Google Study Finds Phishing a Bigger Threat for Users Than Third-Party Data Breaches

Advertisement
By Indo-Asian News Service | Updated: 13 November 2017 12:54 IST

Phishing attacks via fake emails pose the greatest threat to people, followed by keyloggers and third-party breaches as account hacking increases globally, a new Google study has revealed.

Keystroke logging is a type of surveillance software that once installed on a system, has the capability to record every keystroke made on that system. The recording is saved in an encrypted log file.

Advertisement

According to Google, enterprising hijackers are constantly searching for, and are able to find, billions of different platforms' usernames and passwords on black markets.

A Google team, along with the University of California, Berkeley, tracked several black markets that traded third-party password breaches as well as 25,000 blackhat tools used for phishing and keylogging.

Advertisement

"In total, these sources helped us identify 788,000 credentials stolen via keyloggers, 12 million credentials stolen via phishing, and 3.3 billion credentials exposed by third-party breaches," Google said in a blog post late on Friday.

Account takeover, or 'hijacking', is a common problem for users across the web. More than 15 per cent of Internet users have reported experiencing the takeover of an email or social networking account.

Advertisement

"From March 2016 to March 2017, we analysed several black markets to see how hijackers steal passwords and other sensitive data," said Kurt Thomas from Anti-Abuse Research and Angelika Moscicki from Account Security teams at Google.

The tech giant then applied the insights to its existing protections and secured 67 million Google accounts before they were abused.

Advertisement

"While our study focused on Google, these password stealing tactics pose a risk to all account-based online services. In the case of third-party data breaches, 12 percent of the exposed records included a Gmail address serving as a username and a password," the blog post read.

Of those passwords, 7 percent were valid due to reuse. When it comes to phishing and keyloggers, attackers frequently target Google accounts to varying success: 12-25 percent of attacks yield a valid password.

However, because a password alone is rarely sufficient for gaining access to a Google account, increasingly sophisticated attackers also try to collect sensitive data that we may request when verifying an account holder's identity.

"We found 82 percent of blackhat phishing tools and 74 percent of keyloggers attempted to collect a user's IP address and location, while another 18 percent of tools collected phone numbers and device make and model," Google noted.

"While we have already applied these insights to our existing protections, our findings are yet another reminder that we must continuously evolve our defences in order to stay ahead of these bad actors and keep users safe," it added.

There are some simple steps people can take that make these defences even stronger.

"Visit Google's Security Checkup to make sure you have recovery information associated with your account, like a phone number, and allow Chrome to automatically generate passwords for your accounts and save them via Smart Lock," Google cautioned.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Google, Phishing, Internet, Phishing Attack
Advertisement

Related Stories

Popular Mobile Brands
  1. Here's When the Redmi 15A 5G Will Be Launched in India
  2. OnePlus 15T Camera Features Teased Ahead of March 24 Launch
  3. Samsung Will Launch New Galaxy A-Series Smartphones in India on This Date
  4. Oppo K14 5G With 7,000mAh Battery Goes on Sale in India: See Price, Offers
  5. Nothing Phone 4a Pro Review: A Big Leap
  6. Xiaomi Book Pro 14 Debuts With a 72Wh Battery at This Price
  7. Samsung Galaxy Forever Offers Easy Upgrade, Return Option in India
  8. Have a Large Following on TikTok, YouTube or Instagram? Facebook Will Pay You
  9. OnePlus Nord 6 Specifications Surface as Tipster Leaks Photo of Retail Box
  10. Oppo Find X9 Ultra, Find X9s Reportedly Listed on SIRIM Website, Could Launch Soon
  1. Huawei MatePad 11.5, MatePad SE 11 Full Specifications List Revealed via Flipkart Listings
  2. Boat Valour Watch 1R Launched in India With 1.43-Inch AMOLED Display, Up to 10-Day Battery Life: Price, Features
  3. Xiaomi SU7 EV Refreshed With 902km CLTC Range, Nvidia Thor AGX-Powered Assisted Driving Features
  4. Samsung Sets March 25 Launch Date for New Galaxy A-Series in India; Galaxy A37, Galaxy A57 Design Tipped Again
  5. Anthropic Study Finds People Don’t Really Want AI for Creative Work
  6. Bitcoin Trades Near $71,000 as Crypto Market Weathers Ongoing Macroeconomic Pressures
  7. Redmi 15A 5G India Launch Date Announced; Design and Specifications Teased
  8. World Happiness Report 2026: Heavy Social Media Use Linked to Lower Life Satisfaction Among Teenagers
  9. Oppo K14 5G With 7,000mAh Battery, 50-Megapixel Camera Goes on Sale in India: Price, Offers
  10. Oppo Find X9 Ultra, Find X9s Appearance on SIRIM Certification Database Signals Imminent Launch
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.