Skip to main content

China blamed for Gmail attack, top US officials targeted

google-china-logo-gmailGoogle said on Wednesday that hackers believed to be based in Shandong province in China have attempted to trick hundreds of Gmail users into giving away their passwords, including those belonging to US government officials, Chinese political activists, officials in several Asian countries, military personnel and journalists.

In a post on the company’s blog, Eric Grosse, a member of the Google security team, said that the passwords had been obtained “likely through phishing,” with the probable aim being to monitor e-mail content. Forwarding and delegation settings would likely have been changed too, he said.

The company pointed out that it had “detected and disrupted” the security breach and contacted victims, securing their accounts in the process. The relevant government authorities have also been informed, Grosse said. A Reuters report quoted White House spokesman Tommy Vietor saying that he had no evidence suggesting that any government email accounts had been accessed. The report also stated that the FBI were currently reviewing the matter.

Google was keen point out that its internal systems had not been affected by the attack. “These account hijackings were not the result of a security problem with Gmail itself,” Grosse said. “But we believe that being open about these security issues helps users better protect their information online.”

The blog post suggests some ways users of Google’s products can improve their security, including 2-step verification, which uses a phone and second password on sign-in. This method, said the company, protected some users from this latest attack.

It’s not the first time Google believes it has been targeted by hackers based in China. In March, the company claimed that the Chinese government had hacked its Gmail service in an attempt to quell social unrest in the country, and in December last year cables released by Wikileaks appeared to show that another attack on Google had been approved by senior Chinese officials.

Editors' Recommendations

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Europe just suffered its worst DDoS attack ever, but we don’t know why
A depiction of a hacker breaking into a system via the use of code.

A record-breaking distributed denial-of-service (DDoS) attack situated within Europe was attempted during July, a new report has confirmed, but the lack of details on the target leaves the motive undetermined.

The largest DDoS attack ever detected in European-based regions was revealed by cybersecurity and cloud service firm Akamai, who said the target was one of its own customers.

Read more
Hackers targeted AMD to steal huge 450GB of top-secret data
A depiction of a hacker breaking into a system via the use of code.

A data extortion group known as RansomHouse has asserted that it has stolen upwards of 450GB of sensitive data from AMD.

Team Red has since confirmed that it launched an investigation into the matter after the situation came to light.

Read more
Experts found a record number of zero-day hacks in 2021
A digital depiction of a laptop being hacked by a hacker.

Google has published the 2021 review of Project Zero, revealing a record amount of zero-days exploits (labeled as “one of the most advanced attack methods”) exhibited by some of the world’s largest technology companies.

Project Zero is an initiative started by Google in 2014 aimed at detailing security defects known as zero-day exploits. These vulnerabilities are dangerous as they essentially remain undetected unless a mitigation system has been implemented, thus leaving systems, databases, and the like completely exposed to hackers.

Read more