This is how to secure a GMail Account.
Adding Recovery, First login to your google account and click your profile
By then click the "Manage your Google Account."
STEP 2
Click on Security Section
Add both "Recovery Phone" and "Recovery Email."
(Note: This needs verification code from SMS and GMail)
STEP 3
Add "2-Step Verification" under Security Section.
STEP 4
Under Security Section You'll see "Your Devices" Click on any devices that you are not using and Sign-out.
After Change the Password of the Google Account.
(Note: If there's a SMS verification code when changing password and it's not your number, DM the middleman)