Google issues another warning for Gmail users to secure their accounts

To users that haven’t already locked down your personal accounts in light of massive data breaches: It’s never too late.

That’s why Google is once again urging its Gmail subscribers to protect their accounts, following a series of data attacks on corporate systems that could eventually threaten users’ personal security. Google sent notifications to its 2.5 billion Gmail users in late July and then again on Aug. 8, warning them that hackers were ramping up phishing activity intended to fool users into giving up their log-in credentials.

Google specifically referred to a group known as “ShinyHunters,” which the company says has launched a data leak site (DLS) in an effort to escalate extortion pressure levied at users. Google notes the extortion emails include “shinycorp@tuta. com” and “shinygroup@tuta. com” domains.

Mashable Light Speed

In May, cybersecurity researcher Jeremiah Fowler reported that some 184 million passwords were potentially exposed in an open database, with many of the passwords tied to email providers like Google and social media platforms. One month later, Google Threat Intelligence Group (GTIG) reported that one of its corporate Salesforce server clusters (known as instances) was breached and exposed publicly available business information, such as business names and contact details, Google explained. The breach was continued activity from an online threat group known as UNC6040, which uses voice phishing to impersonate IT agents, steal data, and extort money. This week, GTIG issued another advisory to Salesforce clients about a large data breach by hacker group “UNC6395.”

To prevent users getting bested by future phishing attempts, Google has encouraged its users to set up two-factor authentication and update their passwords. The company has also warned users never to click on emails with alerts such as “suspicious sign in prevented,” which are commonly used by hackers during periods of increased cybersecurity warnings. Instead, users should check security alerts on their own — more on how to do that below.

How to check your Google security activity

What You Need

  • Google account access
  • desktop or mobile app.

Step 1:
Log into your Google account.

Go to myaccount.google.com

Step 2:
Navigate to “Security”.

For desktop users, find this on the left side of the screen next to the padlock icon.

Step 3:
Go to “Recent security activity”.

Any security alerts in the last 28 days, including new sign-ins, should be visible here. Users can click for more information.

How to change your Gmail password

What You Need

  • Google account access
  • desktop or mobile app

Step 1:
Log into your Google account.

Step 2:
Navigate to “Security.”

Step 3:
Scroll to the “How you sign in to Google” section.

Step 4:
Click “Password”.

Users can also see the last time they changed their password.

Step 5:
Log in using your current password one more time.

How to set up 2-Step verification for Google

What You Need

  • Google account access
  • desktop or mobile app

Step 1:
Log in to your Google account.

Step 2:
Navigate to “Security.”

Step 3:
Scroll to “How you sign in to Google”.

Step 4:
Click “Turn on 2-Step Verification”.

Step 5:
Follow the steps on-screen.

In order to enable multi factor authentication, users will need to use an on-device passkey, the Google authenticator app (or other third-party authenticator), link a personal phone number, or set up a backup code.


Source link

Leave a Reply

Your email address will not be published. Required fields are marked *