Gmail Users Warned of New Phishing Threats
Gmail Users Warned of New Phishing Threats

Security researchers at Google Threat Intelligence Group have confirmed that sophisticated cyber attacks bypassing Google's multi-factor authentication have already occurred. The attacks, attributed to Russian cyber criminals, target older devices that cannot accommodate the additional verification step required for modern security protocols.

Google provides app passwords—unique 16-digit codes—to protect less modern devices. However, because these passwords circumvent the second verification step, hackers can more easily steal or phish them. According to Malwarebytes, the attackers posed as State Department representatives to target notable academics and critics of Russia.

Malwarebytes warned that although this has been a highly targeted attack, the general public could be next. They advised users to only use app passwords when absolutely necessary and to switch to more secure sign-in methods where possible. Enabling multi-factor authentication with authenticator apps or hardware security keys is recommended over SMS-based codes.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Other safety tips include regularly educating oneself about phishing attempts, monitoring for unusual login activity, keeping operating systems and apps updated, and using security software to block malicious domains.

Pickt after-article banner — collaborative shopping lists app with family illustration