Google has issued a significant security advisory to its approximately 2.5 billion Gmail users, recommending they transition away from traditional passwords in favor of more secure authentication methods, particularly passkeys. The advisory supports Google’s broader 2024 initiative to implement passwordless authentication across its services and comes amid an increase in sophisticated phishing attacks and credential theft targeting Gmail accounts.
The technology giant has observed that 37 percent of successful account intrusions stem from phishing and credential theft attacks. The finding follows Google’s recent detection of AI-enhanced phishing campaigns specifically targeting Gmail users through elaborate security alert scams.
“A passkey, from an end user point of view, looks like the biometrics on your device. From a security point of view, it’s actually stronger than a password — even a strong password — because it can’t be phished,” explains Jeff Shiner, CEO of 1Password, which recently integrated passkey support with Windows Hello.
Current data indicates that 64 percent of users do not regularly update their passwords, creating increased security vulnerabilities. Google recommends implementing app-based two-factor authentication (2FA) as an additional security measure, while cautioning users about sophisticated phishing tactics, including attempts by bad actors to impersonate Google Support through calls and emails. The recommendation comes as Google plans to phase out less secure SMS-based verification by 2025.
“So if I can compromise your email, I can compromise pretty much everything else you have,” states Google. The risk is particularly acute as cybercriminals develop more sophisticated methods to bypass traditional security measures, including recent attacks that can circumvent FIDO authentication keys.
The company’s security recommendations include immediate password changes for users who haven’t recently updated them, adoption of passkeys, implementation of app-based 2FA rather than SMS-based verification, use of standalone password managers, and regular monitoring of account activity. Google has also enhanced its built-in Password Manager with new features to help users transition to more secure authentication methods.
The security measures support Google’s broader initiative to transition toward passwordless authentication systems, which are designed to reduce successful phishing and credential theft attempts. The company is part of a larger industry movement, with other major tech companies like Microsoft also shifting away from traditional passwords toward passkey-based security.
Sources: Afrotech, Cybersecurity Review, PhoneArena, Efani