HomeTechnologyGmail users attacked by hackers, Google confirms: Here’s what you can do to safeguard your account

Gmail users attacked by hackers, Google confirms: Here’s what you can do to safeguard your account

Google has confirmed that hackers have launched a new kind of attack that could put your account at risk, even if you think you’re being careful.

June 25, 2025 / 08:01 IST
Story continues below Advertisement
Gmail
Gmail

If you use Gmail, here’s a heads-up: Google has confirmed that hackers have launched a new kind of attack that could put your account at risk, even if you think you’re being careful.

The attack, which was uncovered by Google’s Threat Intelligence Group and Citizen Lab, is linked to Russian state-backed hackers. They managed to trick high-profile targets by using what looked like real U.S. State Department email addresses. The emails included calendar invites and PDFs. And that’s where the trap was set.

Story continues below Advertisement

Once the victim clicked the PDF, it asked them to visit a real Google URL: https://account.google.com. It seemed trustworthy. But the goal was to get users to create something called an App-Specific Password (ASP)—a special 16-digit password meant for apps that don’t support two-step verification.

Then, the hackers told victims to share a screenshot of this ASP in order to "open the document." Once the attacker had it, they used the ASP to log into the user’s Gmail account without needing any extra verification.