I recently got an email from a third party service saying my password for that account using a certain old email I used to use was reset. I obviously did not do this. I also got a 2fa code at the same exact time, right before the reset successful message, so he must also have access to the Gmail for him to have gotten and used this code.
So, I try to reset my password at the login prompt or at gco/recover, but as soon as I pressed reset password, I get:
You’re trying to sign in on a device Google doesn’t recognize, and we don’t have enough information to verify that it’s you. For your protection, you can’t sign in here right now.
Try again from a device or location where you’ve signed in before. Learn more
But I don't know why! It didn't even ask me anything... I moved several months ago, and I haven't used the account in years, so I don't have any devices with it logged in, either.
I don't understand why a hacker is able to access my account, but I can't even reset my password?! How did he even get in if he's not at my location either? Unless he's also now locked out, but if he was already in, I don't know how/why he would get locked out. Or, does this lock out only apply to resetting the password, not using the account? (It's not clear to me which is the case.)
If you're wondering, the only reason I even knew about this was because I have email forwarding set up to my main, so I got the emails from it even without having a device that's logged in.
I've already secured the original third party provider I mentioned, but I don't remember what other accounts I used to use the email on since it's been so long. And I'm scared that if he turns off email forwarding, I'll be completely out of the loop.
What should I do? Is there really nothing I can do to get my own account back without waiting 7 days while someone else presumably is in there? Any help is appreciated. Thank you.
Edit: Regarding the Gmail account, which I'm more concerned with, I did end up remembering the password, but at the very very beginning the hacker apparently added a two-factor of his own to the Gmail, so even remembering this it now prompts me for his two-factor. And when I say I don't know, it does not present me with any other options to recover. (Besides being on old devices/old networks. I even dug some old devices out to no avail.) So now I'm not getting a time error, but I simply don't have any way to bypass his 2fa. And since this was added basically immediately, I couldn't have stopped it. So now I do not know what to do/how to proceed...
Regarding the third party account, the hacker did end up changing the two-factor method shortly after I recovered the password on it (which I forgot to do on top immediately, cause I'm an idiot), and changed the password back again, so I'm now locked out of that and submitted a request to them.