Phishing Helps Hackers Hijack Google Accounts

Password listImage copyright designer491
Image caption Many people still use passwords that are very easy to guess

Cyber-thieves grab almost 250,000 valid log-in names and passwords for Google accounts every week, suggests research.

The study by Google and UC Berkeley looked at the ways email and other accounts get hijacked.

It used 12 months of log-in and account data found on websites and criminal forums or which had been harvested by hacking tools.

Google said the research helped secure accounts by showing how people fell victim to scammers and hackers.

During the 12 months studying the underground markets, the researchers identified more than 788,000 credentials stolen via keyloggers, 12 million grabbed via phishing and 1.9 billion from breaches at other companies.

Phishing involves attempts to trick people into handing over personal information and keyloggers are programs that record every key someone presses when using a computer.

Physical location

The most useful information for cyber-thieves came from keyloggers and phishing attacks as these included valid passwords in 12%-25% of attacks, it found.

Phishing attacks posed the biggest risk to users as these helped malicious hackers scoop up about 234,000 valid names and passwords every week. By contrast, keyloggers only yielded about 15,000 valid credentials each week.

Cyber-attackers also sought to grab other information that could be useful in attacks, said the researchers.

Data about a person's internet address (IP) as well as the device they were using and their physical location were all potentially useful for attackers seeking to defeat security checks.

Popular passwords found in data breaches

  • 123456
  • password
  • 123456789
  • abc123
  • password1
  • 111111
  • qwerty
  • 12345678
  • 1234567

Gathering this data was much harder, found the research, with only 3.8% of people who had credentials leaked also giving away IP addresses and fewer than 0.001% surrendering detailed device information.

In a blog, Google said it would use the results of the research to refine the ways it spotted and blocked attempts to take over accounts. In particular it would enhance efforts to use historical data about where users logged in and the devices they used to thwart impersonation attacks.

However, the researchers acknowledged that the "multi-pronged problem" of account hijacking required efforts in lots of different areas.

It noted that only 3.1% of people who had an account hijacked subsequently started using improved security measures, such as two-factor authentication, after they regained control of a lost account.

Because of this, they said, educating users about better ways to protect accounts should become a "major initiative".

RECENT NEWS

From Chip War To Cloud War: The Next Frontier In Global Tech Competition

The global chip war, characterized by intense competition among nations and corporations for supremacy in semiconductor ... Read more

The High Stakes Of Tech Regulation: Security Risks And Market Dynamics

The influence of tech giants in the global economy continues to grow, raising crucial questions about how to balance sec... Read more

The Tyranny Of Instagram Interiors: Why It's Time To Break Free From Algorithm-Driven Aesthetics

Instagram has become a dominant force in shaping interior design trends, offering a seemingly endless stream of inspirat... Read more

The Data Crunch In AI: Strategies For Sustainability

Exploring solutions to the imminent exhaustion of internet data for AI training.As the artificial intelligence (AI) indu... Read more

Google Abandons Four-Year Effort To Remove Cookies From Chrome Browser

After four years of dedicated effort, Google has decided to abandon its plan to remove third-party cookies from its Chro... Read more

LinkedIn Embraces AI And Gamification To Drive User Engagement And Revenue

In an effort to tackle slowing revenue growth and enhance user engagement, LinkedIn is turning to artificial intelligenc... Read more