Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Apple Confirms iPhone Attacks—All Users Must Update Now

Apple Confirms iPhone Attacks—All Users Must Update Now

13 December 2025
Wisconsin couple’s ACA health plan soars from  a month to ,600 as subsidies expire

Wisconsin couple’s ACA health plan soars from $2 a month to $1,600 as subsidies expire

13 December 2025
Samsung Galaxy S26 Release Date: What’s Happening In May?

Samsung Galaxy S26 Release Date: What’s Happening In May?

13 December 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Google’s Gmail Warning—Do Not Use Any Of These Passwords
Innovation

Google’s Gmail Warning—Do Not Use Any Of These Passwords

Press RoomBy Press Room19 June 20253 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Google’s Gmail Warning—Do Not Use Any Of These Passwords

Google has confirmed details of a very complex attack with a very simple warning attached. Yet again, bad actors have exploited Google’s legitimate account infrastructure to trick users into compromising their own security. And while in this instance the victims were highly targeted, the basic vulnerability affects all users.

Google’s Threat Intelligence Group and Citizen Lab warn that Russian state-affiliated hackers used seemingly legitimate U.S. State Department email addresses to help target high-value individuals with emails and calendar invites. With a target hooked, a malicious PDF attachment was then sent which triggered a password request to open.

Victims were directed to https://account.google.com “to create an Application Specific Password (ASP) or ‘app password’. ASPs are randomly generated 16-character passcodes that allow third-party applications to access your Google Account, intended for applications and devices that do not support features like 2-step verification (2SV).”

As Citizen Lab says, “while many state-backed attackers still focus on phishing a target’s passwords and MFA codes, others are constantly experimenting with novel ways to access accounts.” This attack “is yet another effort to gain account access through a novel method: convincing the target user to create and share a screenshot of an App-Specific Password (ASP).”

The target was then told to share the Gmail ASP to open the document. This enabled the attackers to gain access to the victim’s Gmail account using that ASP. As Google says, “users have complete control over their ASPs and may create or revoke them on demand.” But if you don’t know you’ve been attacked, you have no reason to do so.

Two separate warnings here. If you consider yourself a high-value target for any flavor of sophisticated or even state-affiliated hacker, if you’re in a high-profile or high-risk job or location, then you should enable Google’s Advanced Protection Program. This will better lock down your account, but it is for a small minority of users.

For all others, the second warning is not to use these ASPs. Google warns “app passwords aren’t recommended and are unnecessary in most cases. To help keep your account secure, use ‘Sign in with Google’ to connect apps to your Google Account.”

Even if you’re not at risk from a sophisticated attack, the use of ASPs has now been flagged and it wil be very easy for attackers to socially engineer simpler, wider campaigns that trick users into sharing ASPs using a wide variety of lures. As such do not set these up and certainly never share them.

Gmail Attack gmail keep account Gmail Passkey Gmail password gmail upgrade account Gmail warning google attack
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Apple Confirms iPhone Attacks—All Users Must Update Now

Apple Confirms iPhone Attacks—All Users Must Update Now

13 December 2025
Samsung Galaxy S26 Release Date: What’s Happening In May?

Samsung Galaxy S26 Release Date: What’s Happening In May?

13 December 2025
Google’s Play Update—Bad News For Most Samsung Users

Google’s Play Update—Bad News For Most Samsung Users

13 December 2025
WWE SmackDown December 12, 2025 Results: Highlights And Takeaways

WWE SmackDown December 12, 2025 Results: Highlights And Takeaways

13 December 2025
‘NYT Mini’ Clues And Answers For Saturday, December 13

‘NYT Mini’ Clues And Answers For Saturday, December 13

13 December 2025
Pixel 10a Specs Leak, Magic8 Pro Launch, Google’s Emoji Update

Pixel 10a Specs Leak, Magic8 Pro Launch, Google’s Emoji Update

13 December 2025
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
John Summit went from working 9 a.m. to 9 p.m. in a ,000 job to a multimillionaire DJ—‘I make more in one show than I would in my entire accounting career’

John Summit went from working 9 a.m. to 9 p.m. in a $65,000 job to a multimillionaire DJ—‘I make more in one show than I would in my entire accounting career’

18 October 2025
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Banking on carbon markets 2.0: why financial institutions should engage with carbon credits

Banking on carbon markets 2.0: why financial institutions should engage with carbon credits

13 December 20250 Views
This CEO went back to college at 52, but says successful Gen Zers ‘forge their own path’

This CEO went back to college at 52, but says successful Gen Zers ‘forge their own path’

13 December 20250 Views
It’s a sequel, it’s a remake, it’s a reboot: Lawyers grow wistful for old corporate rumbles as Paramount, Netflix fight for Warner

It’s a sequel, it’s a remake, it’s a reboot: Lawyers grow wistful for old corporate rumbles as Paramount, Netflix fight for Warner

13 December 20252 Views
Oracle’s collapsing stock shows the AI boom is running into two hard limits: physics and debt

Oracle’s collapsing stock shows the AI boom is running into two hard limits: physics and debt

13 December 20250 Views
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Apple Confirms iPhone Attacks—All Users Must Update Now

Apple Confirms iPhone Attacks—All Users Must Update Now

13 December 2025
Wisconsin couple’s ACA health plan soars from  a month to ,600 as subsidies expire

Wisconsin couple’s ACA health plan soars from $2 a month to $1,600 as subsidies expire

13 December 2025
Samsung Galaxy S26 Release Date: What’s Happening In May?

Samsung Galaxy S26 Release Date: What’s Happening In May?

13 December 2025
Most Popular
Gen Z is drinking 20% less than Millennials. Productivity is rising. Coincidence? Not quite

Gen Z is drinking 20% less than Millennials. Productivity is rising. Coincidence? Not quite

13 December 20250 Views
Banking on carbon markets 2.0: why financial institutions should engage with carbon credits

Banking on carbon markets 2.0: why financial institutions should engage with carbon credits

13 December 20250 Views
This CEO went back to college at 52, but says successful Gen Zers ‘forge their own path’

This CEO went back to college at 52, but says successful Gen Zers ‘forge their own path’

13 December 20250 Views
© 2025 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.