Back to Insights Identity & Access

Do you have a Gmail account (who doesn’t!)? Google recommends upgrading your security settings as soon as possible to avoid vulnerabilities.

Google Confirms: Most Users Must Update Their Vulnerable Passwords; Transition to Passkeys and Two-Factor Authentication Recommended

Google has issued a warning to millions of Gmail users following a new attack in which threat actors leveraged the company’s infrastructure to steal passwords. A primary recommendation is to upgrade security measures and abandon simple passwords in favor of passkeys—a new access method that significantly reduces phishing risks. Anyone still relying on passwords and 2FA (Two-Factor Authentication) should ensure they upgrade their account as soon as possible.

While strong passwords and 2FA assist in account protection, the risk persists. Google notes that 2FA codes can be stolen or compromised in cases of sophisticated attacks. In contrast, upgrading to passkeys offers a phishing-resistant solution. This technology enables account login without a password, utilizing biometric measures such as fingerprints or facial recognition instead.

Historic Password Leak: What You Need to Know

According to recent reports, the password leak involved over 16 billion records, some containing highly sensitive data, including medical, financial, and geographic location information. The core issue is that this is not a single new breach, but a compilation of leaks from multiple sources over time. This leaked data can be used by attackers for identity theft or to breach various accounts.

A password leak is not limited to attacks on a single account. Threat actors can use this information to take over additional accounts, perform password resets, or steal further personal information. Google recommends moving away from old passwords and transitioning to passkeys, a solution that eliminates the need for a password entirely. Furthermore, any message received regarding a password reset, especially from unknown sources, should be deleted immediately.

Avoiding Phishing Attacks and Account Breaches: Avoid Unknown Password Reset Links

Google warns that any message suggesting a password reset via unknown links is a scam. Phishing attacks often provide links leading to fraudulent websites designed to harvest your information. The only way to make changes to passwords is through the company’s official channels, not via links sent in suspicious messages.

Although the industry is working to combat these attacks, these leaks highlight the immediate need to upgrade personal account protection. Beyond using strong passwords and two-step verification, passkeys offer the strongest protection currently available by tethering account security to device security.

Recommendations from IPV Security Experts:

1. Use Passkeys: Transition to passkey usage for all possible accounts, including Google, iCloud, Microsoft, and others.
2. Update Passwords Frequently: Even if your password appears strong, avoid reuse and change it often.
3. Maintain 2FA Security: Enable two-factor authentication using Authenticator apps or other hardware methods (avoid SMS).

In conclusion, Google’s new recommendation to upgrade account protection via passkeys is a modern and essential solution. This change ensures better safeguarding of personal information and mitigates risks of phishing and identity theft.

For more information: [Forbes Article Link]

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation