Mashable 08月30日
Google提醒用户加强账户安全,防范网络钓鱼
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

谷歌再次呼吁Gmail用户加强账户安全,以应对日益增长的网络钓鱼活动。近期,一系列针对企业系统的攻击可能波及用户个人安全。谷歌已向其25亿Gmail用户发送通知,警告黑客正在升级旨在诱使用户泄露登录凭证的钓鱼活动。文章提到“ShinyHunters”等黑客组织利用数据泄露网站和语音钓鱼等手段进行勒索。为应对威胁,谷歌鼓励用户启用两步验证、更新密码,并警惕“可疑登录已阻止”等邮件,建议用户直接在账户中查看安全警报。

🛡️ **账户安全风险加剧,谷歌积极预警:** 谷歌近期向其庞大的Gmail用户群体发出警告,强调了在近期大规模数据泄露事件后,加强个人账户安全的重要性。网络钓鱼活动日益猖獗,黑客正利用各种手段(如冒充IT人员、发送虚假安全警报)诱骗用户泄露登录凭证,以窃取数据和进行敲诈勒索。

🎣 **黑客组织活动频繁,手段多样化:** 文章点名了“ShinyHunters”等黑客组织,这些组织通过建立数据泄露网站(DLS)来增加对用户的勒索压力。此外,其他威胁组织如UNC6040和UNC6395也通过语音网络钓鱼等技术,冒充IT支持人员,窃取敏感信息,并进行经济勒索。这些攻击活动表明了网络威胁的复杂性和持续性。

🔒 **用户应采取关键安全措施:** 为有效防范未来可能发生的网络钓鱼攻击,谷歌强烈建议用户立即采取行动。首要措施是启用“两步验证”(2-Step Verification),为账户增加一层额外的安全保障。其次,定期更新和使用强密码至关重要。最后,用户不应轻信邮件中的安全警报,而应主动登录自己的Google账户,前往“安全”设置中的“近期安全活动”页面,自行核查任何可疑的登录尝试或安全事件。

To users that haven't already locked down your personal accounts in light of massive data breaches: It's never too late.

That's why Google is once again urging its Gmail subscribers to protect their accounts, following a series of data attacks on corporate systems that could eventually threaten users' personal security. Google sent notifications to its 2.5 billion Gmail users in late July and then again on Aug. 8, warning them that hackers were ramping up phishing activity intended to fool users into giving up their log-in credentials.

Google specifically referred to a group known as "ShinyHunters," which the company says has launched a data leak site (DLS) in an effort to escalate extortion pressure levied at users. Google notes the extortion emails include "shinycorp@tuta. com" and "shinygroup@tuta. com" domains.

In May, cybersecurity researcher Jeremiah Fowler reported that some 184 million passwords were potentially exposed in an open database, with many of the passwords tied to email providers like Google and social media platforms. One month later, Google Threat Intelligence Group (GTIG) reported that one of its corporate Salesforce server clusters (known as instances) was breached and exposed publicly available business information, such as business names and contact details, Google explained. The breach was continued activity from an online threat group known as UNC6040, which uses voice phishing to impersonate IT agents, steal data, and extort money. This week, GTIG issued another advisory to Salesforce clients about a large data breach by hacker group "UNC6395."

To prevent users getting bested by future phishing attempts, Google has encouraged its users to set up two-factor authentication and update their passwords. The company has also warned users never to click on emails with alerts such as "suspicious sign in prevented," which are commonly used by hackers during periods of increased cybersecurity warnings. Instead, users should check security alerts on their own — more on how to do that below.

How to check your Google security activity

Total Time
    3 min.
What You Need
    Google account access desktop or mobile app.

Step 1: Log into your Google account.

Go to myaccount.google.com

Step 2: Navigate to "Security".

For desktop users, find this on the left side of the screen next to the padlock icon.

Step 3: Go to "Recent security activity".

Any security alerts in the last 28 days, including new sign-ins, should be visible here. Users can click for more information.

How to change your Gmail password

Total Time
    3 min
What You Need
    Google account access desktop or mobile app

Step 1: Log into your Google account.

Step 2: Navigate to "Security."

Step 3: Scroll to the “How you sign in to Google” section.

Step 4: Click "Password".

Users can also see the last time they changed their password.

Step 5: Log in using your current password one more time.

How to set up 2-Step verification for Google

Total Time
    5 min
What You Need
    Google account access desktop or mobile app

Step 1: Log in to your Google account.

Step 2: Navigate to "Security."

Step 3: Scroll to “How you sign in to Google”.

Step 4: Click "Turn on 2-Step Verification".

Step 5: Follow the steps on-screen.

In order to enable multi factor authentication, users will need to use an on-device passkey, the Google authenticator app (or other third-party authenticator), link a personal phone number, or set up a backup code.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Google Gmail 账户安全 网络钓鱼 两步验证 Google Security Phishing Account Security Two-Step Verification
相关文章