logo
Gmail Password Warning — You Have 7 Days To Act, Google Says

Gmail Password Warning — You Have 7 Days To Act, Google Says

Forbes02-05-2025

Update, May 2, 2025: This story, originally published May 1, has been updated with details of AI-powered threats that email users need to be aware of as Gmail password hackers attack.
It can't have escaped your attention that May 1 is World Password Day, when security experts and public relations organizations compete to see who can create the most ridiculous password-related stories to feed to the media and public alike. Yes, I'm cynical about the whole charade, as we should be taking password security seriously all year and not just on a designated day — preferably getting rid of them altogether and shifting to the more secure passkey option. It can't have escaped your attention that users of the world's most popular free email platform, Gmail, have been under attack from hackers who seek to compromise passwords and gain access to the valuable data that a Google account can hold. So, dear reader, my password story for May 1 has less to do with making your password stronger and everything to do with getting access to your Gmail account back after a Gmail password hacker has compromised it and locked you out. Google has said you have seven days — yes, a whole week — in which you can get that access back even if the attacker has changed your recovery telephone number.
As you might imagine, given my experiences as a hacker and the fact that I have been writing about cybersecurity matters for more than 30 years now, I receive a lot of emails and messages from people who have fallen victim to attacks and are looking for help. By far the most common of these pleas for help is along the lines of 'Gmail password hackers have compromised my account, changed the recovery options, password, two-factor authentication method, and locked me out — what the heck can I do?'
Unfortunately, these kinds of password-hacking compromises against Gmail users have become increasingly popular as threat actors of all types employ AI-driven attacks to access those highly valuable email accounts. Read on to discover how some of these AI attacks are evolving, as details emerge in a new Check Point Research report.
But first, and rather fortunately, Google is fighting back when it comes to offering both protection against these increasingly sophisticated attackers and help in recovering accounts if a user has fallen victim.
As long as you have had the forethought to provide a recovery telephone number or email address before the attack took place, then you have seven days in which you can regain access to your hacked Gmail account even if the attacker has changed them.
Everyone uses a seatbelt when driving or being driven because it has been proven to dramatically improve safety and reduce the chances of fatality if involved in an accident when compared to not wearing one. Now replace seatbelt with recovery options, car with Gmail account, and accident with incident to arrive at a similar conclusion: having a recovery telephone number in place improves your chances of getting your account back if a hacker attacks.
Likewise, using a phishing-resistant authentication technology, such as a passkey, instead of a password decreases the likelihood of an attacker being successful in the first place. To continue the motoring analogy, a passkey is like a car protected by driveway bollards and a remote kill switch rather than parking on the street and relying on an easily bypassed door lock.
'We recommend all users to set up a recovery phone as well as a recovery email on their account,' Gmail spokesperson Ross Richendrfer told me, 'these can be used in cases where users forget their own passwords, or an attacker changes the credentials after hijacking the account.'
And therein lies the rub for any hacker: if you are the original account holder, despite the best efforts of an attacker to lock you out of your own account by changing all the security options, you can get access back as long as you act within seven days. 'Our automated account recovery process allows a user to use their original recovery factors for up to 7 days after it changes,' Richendrfer said, 'provided they set them up before the incident.'
If you have found yourself locked out of your account following a Gmail password hack attack, Richendrfer said you can refer to the 'How to recover your Google account or Gmail' guidebook for step-by-step instructions on what to do next.
Analysts at Check Point Research have published details of AI-powered threats, no longer theoretical and very much right here and evolving rapidly, that put your Gmail password at risk. 'As access to Al tools becomes more widespread,' Lotem Finkelstein, director of Check Point Research, said, 'threat actors exploit this shift in two key ways: by leveraging Al to enhance their capabilities and targeting organizations and individuals adopting Al technologies.' It's the former that I'm concerned about in the context of this article about losing control of your Gmail account. It should go without saying, however, that the same AI threats apply to whatever email platform you use, and beyond to most online service accounts in fact.
The use of social engineering is the de facto tactic employed by most attackers looking to compromise a Gmail email account. Indeed, even those attacks that are looking to exploit a known security vulnerability will often begin by exploiting human nature first. These social engineering, or phishing, if you prefer, attacks will leverage every possible media type to convince the victim it is a genuine communication that needs to be interacted with as a matter of urgency. Be it by way of text, audio, or imagery, the phishing attacker will employ it. The problem is, as Check Point Research said, 'with recent advancements in AI, attackers can create authentic-looking materials at scale, conduct automated chats, and hold real-time audio and video conferences while impersonating others.' No wonder so many people are taken in, and so many passwords get compromised, leading to a Gmail account lockout.
The Check Point Report warned that AI-driven tools now proliferate on criminal forums, on the dark web, and in surface web criminal forums, leading to a critical compromise of our ability to rely upon audio and visual clues to determine fact from fiction. 'Fully autonomous audio deepfake tools for large-scale phone scams are already available,' Check Point said, 'meaning that recognizing a familiar face or voice is no longer sufficient proof of identity; instead, interactions must be reinforced by additional authentication measures.'
Don't let Gmail password hackers lock you out of your account. Be alert to every communication and question everything — no matter how realistic it looks or sounds.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

AI leaders have a new term for the fact that their models are not always so intelligent
AI leaders have a new term for the fact that their models are not always so intelligent

Business Insider

timean hour ago

  • Business Insider

AI leaders have a new term for the fact that their models are not always so intelligent

Progress is rarely linear, and AI is no exception. As academics, independent developers, and the biggest tech companies in the world drive us closer to artificial general intelligence — a still hypothetical form of intelligence that matches human capabilities — they've hit some roadblocks. Many emerging models are prone to hallucinating, misinformation, and simple errors. Google CEO Sundar Pichai referred to this phase of AI as AJI, or "artificial jagged intelligence," on a recent episode of Lex Fridman's podcast. "I don't know who used it first, maybe Karpathy did," Pichai said, referring to deep learning and computer vision specialist Andrej Karpathy, who cofounded OpenAI before leaving last year. AJI is a bit of a metaphor for the trajectory of AI development — jagged, marked at once by sparks of genius and basic mistakes. "You see what they can do and then you can trivially find they make numerical errors or counting R's in strawberry or something, which seems to trip up most models," Pichai said. "I feel like we are in the AJI phase where dramatic progress, some things don't work well, but overall, you're seeing lots of progress." In 2010, when Google DeepMind launched, its team would talk about a 20-year timeline for AGI, Pichai said. Google subsequently acquired DeepMind in 2014. Pichai thinks it'll take a little longer than that, but by 2030, "I would stress it doesn't matter what that definition is because you will have mind-blowing progress on many dimensions." By then the world will also need a clear system for labeling AI-generated content to "distinguish reality," he said. "Progress" is a vague term, but Pichai has spoken at length about the benefits we'll see from AI development. At the UN's Summit of the Future in September 2024, he outlined four specific ways that AI would advance humanity — improving access to knowledge in native languages, accelerating scientific discovery, mitigating climate disaster, and contributing to economic progress.

YouTube is warning some Premium Lite subscribers about more ads next month, but don't worry
YouTube is warning some Premium Lite subscribers about more ads next month, but don't worry

Android Authority

time3 hours ago

  • Android Authority

YouTube is warning some Premium Lite subscribers about more ads next month, but don't worry

Joe Maring / Android Authority TL;DR YouTube Premium Lite offers a budget-priced paid subscription that removes most ads from YouTube. Exceptions have included things like music videos, and in some markets Google has warned that Shorts may show ads, as well. The company is now sending out notices to more subscribers warning them that ads in Shorts will start appearing at the end of June. YouTube Premium is well worth paying for, giving users ad-free access to maybe the broadest library of content in streaming history. But especially if you get your music fix from another provider (like paying for Spotify Premium), it doesn't make a ton of sense to be paying full price for YouTube Premium and not taking advantage of its YouTube Music access. That's exactly why we were so happy to see Google introduce YouTube Premium Lite, which just focuses on removing (most) ads without worrying about any extras — and does so for a fraction of the price. While Premium Lite removes the vast majority of ads from normal videos, we've known that Google has carved out a series of exceptions. Those consist of 'music content, Shorts, and when you search or browse.' So far, at least in our experience, those have proved to be minimal, and we've found Premium Lite to offer a very reasonable compromise to paying full price. That said, the situation is now changing a bit, and not for the better — at least for Premium Lite subscribers in some regions. Google has recently been sending out emails to Premium Lite users in Germany, according to Deskmodder (via 9to5Google). These advise subscribers that ads in YouTube Shorts will start appearing as of June 30. We've also uncovered TWiT Community user big_D sharing the same message (this time in English). Curious why Google would be sending out notifications about ads we already knew about, and wondering why these messages didn't seem to be targeted at Premium Lite users in all nations, we reached out to Google in the hopes of getting some clarification. And it turns out that there's a simple explanation for all of this. You may recall that when we first began hearing about Premium Lite in testing last fall, it wasn't yet available in the US, instead getting started in Australia, Germany, and Thailand. And it turns out, as Google was still getting its plans for the service together, it hadn't told subscribers in Germany and Thailand that they'd be seeing ads in Shorts. By the time access expanded to the US, ads in Shorts were on the table from the beginning, but Google is only going back now and notifying customers in Germany and Thailand that they're getting them, too. So that's what going on with these emails: Most Premium Lite subscribers already knew about ads for Shorts, and now YouTube's telling the rest of you. Got a tip? Talk to us! Email our staff at Email our staff at news@ . You can stay anonymous or get credit for the info, it's your choice.

Sprouting Gear Inc. Founder Paul Pluss Announces Report on:
Sprouting Gear Inc. Founder Paul Pluss Announces Report on:

Yahoo

time4 hours ago

  • Yahoo

Sprouting Gear Inc. Founder Paul Pluss Announces Report on:

'The Unintended Consequences of the AI Race on the Livestock Industry' RAMONA, Calif., June 07, 2025 (GLOBE NEWSWIRE) -- The U.S. livestock industry, already grappling with rising feed costs and shrinking herd sizes, now faces a fast-approaching and under-recognized threat: the massive expansion of artificial intelligence (AI) infrastructure—especially data centers—and its impact on water availability, says Paul Pluss, a veteran livestock rancher and researcher focused on the intersection of agriculture, water policy, and emerging infrastructure demands. 'The water usage of data centers operated by Microsoft, Google, Meta, and Amazon remains largely unrecognized by agricultural stakeholders. Prime location for data centers is the same hot dry inland location preferred for feedlots and are often sharing the same aquifers and rivers" said Pluss. Fueled by public and private investment in AI infrastructure, the number of U.S. data centers is expected to grow from 5,426 today to more than 8,378 within five years. Many existing facilities are also expanding. These data centers—crucial for powering AI models, cloud computing, and digital services—require enormous amounts of water to cool their servers. Key figures: Each data center can consume up to 5 million gallons of water per day for cooling. Average water usage per megawatt of electricity is estimated at 6 to 7 million gallons. U.S. data center power demand is currently 35 gigawatts and rising. Annual electricity usage by data centers is expected to nearly triple, from 224 terawatt-hours today to 606 terawatt-hours within five years. Based on current and projected growth, total water use by U.S. data centers could exceed 15 trillion gallons annually—equivalent to more than 46 million acre-feet of water per year (calculated on the well-documented 5M gallons/day per center, prior to new expansions). This level of water consumption rivals agricultural water use in major farming states and could soon surpass the entire livestock industry's combined water footprint, including feed crop irrigation, drinking water, and processing needs. View the report here, as well as a articles and short videos to explain hydroponic livestock feeding and the economics behind it: The Carbon Footprint of Livestock 'Can We REALLY Slash Livestock Environmental Damage by 90 Percent?' Our Country's Water Crisis: Why Aquifers Are a Bigger Problem Than the Colorado River 'Our Country's Water Crisis' From 2 Pounds of Seed to 19 Pounds of Feed Paul PlussCEO & Founderpaul@ in to access your portfolio

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store