{"id":202271,"date":"2025-06-21T10:16:09","date_gmt":"2025-06-21T10:16:09","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/202271\/"},"modified":"2025-06-21T10:16:09","modified_gmt":"2025-06-21T10:16:09","slug":"google-confirms-most-gmail-users-must-upgrade-all-their-accounts","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/202271\/","title":{"rendered":"Google Confirms Most Gmail Users Must Upgrade All Their Accounts"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/uk\/wp-content\/uploads\/2025\/06\/1750500969_31_960x0.jpg\" alt=\"Google app on screen\" data-height=\"3440\" data-width=\"5160\" style=\"position:absolute;top:0\"\/><\/p>\n<p class=\"color-body light-text\" role=\"button\">Most accoiunts need an upgrade, says Google.<\/p>\n<p>AFP via Getty Images<\/p>\n<p>Republished on June 21 with new advice after \u201crecord breaking\u201d security alert.<\/p>\n<p>Google has <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/06\/19\/googles-gmail-warning-do-not-use-any-of-these-passwords\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/06\/19\/googles-gmail-warning-do-not-use-any-of-these-passwords\/\" target=\"_self\" aria-label=\"confirmed another atack on Gmail users\" rel=\"noopener\">confirmed another atack on Gmail users<\/a> this week. Yet again, its own infrastructure has been exploited to compromise user accounts. And yet again, it comes with another warning for users to upgrade their accounts \u2014 this is now a must.<\/p>\n<p>Earlier this month, I covered <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/06\/08\/google-confirms-almost-all-gmail-users-must-upgrade-accounts\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/06\/08\/google-confirms-almost-all-gmail-users-must-upgrade-accounts\/\" target=\"_self\" aria-label=\"Google\u2019s warning\" rel=\"noopener\">Google\u2019s warning<\/a> that most of its users still only use basic password security and are wide open to data breaches and attacks. \u201cWe want to move beyond passwords altogether,&#8221; <a class=\"color-link\" href=\"https:\/\/blog.google\/technology\/safety-security\/google-survey-digital-security-2025\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/blog.google\/technology\/safety-security\/google-survey-digital-security-2025\/\" aria-label=\"Google said,\">Google said,<\/a> pushing users to replace them.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-6\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/06\/20\/microsoft-google-and-facebook-warnings-stop-using-your-passwords\/\" target=\"_blank\" aria-label=\"Stop Using Your Microsoft, Google And Facebook Passwords\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/06\/20\/microsoft-google-and-facebook-warnings-stop-using-your-passwords\/\">ForbesStop Using Your Microsoft, Google And Facebook PasswordsBy Zak Doffman<\/a><\/p>\n<p><a class=\"color-link\" href=\"https:\/\/www.google.com\/account\/about\/passkeys\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.google.com\/account\/about\/passkeys\/\" aria-label=\"Passkeys\">Passkeys<\/a>, it says, &#8220;are phishing-resistant and can log you in simply with the method you use to unlock your device (like your fingerprint or face ID) \u2014 no password required.\u201d Put simply, this links account security to hardware security, and means there are no passwords to steal or two-factor authentication (2FA) codes to bypass or intercept.<\/p>\n<p>While that is critical for Gmail users, it\u2019s actually much wider. Google reached out to me after that article, to emphasize that the benefits are more significant for users: Adding a passkey to a Google account protects all the services and accounts that can be accessed by that sign in. Conversely, not doing so leaves all those other accounts at risk.<\/p>\n<p>Even if most user accounts were secured by passwords and 2FA codes, there would still be a push to passkeys. And while Google, Microsoft and others make 2FA mandatory, the reality is that there\u2019s still a risk that codes can be shared even if they can\u2019t be stolen. That was the crux of the latest Gmail attack, tricking users into sharing codes.<\/p>\n<p class=\"color-body light-text\" role=\"button\">Scams and Protections (June 2025)<\/p>\n<p>Google \/ Morning Consult<\/p>\n<p>The raft of headlines around <a class=\"color-link\" href=\"https:\/\/cybernews.com\/security\/billions-credentials-exposed-infostealers-data-leak\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/cybernews.com\/security\/billions-credentials-exposed-infostealers-data-leak\/\" aria-label=\"a new 16 billion record data breach\">a new 16 billion record data breach<\/a> should focus minds, even if \u201cthis is not a new data breach, or a breach at all,\u201d says <a class=\"color-link\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/no-the-16-billion-credentials-leak-is-not-a-new-data-breach\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.bleepingcomputer.com\/news\/security\/no-the-16-billion-credentials-leak-is-not-a-new-data-breach\/\" aria-label=\"Bleeping Computer\">Bleeping Computer<\/a>. \u201cThe websites involved were not recently compromised to steal these credentials.\u201d<\/p>\n<p><a class=\"color-link\" href=\"https:\/\/mashable.com\/article\/16-billion-passwords-leaked-explanation\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/mashable.com\/article\/16-billion-passwords-leaked-explanation\" aria-label=\"Mashable\">Mashable<\/a> agrees. \u201cSome commentators were quick to call it the largest password leak in history, and in terms of raw records exposed, that\u2019s mostly, technically true. However, these records did not come from a single breach \u2014 or even a new breach. Instead, they came from many smaller ones,&#8221; with \u201cthe end result more a \u2018greatest hits\u2019 rather than a new, noteworthy hack.\u201d Albeit that doesn\u2019t change the fact the data is out there.<\/p>\n<p><a class=\"color-link\" href=\"https:\/\/www.kaspersky.co.uk\/blog\/16-billion-passwords-leak-2\/29080\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.kaspersky.co.uk\/blog\/16-billion-passwords-leak-2\/29080\/\" aria-label=\"Kaspersky\">Kaspersky<\/a> says \u201cthe journalists haven\u2019t provided any evidence of existence of this database. Therefore, neither Kaspersky\u2019s experts nor anyone else has managed to analyze it. Therefore, we cannot say whether yours \u2013 or anyone else\u2019s \u2013 data is in there.\u201d<\/p>\n<p>But, regardless, Google\u2019s latest survey still paints a bleak picture. Although \u201c60% of U.S. consumers say they \u201cuse strong, unique passwords,\u201d less than 50% \u201cenable 2FA.\u201d<\/p>\n<p>The truth is that the only form of simple 2FA is SMS codes, which are sent quickly without having to exit the app or click or tap. They even autofill and often auto-delete. But SMS is woefully insecure, <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/06\/18\/why-you-should-stop-using-sms-2fa-codes-on-your-smartphone\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/06\/18\/why-you-should-stop-using-sms-2fa-codes-on-your-smartphone\/\" target=\"_self\" aria-label=\"it\u2019s the worst possible 2FA option\" rel=\"noopener\">it\u2019s the worst possible 2FA option<\/a>. And anything else \u2014 authenticator apps, physical keys, even trusted device or app sign-ins \u2014 is more painful.<\/p>\n<p>Passkeys are the opposite. They\u2019re even easier than passwords and SMS 2FA. The code (which you never see) combines your login ID, password and 2FA into a simple sign-in process authenticated by your device security \u2014 ideally biometrics. And because there is no code you can see or copy, you can\u2019t share the passkey even if you want to. Even if any of the underlying code is stolen, it only works on your actual device.<\/p>\n<p>Google is right \u2014 this is about much more than Gmail, even if those email account attacks generate headline after headline. While there are some misgivings about the dominance and data overreach in big tech using its span of control to sign you into multiple services, even those they don\u2019t own or control, it is more secure.<\/p>\n<p>As Kaspersky suggests, \u201clet\u2019s set skepticism aside. Yes, we don\u2019t reliably know what exactly this leak is, or whose data is in it. But that doesn\u2019t mean you should do nothing. The first and best recommendation is to change your passwords,\u201d which is an obvious immediate step. But it doesn\u2019t solve the problem.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-7\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/06\/19\/you-must-never-call-these-numbers-on-your-smartphone\/\" target=\"_blank\" aria-label=\"Do Not Call These Numbers On Your Smartphone\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/06\/19\/you-must-never-call-these-numbers-on-your-smartphone\/\">ForbesDo Not Call These Numbers On Your SmartphoneBy Zak Doffman<\/a><\/p>\n<p>\u201cUse passkeys wherever possible,\u201d Kaspersky also tells users. \u201cThis is the modern passwordless method of logging into accounts, which is already supported by Google, iCloud, Microsoft, Meta and others.\u201d<\/p>\n<p>As Google says, \u201cwhen you pair the ease and safety of passkeys with your Google Account, you can then use Sign in with Google to log in to your favorite websites and apps \u2014 limiting the number of accounts you have to maintain.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Most accoiunts need an upgrade, says Google. AFP via Getty Images Republished on June 21 with new advice&hellip;\n","protected":false},"author":2,"featured_media":202272,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[24779,81595,81594,81593,5594,632,81589,81592,81590,81591,53,16,15],"class_list":{"0":"post-202271","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-gmail-attack","9":"tag-gmail-change-account","10":"tag-gmail-keep-account","11":"tag-gmail-lose-account","12":"tag-gmail-upgrade","13":"tag-gmail-warning","14":"tag-google-change-password","15":"tag-google-data-deletion","16":"tag-google-keep-account","17":"tag-google-lose-account","18":"tag-technology","19":"tag-uk","20":"tag-united-kingdom"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@uk\/114720839213440123","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/202271","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=202271"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/202271\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/202272"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=202271"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=202271"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=202271"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}