The news of the spear phishing attack on GMail users has highlighted a number of interesting points around GMail and its security. The attack, believed to have originated from Jinan, China, specifically targeted users with an email that included a malware link prompting them to enter their GMail log-in details again. This information was then used to access and monitor their GMail accounts illegally.
This breach has not come about through any vulnerabilities in Google’s security systems. As with all phishing tactics, this attack could be applied to any email service as it is the user that discloses the valuable information and not the technology.
The most interesting thing about this attack, however, is that Google was aware of it very early on, which meant the number of users affected was limited.
Google has excellent intrusion detection systems that monitor and flag any unusual behaviour in its GMail accounts. For example if a UK GMail user had responded to the recent phishing e-mail and then their account was accessed from a Chinese IP address, Google will automatically alert this unusual activity to the account user. The user is also given the ability to close any remote sessions.
Google added two-factor authentication for corporate users of Google Apps for Business in 2010 and has now released this for all GMail users. This enhanced verification requires two independent factors for authentication, much like you might see on your banking website: your password, plus a code obtained using a smartphone app or via a one-time text sent to a registered mobile. This protects GMail accounts from exposure even if the user did inadvertently disclose their login credentials.
Security is an area Google invests a lot of research into, particularly focusing on building access controls into its applications from the start. The incident has highlighted the level and success of Google’s security procedures and their understanding of online applications.
Monday, 06 June 2011 10:36
The phishing attack on GMail users highlights Google's excellent security procedures
Blog Archive
Ancoris blog covering all our latest views and news about our company, cloud computing and enterprise security.
- Will Google Drive be a Dropbox killer? Written on Tuesday, 15 May 2012 10:35
- Ancoris enters the Post-PC era, switches to Google Chromebooks with full legacy application access Written on Thursday, 26 April 2012 08:21
- Ancoris Strengthens its Cloud and Remote Access Offerings with Ericom’s Access Solutions Written on Friday, 30 March 2012 10:40
- European Union provides welcome backing for cloud computing Written on Monday, 27 February 2012 10:14
- Ancoris Named G-Cloud Supplier Written on Monday, 20 February 2012 14:14
- Ancoris becomes one of the first Google Apps Premier Enterprise Resellers Written on Tuesday, 14 February 2012 16:46
- Enterprise maturity of Google Apps for Business confirmed by deal with BBVA Written on Tuesday, 17 January 2012 14:09
- 2012 Predictions: The government’s push into cloud computing will reduce security fears Written on Tuesday, 10 January 2012 10:49
- 2012 Predictions: Social and collaborative computing will begin to come of age in the business world Written on Thursday, 05 January 2012 22:06
- 2012 Predictions: Increased user mobility will drive virtualisation of legacy applications Written on Monday, 19 December 2011 13:06
- 2012 Predictions: Bring Your Own Device strategies will go mainstream Written on Monday, 12 December 2011 22:39
- Ancoris selected for Google’s Chromebook Reseller Pilot Program Written on Thursday, 08 December 2011 09:49
- 2012 Predictions: “Private clouds” will be exposed as old-fashioned hosting masquerading under a new name Written on Monday, 05 December 2011 17:21
- Ancoris awarded CRN Specialist Reseller of the Year 2011 Written on Monday, 21 November 2011 16:01
- Top reason # 5 for choosing Google Apps: A platform built for the future Written on Monday, 07 November 2011 15:01
- Top reason # 4 for choosing Google Apps: Enhanced communications are made affordable Written on Monday, 31 October 2011 16:08
- Top reason # 3 for choosing Google Apps: Pure cloud architecture offers superior data protection Written on Monday, 17 October 2011 11:08
- Top reason # 2 for choosing Google Apps: Users are productive from anywhere Written on Monday, 10 October 2011 09:15
- Ancoris Top 5 reasons to choose Google Apps over Office 365: Improved collaboration leads to business innovation Written on Monday, 03 October 2011 12:44
- Gartner hails Gmail as credible alternative to Microsoft Exchange Written on Tuesday, 27 September 2011 10:13
- Microsoft finally boards cloud computing train but fails to impress users Written on Thursday, 08 September 2011 13:19
- How to use cloud computing to simplify business continuity plans Written on Monday, 22 August 2011 10:11
- New Look for Google & Google Apps Written on Wednesday, 27 July 2011 10:05
- Is Cloud Computing a solution to the problem of project overruns? Written on Thursday, 21 July 2011 15:33
- Cloud Computing gives a new meaning to "local" Written on Thursday, 07 July 2011 11:47
- Are old-fashioned hosted solutions preventing business from reaping the benefits of cloud computing? Written on Wednesday, 22 June 2011 15:21
- Retailers using Google Apps for Business find innovation is the 'killer app’ Written on Wednesday, 15 June 2011 16:18
- The phishing attack on GMail users highlights Google's excellent security procedures Written on Monday, 06 June 2011 10:36
- Google Partners provide the personal touch Written on Tuesday, 31 May 2011 08:57
- Google Chrome OS Laptops announced for UK availability in June Written on Wednesday, 11 May 2011 20:54
Case Studies: Messaging and Collaboration
- Google Apps helps LINE Communications improve collaboration
- Ancoris helps Edward Elgar Publishing migrate to reliable, accessible email with Google Apps
- Specsavers goes to Google Apps with Ancoris
- Gill’s Cruise Centre “Goes Google” with Ancoris
- Google Apps helps creativity and collaboration flourish at Imagination
- Symbian saves 75% of on-going IT costs through adoption of Cloud
- Law firm delivers better service to clients using Google Sites
- Moran & Bewley’s Hotels chooses Google Apps & Ancoris for cost-effective email
Case Studies: Email and Web Security
- Ancoris simplifies email security for Baxi Group with Google Message Security
- Ancoris to deliver Cisco ScanSafe Web Security Service to 14,000 Reckitt Benckiser staff worldwide
- Google Postini Services reduce IT overhead at VSO
- Chester Zoo adopts Google Message Security
- Ancoris helps Speedy Hire secure Internet use with Cisco ScanSafe
Ancoris Cloud Briefing
Wednesday 27th June 2012
@ Google, Central St Giles, London
"Work in the Future" is an executive briefing that will discuss the value of cloud services from an operational and financial perspective.
Agenda and registration
Whitepaper
5 Reasons to Choose Google Apps for Business over Office 365
Download Whitepaper

