{"id":304246,"date":"2025-07-30T15:36:16","date_gmt":"2025-07-30T15:36:16","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/304246\/"},"modified":"2025-07-30T15:36:16","modified_gmt":"2025-07-30T15:36:16","slug":"gmails-new-password-warning-update-accounts-now-as-attacks-surge","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/304246\/","title":{"rendered":"Gmail\u2019s New Password Warning \u2014 Update Accounts Now As Attacks Surge"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/uk\/wp-content\/uploads\/2025\/07\/1753889776_725_960x0.jpg\" alt=\"Gmail logo on a smartphone, with computer code seen behind and 'password' highlighted in red.\" data-height=\"3156\" data-width=\"4732\" style=\"position:absolute;top:0\"\/><\/p>\n<p class=\"color-body light-text\" role=\"button\">Change your Gmail password now \u2014 Google warns users.<\/p>\n<p>SOPA Images\/LightRocket via Getty Images<\/p>\n<p>Update, July 30, 2025: This story, originally published on July 28, has been updated with confirmation of a second Google security update: Gmail passkey and Device Bound Session Credentials announcements are now joined by Project Zero reporting transparency changes.<\/p>\n<p>It\u2019s official: Google accounts are <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/25\/gmail-and-samsung-account-deletions---why-94-of-you-must-act-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/25\/gmail-and-samsung-account-deletions---why-94-of-you-must-act-now\/\" target=\"_self\" aria-label=\"under attack\" rel=\"noopener\">under attack<\/a>, and those attacks have spiked by an incredible amount. According to Google itself, it observed an 84% increase in Gmail two-factor authentication <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/04\/fbi-2fa-bypass-warning-issued---the-attacks-have-started\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/04\/fbi-2fa-bypass-warning-issued---the-attacks-have-started\/\" target=\"_self\" aria-label=\"bypass attacks\" rel=\"noopener\">bypass attacks<\/a> across 2024 and has now confirmed that this \u201dhas only intensified in 2025.\u201d When it comes to the bigger picture, phishing and <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/01\/secure-your-gmail-now-as-google-warns-of-password-attacks\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/01\/secure-your-gmail-now-as-google-warns-of-password-attacks\/\" target=\"_self\" aria-label=\"credential theft\" rel=\"noopener\">credential theft<\/a> are now behind more than a third of all successful <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/05\/08\/new-gmail-2fa-code-attack-alert---dont-lose-your-account-access\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/05\/08\/new-gmail-2fa-code-attack-alert---dont-lose-your-account-access\/\" target=\"_self\" aria-label=\"Google account attacks\" rel=\"noopener\">Google account attacks<\/a>. But Google has been fighting back, and a July 29 announcement outlines a new security protection being offered to some, along with a warning for all users to change their passwords now.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-6\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/30\/urgent-google-chrome-update-confirmed---download-and-restart-now\/\" target=\"_blank\" aria-label=\"Urgent Google Chrome Update Confirmed \u2014 Download And Restart Now\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/30\/urgent-google-chrome-update-confirmed---download-and-restart-now\/\">ForbesUrgent Google Chrome Update Confirmed \u2014 Download And Restart NowBy Davey Winder<\/a><\/p>\n<p>Change Your Gmail Password Now As Attacks Escalate<\/p>\n<p>It is always refreshing to hear the largest of tech companies being honest about the security challenges they face, and Google certainly falls into this category. More so when you are talking about Gmail, with some 2.5 billion users worldwide, and under constant attack, like all large email platforms, from threat actors looking to compromise accounts.<\/p>\n<p>\u201cAttackers are intensifying their phishing and credential theft methods,\u201d Andy Wen, senior director of product management at Google has warned, \u201cwhich drive 37% of successful intrusions.\u201d What\u2019s more, Wen continued, \u201cwe\u2019ve seen an exponential rise in cookie and authentication token theft as a preferred method for attackers.\u201d Thankfully, the <a class=\"color-link\" href=\" https:\/\/workspace.google.com\/blog\/identity-and-security\/defending-against-account-takeovers-top-threats-passkeys-and-dbsc?e=48754805\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/workspace.google.com\/blog\/identity-and-security\/defending-against-account-takeovers-top-threats-passkeys-and-dbsc?e=48754805\" aria-label=\"Google announcement\">Google announcement<\/a> does not stop there. Instead, it shares account security enhancements to mitigate just these types of attacks.<\/p>\n<p>While the Google announcement itself is directed at Google Workspace customers specifically, the first of the recommendations forms a warning that all 2.5 billion Gmail users should heed: update your account from using a password to a passkey. The \u201cenhancement\u201d that Google is referring to here is that such passkeys support is now available, with \u201cexpanded admin capabilities to audit enrollment and restrict passkeys to physical security keys,\u201d to more than 11 million Google Workspace customers. That\u2019s important, of course, but please make the change from password to passkey regardless of whether you are using a paid-for or free Gmail account. The attackers, I can assure you, couldn\u2019t care less.<\/p>\n<p>The other advice is strictly for those Workspace customers, however, and comes by way of an open beta of Device Bound Session Credentials to protect against those 2FA cookie bypass attacks mentioned earlier, as well as another beta, a shared signals framework, that will be offered to \u201cselect customers and partners\u201d later this year.<\/p>\n<p>\u201cThese advancements can meaningfully enhance account security,\u201d Wen said, \u201cmarking a major step forward in defending against account takeovers for Google Workspace customers.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-5\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/30\/141-million-file-data-breach-reveals-bank-statements-and-crypto-keys\/\" target=\"_blank\" aria-label=\"141 Million Data Breach Files Reveal Bank Statements And Crypto Keys\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/30\/141-million-file-data-breach-reveals-bank-statements-and-crypto-keys\/\">Forbes141 Million Data Breach Files Reveal Bank Statements And Crypto KeysBy Davey Winder<\/a><\/p>\n<p>Device Bound Session Credentials provide users with enhanced post-authentication protection, Wen explained, by helping to ensure that only the originating device can access the active session which, therefore, reduces the risk of cookie theft and 2FA bypass. DBSC also provides stronger sessions integrity, Google said, by bolstering protections with \u201cmore granular account attributes when used together with context-aware access, even if an attacker obtains login credentials after the initial login.\u201d<\/p>\n<p>Not Just Gmail \u2014 Google Announces Project Zero Transparency Changes<\/p>\n<p>A July 30 announcement by the <a class=\"color-link\" href=\"https:\/\/googleprojectzero.blogspot.com\/2025\/07\/reporting-transparency.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/googleprojectzero.blogspot.com\/2025\/07\/reporting-transparency.html\" aria-label=\"Project Zero team\">Project Zero team<\/a> is the second major confirmation of security changes from Google in as many days. Tim Willis, head of Google\u2019s Project Zero, founded in 2014 and tasked with uncovering zero-day security vulnerabilities, has confirmed that changes are being introduced to reduce the \u201cpatch gap\u201d or delay between funding a vulnerability and getting the fix to your devices.<\/p>\n<p>The patch gap is, Willis admitted, a very complex issue to solve and goes beyond my oversimplistic description above. \u201cOur work has highlighted a critical, earlier delay: the upstream patch gap,\u201d Willis said, explaining that this covers the period between an upstream vendor having a fix and it getting integrated into \u201cdownstream dependents\u201d products that can be distributed to users. \u201cThis upstream gap significantly extends the vulnerability lifecycle,\u201d Willis warned.<\/p>\n<p>Enter reporting transparency, or rather, Google Project Zero\u2019s reporting transparency trial. The existing core 90-day vulnerability disclosure deadline is going nowhere and will remain in effect, but it will be amended by an addition at the beginning of the process itself. As of today, Willis has confirmed, Google Project Zero will publicly share that a vulnerability has been discovered and do so within a week of it being reported to a vendor.<\/p>\n<p>\u201cWe hope that this trial will encourage the creation of stronger communication channels between upstream vendors and downstream dependents relating to security,\u201d Willis concluded, \u201cleading to faster patches and improved patch adoption for end users.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-7\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/30\/dropbox-app-warning-confirmed---passwords-deleted-if-you-dont-act\/\" target=\"_blank\" aria-label=\"Dropbox App Warning Confirmed \u2014 Passwords Deleted If You Don\u2019t Act\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/30\/dropbox-app-warning-confirmed---passwords-deleted-if-you-dont-act\/\">ForbesDropbox App Warning Confirmed \u2014 Passwords Deleted If You Don\u2019t ActBy Davey Winder<\/a><br \/>\nWhy All Users Should Update Gmail Accounts To Use Passkey Protection<\/p>\n<p>The <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/04\/19\/stop-using-your-password---800-million-stolen-passwords-listed-online\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/04\/19\/stop-using-your-password---800-million-stolen-passwords-listed-online\/\" target=\"_self\" aria-label=\"benefits of passkeys\" rel=\"noopener\">benefits of passkeys<\/a> compared to passwords are no secret, and have been put forward time and time again. Wen has reinforced the greater security that can be offered by making this one simple change: \u201cUnlike passwords, which can be guessed, stolen, or forgotten, passkeys are unique digital credentials tied to a user\u2019s device.\u201d<\/p>\n<p>Here are three reasons why Google wants all users to switch to passkey technology, and switch now:<\/p>\n<ol>\n<li>Passkeys are inherently more phishing-resistant because users cannot be tricked into handing over passkeys to a malicious actor.<\/li>\n<li>Signing in with passkeys is as simple as unlocking your device, such as using a PIN or biometrics, such as a fingerprint or facial recognition.<\/li>\n<li>Unlike passwords that are often reused, each passkey is unique and generated for each specific website or service.<\/li>\n<\/ol>\n<p>So, what are you waiting for? Take note of the Google warning and update your Gmail account security now.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-8\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/28\/new-fbi-warning---windows-and-linux-users-must-apply-2fa-now\/\" target=\"_blank\" aria-label=\"New FBI Warning \u2014 Windows And Linux Users Must Apply 2FA Now\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/28\/new-fbi-warning---windows-and-linux-users-must-apply-2fa-now\/\">ForbesNew FBI Warning \u2014 Windows And Linux Users Must Apply 2FA NowBy Davey Winder<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Change your Gmail password now \u2014 Google warns users. SOPA Images\/LightRocket via Getty Images Update, July 30, 2025:&hellip;\n","protected":false},"author":2,"featured_media":304247,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[112027,112021,112023,24781,112020,112019,112022,112024,112026,112025,53,16,15],"class_list":{"0":"post-304246","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-dbsc","9":"tag-gmail-2fa","10":"tag-gmail-2fa-bypass","11":"tag-gmail-hack","12":"tag-gmail-passkey","13":"tag-gmail-password","14":"tag-gmail-password-hacked","15":"tag-google-2fa","16":"tag-google-device-bound-session-credentials","17":"tag-google-password-hack","18":"tag-technology","19":"tag-uk","20":"tag-united-kingdom"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@uk\/114942928093776401","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/304246","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=304246"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/304246\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/304247"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=304246"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=304246"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=304246"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}