logo

Gmail’s multi-factor authentication bypassed by hackers to pull off targeted attacks

ID: fb4e8310-9466-5d07-9e8c-349c8fd1b64b

STIX ID: report--fb4e8310-9466-5d07-9e8c-349c8fd1b64b

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2025-06-23

Date Updated: 2026-04-28

...
...

Russian-linked attackers conducted a months-long, targeted social-engineering campaign against prominent academics and critics of Russia by impersonating U.S. State Department officials and convincing victims to create and share Google app-specific passwords. By abusing app passwords—which bypass the second MFA step—the adversary obtained full access to victims' Gmail accounts; researchers suspect a state-sponsored actor due to the campaign's sophistication and targeting. The report warns that this technique makes MFA effectively bypassable in these scenarios and provides defensive guidance to avoid using app passwords when possible and to adopt stronger authentication methods.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.