It has been reported that high profile Gmail users – including US government officials, reporters and political activists – have had their email accounts hacked. IT security and control product firm Sophos is warning users that this wasn’t a sophisticated attack against Google’s systems, but rather a cleverly-crafted HTML email which pointed to a Gmail phishing page.
Victims believed that they had been sent an attachment, clicked on the link, and were greeted by what appeared to be Gmail’s login screen. If recipients filled in their details, their Gmail username and password were automatically handed over to unauthorised parties. Graham Cluley, senior technology consultant at Sophos, has provided five steps, advising Gmail users on how to protect themselves to reduce the chances of their account being hacked.<br><br>1. Set up two step verification – this provides an extra layer of security by sending a verification code to the users’ mobile when they login<br>2. Check if your Gmail messages are being forwarded without your permission – users should check their "Forwarding and POP/IMAP" settings to ensure that emails aren’t being forwarded to an unknown account without their authorisation<br>3. Verify where your Gmail account is being accessed from – check is someone has been accessing your account at unusual times of day or from an unusual location<br>4. Choose a unique, hard-to-crack password – avoid using the same password for multiple sites and do not use a dictionary word<br>5. Secure your computer with up-to-date anti-virus software and security patches<br><br>"These five steps are really easy and they apply to all users of cloud hosted email accounts in order to improve the security of their data online," said Cluley. "However one thing that people should be asking themselves, is why are they storing sensitive information in cloud based accounts in the first place? The recent news headlines claim that senior US political and military officials were being targeted by these hackers, but surely they shouldn’t be storing confidential or sensitive information in their webmail account. Users should always think about the data that they are storing in their web email, because if it’s only protected by a username and password, it may actually be less secure than your regular work email system provides."<br><br>Further information and advice about how to best protect Gmail accounts can be found in Cluley’s article here:<br><br>http://nakedsecurity.sophos.com/2011/06/02/how-to-stop-your-gmail-account-being-hacked
Meanwhile Jon Geater, Director of Technical Strategy at Thales e-Security, has written his latest blog post on the cyber attacks against gmail accounts. From Thales e-Securityโs blog: www.keymanagementinsights.com
Another day, another cyber security headline. This time itโs the attack on personal gmail accounts which has left hundreds of US government and military personnel (along with other high-value targets) potentially exposed…
Thereโs not a lot to say about this that I didnโt say in my Advanced Persistent Threat post (and related articles) except to note that widespread reporting of this issue has been refreshingly plain and understanding. I fully expected to see tales of cyber war, Google-bashing and condemnation of Cloud Security arising from this but instead it seems people (by which I mean mainstream media) are starting to get the idea about things like Spear Phishing, and understand this attack for what it was.
Insidious, yes. Worrying, certainly. Important too but the point is this specific attack is not where the damage is being done: that comes later when the information harvested is exploited. That people are beginning to understand these subtleties of online security is truly a good thing.
Now all we need to do is fix the systems that make these attacks so easy on all but the most wary of prey. So thatโs just DNS, HTTP, web browsers, HTML emailโฆ Hmm. I wonder if this will get a special mention at this weekโs Cyber Security Summit.




