does not necessarily mean someone was actively using the device.
On a computer, open Chrome’s three-dot menu, choose Help, then About Google Chrome. Chrome checks for updates and downloads an available update. Select Relaunch if prompted to finish applying it. Save anything important before restarting the browser. Chrome normally restores regular tabs, but Incognito windows are not reopened. Keeping this page’s status current is a simple way to confirm the browser has finished updating.
Incognito limits what Chrome retains locally after you close all Incognito windows, including that session’s browsing history and site data. It does not hide your activity from websites, your employer or school, or your internet provider. Downloaded files and saved bookmarks remain on the device. To open an Incognito window, use Chrome’s menu, New Incognito Window; close every Incognito window when you finish the private session.
Avoid the message’s links and attachments. If you need to check the account, open the service through a known address or its app instead. In Gmail on a computer, open the message, use the More menu beside Reply, and select Report phishing. A familiar sender name alone does not prove authenticity. Reporting sends the message and its attachments to Google for analysis, so treat that action as sharing the suspicious content.
Open your Google Account, choose Security & sign-in, then select Password under the sign-in controls. Sign in again if requested, enter a new password, and confirm the change. Use a password you do not use on another account. Changing it signs you out in many places, but some verification devices and other connected services can be exceptions. If you cannot sign in at all, use Google’s account recovery process instead.
In File Explorer, right-click the file or folder. On Windows 11, choose Show more options if necessary, then Scan with Microsoft Defender. Review the scan results in Windows Security and follow any recommended action before opening a flagged file. If another antivirus provider is active, Microsoft Defender may be disabled; check Windows Security’s provider settings and use that provider’s scanning controls instead.
In your Google Account’s security settings, open 2-Step Verification and find Backup codes. Follow the prompts to create a set, then download or print it and store it somewhere you can reach without signing into that account. Each code works once. Creating a new set invalidates the previous set, so replace old copies when you regenerate them. Keep codes private: they can be used to complete a sign-in.
Open Chrome’s menu, choose Passwords and autofill, then Google Password Manager and Checkup. Review any warnings about compromised, reused, or weak passwords. For an affected account, visit the real service and change the password there, then update the saved entry if needed. Editing only the password stored in the manager does not change the account’s actual password. Use a different new password for each account you fix.
At sign-in, look for another verification option. Depending on what you previously set up, you may be able to use another signed-in phone, a backup number, a saved backup code, a security key, or a passkey on another device. A trusted device may also help. If none is available, follow Google’s account recovery process. Work or school users can contact their administrator; access is not guaranteed without successful verification.
On a device you own and use personally, open your Google Account’s passkey settings, choose Create a passkey, and follow the device-unlock prompt. A screen lock protects its use. Avoid creating one on borrowed or shared equipment, since someone able to unlock that device could access your account.
No. Google warns that someone who can unlock a device holding your passkey can sign in again, even after you sign out. Create passkeys only on devices you personally control. If you made one on shared equipment, remove it from the account and relevant credential manager.
Open Google Account settings, choose Security and sign-in, and find Passkeys and security keys. Select the passkey you created and remove it. If a credential manager still offers it, remove that stored copy there too. Automatically created Android passkeys use a different device-sign-out procedure in Google’s instructions.
Keep both phones available. On the old phone, open Authenticator’s menu, select Transfer accounts, then Export accounts; unlock and choose the accounts. On the new phone, choose Transfer accounts and Import accounts, then scan the displayed QR code or codes. Keep those transfer codes private.
Codes are stored on that device instead of being synchronized through your Google Account. Switching an existing setup to this mode removes codes from your Google Accounts, so other devices will not have them through sync. Plan a manual transfer before replacing or erasing the old phone.
Yes. Once the account is set up in Authenticator, it can generate verification codes without internet or mobile service. That does not give the website itself an offline sign-in connection. Keep the device clock accurate; current Authenticator versions use the operating system’s time setting.
Go directly to the manufacturer’s known support website instead of assuming a sponsored result or prominent phone number is genuine. Scammers can place support ads and appear in search results. Check who you are contacting before granting remote access, especially when someone uses urgent warnings to demand payment.
Check your actual account transactions and contact the company using a known, independent number. Do not call the number in the alarming renewal message. A message can claim a charge that never happened; a caller may then invent a refund mistake to pressure you into sending money.
Use the link preview your scanner provides and inspect the destination for misspellings or substituted letters. An unexpected QR code can lead to a convincing imitation site. If the code arrived in an urgent unsolicited message, contact the company through a known website instead of following it.
Stop interacting with that site. If you entered a password, change it through the genuine service and anywhere else you reused it. Review bank and card activity for unfamiliar transactions, and report the incident to the FTC. Scammers can place their own stickers over legitimate parking codes.
Research the company and recruiter independently, including searches for their names with complaints or scams. Contact the real company through its established website rather than the offer’s links. Do not pay for promised employment, starter kits, or required training simply because an unsolicited recruiter says you have been selected.
Source checks for these answers: September 21, 2026 – September 22, 2026. Product instructions and local requirements can vary.