Tag: gmail

  • 2.5 Billion Gmail users at risk after database leak exposes pertinent account information

    2.5 Billion Gmail users at risk after database leak exposes pertinent account information

    It was recently revealed that Google’s Salesforce database was breached, exposing data for over 2.5 billion users at the time of reporting.

    Initially it was being reported that the leak would primarily effect only their business users as the data found in Salesforce mostly pertains to those accounts. However that was quickly dispelled as Gmail users reported increased attacks against their accounts, with some users reporting they even received a call from alleged Google employees notifying them of the breach of their account.

    We want to make it clear that no password data was leaked in this data breach (at least at the time of writing) instead the data is being used to increase the effectiveness of phishing attacks leveled at Gmail users. One example of the attacks that are occurring includes users being told to initiate an account reset wherein the bad actor intercepts the password and locks the original user out.

    Another attack being initiated is what Google calls “dangling bucket takeover” where the attacker essentially has access to a link connected to the users Google storage and uses it to hijack their account. Google outlines the four ways you can protect against this kind of attack in the page linked.

    While company based accounts might be the most prime targets – and this goes for phishing in general – that doesn’t mean individual users are safe. Spear phishing, a popular variant of phishing that involves researching and gaining access to user accounts outside of their prime target such as an employees close to the company lead, could be a motivator for the current rise in attacks related to this breach. They would then use those accounts to increase the legitimacy of phishing attempts leveled at the primary target (by sending messages as the compromised user).

    It is paramount in 2025 that users practice good safety hygiene when it comes to their online data, especially in an age where the onslaught of data breach news can feel overwhelming and increase a sense of helplessness. Even though data breaches are not rare, users can still protect themselves in the following ways:

    1. Enable Two-Factor Authentication (2FA)
    • Turn on Google 2-Step Verification.
    • Use an authenticator app (Google Authenticator, Authy, or similar) instead of SMS, since text messages can be intercepted.
    • For even stronger protection, consider a hardware security key (e.g., YubiKey).
    1. Use a Strong, Unique Password
    • Avoid reusing passwords across multiple sites.
    • Use a password manager (Bitwarden, 1Password, LastPass, etc.) to generate and store long, random passwords.
    • Change your password immediately if you suspect any compromise.
    1. Regularly Review Account Activity
    • Check Gmail’s “Last account activity” (bottom right of inbox) for unusual logins.
    • Review the Google Account Security page to see devices that have accessed your account.
    • Remove old or unused devices and apps with account access.
    1. Be Proactive Against Phishing
    • Always verify the sender’s address before clicking links.
    • Hover over links to confirm they point to legitimate Google domains.
    • Turn on Gmail’s Enhanced Safe Browsing in account security settings for extra phishing protection.

    Email remains the number one entry point for cyberattacks, from phishing scams to ransomware. At Valley Techlogic, we take a proactive approach to keeping your inbox safe. Our team helps businesses implement advanced spam filtering, real-time threat detection, and encryption to safeguard sensitive communications.

    Beyond just tools, we provide continuous monitoring, security awareness training, and rapid response in the event of a breach. With Valley Techlogic as your partner, you can rest easy knowing your organization’s most critical communication channel is protected. Learn more today with a consultation.

    Looking for more to read? We suggest these other articles from our site.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic and LinkedIn at https://www.linkedin.com/company/valley-techlogic-inc/.

  • 5 Tips for Conquering Email Spam (and Phishing) in 2022

    We’ve posted on how to spot a phishing email before on this website, but what about just thwarting the attempt before it even reaches your inbox?

    Email filtering is a complex topic, too strict and you miss important emails. Too lax, your inbox is flooded with spam and attempts to scam you. At Valley Techlogic, we feel like we have a good regimen for helping our clients get the emails they need and not the ones they don’t.

    On top of that, email phishing is STILL the biggest security threat to your business. In 2021, 83% of businesses experienced phishing attack attempts and 15 billion spam emails occur every day.

    That’s a lot of attempts to circumvent the security features you have in place within your business, or if you don’t have protections in place (especially highly effective ones like multi-factor authentication) then your business may be a sitting duck. All it takes is one employee clicking on the wrong attachment and you have a major security headache on your hands.

    So, to foil those attempts, here are 5 tips for conquering email spam and preventing phishing attempts at the same time:

    1. Mark spam as spam. One of the easiest ways to see less spam in your inbox is to mark spam as spam, email filters learn from you what you’re looking to see in your inbox. While the most egregious spam will still be filtered out by your email provider for the most part, for sophisticated spam attempts your assistance helps. This also blocks the sender from sending future attempts.
    2. Learn the telltale signs. There 5 easy telltale signs an email is spam or phishing. They are: an unrecognizable sender, requesting personal information, an email that doesn’t match the purported sender, it asks you to take immediate action and/or there are a lot of typos.
    3. Enable more advanced privacy settings. Many email providers have privacy and security settings to provide more advanced protection. See our guide below for enabling these settings for Gmail and Outlook.
    4. For businesses, don’t go with the obvious choice for email. Many of us use just our first name or our first name and a last initial when creating our work emails, while this helps make our emails more memorable and easier to recite, it also opens us up to spam. If you have a spam problem, it might be best to switch things up in this area.
    5. Unsubscribe from mailing lists, especially the ones you didn’t sign up for. Another good way to combat spam in particular is to unsubscribe from mailing lists, there are rules and regulations that say vendors must respect this request or they’re potentially violating their emailing providers terms and conditions.
      Email Security Guide for Gmail and Outlook
      Click to view the full size version.

      Another way to combat spam and phishing emails is through a tool. There are tools that can be built into your browser or email client, many of them use the SLAM method. With this method they check the sender, the links, the attachments, and the message itself to look for telltale signs it’s a spam or phishing email.

    At Valley Techlogic we provide security awareness training – which is another excellent tool for preventing cyberattacks – and an extension for Outlook that includes the training and spam/phishing testing tool right in your inbox to all of our clients.

    We can also offer simulated phishing attempts so you will know if anyone in your organization could use additional training on the topic. Schedule a consultation today to learn more about how we can help you with your business’s email related goals.

    Looking for more to read? We suggest these other articles from our site.

    This article was powered by Valley Techlogic, an IT service provider in Atwater, CA. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on Twitter at https://x.com/valleytechlogic.