谷歌“调查”Gmail黑客事件,导致用户被锁定且无法恢复。
Google 'Looking into' Gmail Hack Locking Users Out with No Recovery

原始链接: https://www.forbes.com/sites/daveywinder/2025/12/05/google-looking-into-gmail-hack-locking-users-out-with-no-recovery/

一种新的Gmail黑客攻击正在将用户锁定在账户之外,似乎无法恢复。黑客正在利用谷歌的Family Link功能,将受害者的账户年龄更改为18岁以下,并将其添加到一个他们控制的家庭群组中的“儿童”账户。这有效地将控制权交给了攻击者,绕过了标准的恢复选项。 受害者报告说无法重新获得访问权限,甚至有人面临为了释放账户而支付赎金的要求。虽然谷歌承认这是一个“已知的账户被攻破后的行为”,但它仍然相对罕见——尽管现在这种策略已经公开,可能会增加。 谷歌建议用户启用双重验证(以及理想情况下,密码密钥),定期检查已连接的设备和恢复信息,并利用恢复联系人功能。核心预防措施仍然是强大的账户安全,以避免最初的入侵。谷歌承诺很快提供更具体的指导,但现在采取主动的安全措施至关重要。

黑客新闻 新 | 过去 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 Google “正在调查”Gmail黑客事件,导致用户无法恢复账户 (forbes.com/sites/daveywinder) 24点 由 lawlessone 1小时前 | 隐藏 | 过去 | 收藏 | 1条评论 dtdynasty 32分钟前 [–] 作为在这个领域工作的人,像Google这样的大型组织通常会将功能开发团队和反滥用团队分开。组织结构导致了意想不到的功能后果。当你在努力为人们提供价值时,却被不法分子利用,这很糟糕。回复 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请YC | 联系 搜索:
相关文章

原文

I write a lot about Google security, and that which involves the most popular free email platform on the planet, with 2 billion active users, Gmail, in particular. Sure, much of this will focus on the latest vulnerability alerts, and threat campaigns, as well as the occasional compromised Gmail passwords warning. I will always include advice as to how to mitigate the risk of any attack, much of which comes from Google itself. When I hear from readers that they are being locked out of their Gmail account by hackers and are unable to get back in, no matter what, that’s a concern. When Google informs me that it is “looking into it” and will issue specific guidance “in the near future,” that’s even more so. Here’s what you need to know about the Gmail hack attack that prevents you from regaining access to your account, and how to best protect yourself from becoming yet another victim.

ForbesHas Your Gmail Password Been Hacked? Check Now, Here’s How

Hackers Lock Down Compromised Gmail Accounts Using Parent And Child Protections

As regular readers will likely already know, I entered the world of cybersecurity as a hacker in the 1980s. Hacking is not a crime, quite literally so back then, as there were no laws that specifically applied to the act of unauthorised network intrusion. Criminal hacking is quite another thing altogether. So, when I read about a Gmail user who had not only been compromised but found themselves locked out of their account with seemingly no chance of recovery, my hacker brain started to engage. How could this be, I wondered, given that there are so many ways to get account control back, even if an attacker has changed your password post-compromise. And then the chicken clucked, the bell rang, and the penny dropped: this was a very clever bit of hackery involving the use of a feature meant to protect accounts, not hold them hostage.

A Google user posted a plea for help to the Gmail subreddit that explained how an attacker had changed his age to 10 on his account profile and then added it to a family account under the attacker’s control. Ten years old being younger than the account had actually existed for, it is 12 years old apparently, might, you would have hoped, set off some Google alarm bells in these days of advanced AI protections, but no. By adding the compromised account to a family account and making it a child one, the actual owner found themselves totally locked out and unable to use any of the myriad recovery options provided by Google. The icing on this particularly smelly cake was that the attacker then demanded the victim send a bunch of gift cards to get the account released. “TL;DR: Account accessed, placed as a child in a Google family, and locked out,” the victim concluded, “please help.”

As the thread developed, others confirmed that the use of a child account is becoming a common tactic among hackers, and recovering from it appears impossible. “You would think that changing people’s date of birth on their accounts should require a forced re-auth and not be doable without providing all authentication factors,” one wrote, quite sensibly.

ForbesCritical Password Warning As Dangerous ‘Wrench Attacks’ Continue

Google Is Looking Into Gmail Account Post-Compromise Threat

Perhaps the most astute comment in the subreddit thread was someone suggesting that Google had probably not anticipated such a situation. This does seem likely, although it’s a very unfortunate error if so. I reached out to Google to ask for advice for the victims of this hack attack lockout issue, and a spokesperson told me that the security team was looking into it as a “a known post-compromise action some hijackers take.” Google stressed, however, that it is also a fairly uncommon one. I suspect, however, now that the tactic is becoming known in online forums, that more attackers will deploy it. “Look for more detail and specific guidance from us on this in the near future,” the Google spokesperson said, sharing the following core guidance for stopping account takeovers in the meantime:

  • Turn on two-step verification and adopt passkeys.
  • Double-check that only current/available phones or numbers are associated with accounts, and regularly review what devices are associated with them.
  • Set up recovery information, like a recovery email or phone number, or use the recently announced recovery contacts feature.

Remember, the best way to prevent an attacker from locking you out of your Gmail account in this way is to prevent them from compromising it in the first place. You know it makes sense, so get that Google passkey set up now.

ForbesGoogle Chrome Security Alert: 3 Billion Users Must Update Now
联系我们 contact @ memedata.com