Moneycontrol PRO
HomeTechnologyGmail users attacked by hackers, Google confirms: Here’s what you can do to safeguard your account

Gmail users attacked by hackers, Google confirms: Here’s what you can do to safeguard your account

Google has confirmed that hackers have launched a new kind of attack that could put your account at risk, even if you think you’re being careful.

June 25, 2025 / 08:01 IST
Gmail

If you use Gmail, here’s a heads-up: Google has confirmed that hackers have launched a new kind of attack that could put your account at risk, even if you think you’re being careful.

The attack, which was uncovered by Google’s Threat Intelligence Group and Citizen Lab, is linked to Russian state-backed hackers. They managed to trick high-profile targets by using what looked like real U.S. State Department email addresses. The emails included calendar invites and PDFs. And that’s where the trap was set.

Once the victim clicked the PDF, it asked them to visit a real Google URL: https://account.google.com. It seemed trustworthy. But the goal was to get users to create something called an App-Specific Password (ASP)—a special 16-digit password meant for apps that don’t support two-step verification.

Then, the hackers told victims to share a screenshot of this ASP in order to "open the document." Once the attacker had it, they used the ASP to log into the user’s Gmail account without needing any extra verification.

Here’s the scary part: these ASPs are created and controlled by users. Unless you know you’ve been targeted, you wouldn’t think to revoke them.

What you should do now:

--Don’t use App-Specific Passwords unless absolutely necessary. Google now says these are outdated and not needed in most cases.

--Never share an ASP, no matter how convincing a message looks.

--Stick to “Sign in with Google” when linking third-party apps to your account—it’s safer and more secure.

If you’re in a sensitive job, or consider yourself a potential high-value target, consider enrolling in Google’s Advanced Protection Program. It’s built for people who need extra account security.

Even if this attack was aimed at a small group, the method could be used in larger scams soon. So stay alert, and never share special passwords or access codes—no matter how real the request looks.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Jun 25, 2025 08:00 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347