Google tells Iranian users to check if their Gmail accounts have been hacked

Filed Under: Data loss, Google, Privacy

Iranian flagGoogle is advising *all* its users in Iran to change their Gmail passwords, and check that their Google accounts have not been compromised.

In a blog post, Google said that it was directly contacting users in Iran who may have been hit by a man-in-the-middle attack.

As you've no doubt been reading on Naked Security, the threat emerged after disgraced Dutch SSL certificate authority DigiNotar was compromised.

Screenshot of Google blog post

As Google, correctly points out - it's not just a question of changing passwords. Even if hackers who broke into your Gmail account no longer know your password, there are still things they could have done *while* they had access to your email which will allow them to continue to monitor your communications.

For instance, it's possible for someone to have tampered with your Gmail account to silently forward all messages that you receive to another account.

Gmail forwarding

Similarly, it's a good dea to check that no-one has been unexpectedly authorised to read and send email from your account.

Gmail delegation

Although ensuring that their Gmail has not been compromised will probably be the most obvious concern for many users, it's worth bearing in mind that other Google apps - such as Google Docs - could be at risk if you suffered from the man-in-the-middle attack.

Take Google's advice seriously and take steps to ensure that your account isn't compromised.

Further reading: Check out my much more detailed article about "How to stop your Gmail account being hacked".

, , , ,

One Response to Google tells Iranian users to check if their Gmail accounts have been hacked

  1. Ara says:

    Thank you for this Graham! I have many friends there and shall spread the news...

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <pre> <q cite=""> <strike> <strong>

About the author

Graham Cluley has worked in the computer security industry for more than 20 years, developing anti-virus software and doing quite a lot of talking about internet threats. He's won awards for his blogging, but is proudest of the text adventure games he wrote when he was still wearing short trousers. You can learn more about those (the games, not the trousers) at grahamcluley.com. Send Graham an email, subscribe to his updates on Facebook, follow him on Twitter and App.net, and circle him on Google Plus for regular updates.