Big Data. Big Decisions
InformationWeek
Special Coverage Series


Google: We've Stopped Most Gmail Account Hijacking

Google cites 99.7% decrease in Gmail account hijackings since 2011 peak, thanks to risk analysis defenses.

Google this week announced that since putting a system in place to check 120 different variables related to online sign-ins, it's reduced the incidence of Gmail account hijackings by 99.7% since they peaked in 2011.

That's welcome news for anyone who's experienced first-hand the joys of having a friend or acquaintance get their webmail account hijacked. Cue "urgent" appeals and fake sob stories about getting mugged in London just hours before being scheduled to return home. "Kindly help me send the money via Western Union Money Transfer to my name and hotel address below," read one widely distributed scam email.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

More recently, scammers used compromised webmail accounts to send emails with a bit.ly link that led to a fake -- but real-looking -- careers page at "careers.nbcnews.com-iw9.net" that interwove content stolen from NBC with plugs for work-at-home operations and "home cash success." More often than not, such scams are just fronts for money mule operations.

[ Do you know the warning signs that your identity has been stolen? See Identity Fraud Hits 3-Year High; Costs $21 Billion. ]

According to Google, the principal account-hijacking technique involves attackers using usernames and passwords stolen from other sites -- which may have been purchased on cybercrime forums -- then testing to see if they've been reused for Webmail accounts, thus allowing the grifters to go to work.

"We've seen a single attacker using stolen passwords to attempt to break into a million different Google accounts every single day, for weeks at a time," said Google security engineer Mike Hearn in a blog post. "A different gang attempted sign-ins at a rate of more than 100 accounts per second."

Most account takeovers are made by scammers seeking to reliably distribute greater amounts of spam. "Although spam filters have become very powerful -- in Gmail, less than 1% of spam emails make it into an inbox -- these unwanted messages are much more likely to make it through if they come from someone you've been in contact with before," Hearn said. "As a result, in 2010 spammers started changing their tactics -- and we saw a large increase in fraudulent mail sent from Google Accounts."

But scammers aren't the only people intent on hijacking webmail accounts. In 2011, notably, Google warned that hundreds Gmail users -- including senior U.S. government officials and Chinese activists -- had been targeted in account-takeover attacks. In 2012, Google added a warning system to Gmail accounts that announces when a user's account appears to be the target of a state-sponsored account takeover attempt.

Google said its risk assessment system now successfully blocks most of these types of account takeovers. "Every time you sign in to Google, whether via your Web browser once a month or an email program that checks for new mail every five minutes, our system performs a complex risk analysis to determine how likely it is that the sign-in really comes from you," said Hearn, noting that 120 different variables get assessed.

"If a sign-in is deemed suspicious or risky for some reason -- maybe it's coming from a country oceans away from your last sign-in -- we ask some simple questions about your account," he said. "For example, we may ask for the phone number associated with your account, or for the answer to your security question. These questions are normally hard for a hijacker to solve, but are easy for the real owner."

This type of adaptive authentication -- asking more questions whenever something looks suspicious -- isn't unique to Google, and is already available off-the-shelf from other security companies, such as RSA, which said its related software is now widely used by financial services firms.

While the risk analysis tools being employed by Google have helped stem account takeovers, to block even more such hacks, Hearn recommended that users enable two-factor authentication for Gmail, create strong passwords and ensure that their account recovery settings include a backup email address and a phone number.



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.