You’ve not been careful enough and, alas, your password leaked. Don’t risk – assume immediately that your account data is exposed. The damage might be huge if you don’t take timely measures to minimize data loss and regain control of the account. These measures are:

  1. Alert your administrator –  But, don’t email your admin from your hacked account, it’s been compromised, remember? Rather text or call him/her.
  2. Review account access – Go to  https://myaccount.google.com/  and click on “Device activity & notification.” In the section “Recently used devices” select “Review devices.” Remove or erase data from devices unknown to you.
  3. Reset sign-in cookies – A Google Apps administrator may reset a user’s password and sign-in cookies, or require the user to choose a new password the next time the user signs in.
  4. Reset password –  Reset your password from the https://myaccount.google.com page in the “Sign in & Security” section of the link mentioned above.
  5. Strengthen security – use a password consisting of at least 7 to 12 characters and don’t forget about 2-step verification.

To check if your accound has been breached, go to  https://haveibeenpwned.com/