Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Hackers find a way to bypass Gmail two-factor authentication

Add as a preferred source on Google
Macbook with Gmail
Image used with permission by copyright holder

Two-factor authentification has been hailed as a significant move forward in providing online security, letting us log in with confidence to sites such as Gmail. Websites that once required an insecure password now need a complex password with a second form of authentication from a mobile device, or implement other two-factor systems. However, as with everything, two-factor authentication isn’t impervious to flaws, and a new report by Amnesty International details how hackers have been phishing two-factor codes.

Authenticating with a two-factor system is two-step, as hinted by the name, and will typically involve asking a user to enter both a password and a code, either generated by or sent to a mobile device. This secure option does indeed help to prevent hackers from accessing user accounts if they have only gained access to one factor, such as your password, if a website’s data has been breached. But, if you unknowingly give your two-factor code over to a malicious individual or site, the system has been defeated.

Recommended Videos

The Amnesty International report noted that hackers have begun to utilize an automated process that occurs by first phishing your password from a fraudulent website, then submitting the password to Gmail, triggering a two-factor text message, and finally having you submit that message into the fraudulent site.

Because some systems don’t requiring a user to re-authenticate for switching off two-factor, hackers can then quickly walk away with your account. Even without taking full control of an account, hackers can generate app-specific passwords, secondary passwords that can be used to access two-factor accounts without needing to re-authenticate each time.

Throughout 2017 and 2018, hackers targeted more than a thousand Google and Yahoo accounts across the Middle East and North Africa. When testing, Amnesty International found that its smartphone setup for testing the phishing system did indeed receive a genuine text message from Google’s server to authenticate in connection with the malicious site. The organization notes that the attacks targeted dissidents in the United Arab Emirates.

While the news is not a reason to disengage any two-factor systems you are currently employing, we still recommend switching on two-factor authentication for any websites that offer it, it is another bit of proof that no security system is impermeable.

Michael Archambault
Former Digital Trends Contributor
Michael Archambault is a technology writer and digital marketer located in Long Island, New York. For the past decade…
A clever Mac app lets you feel vibrations through the trackpad when you click a link or button
This $5 Mac app turns your trackpad into a tiny web radar
HapticPad Mac App

A new Mac app called HapticPad tries to make browsing more tactile. Posted by its developer on Reddit’s r/macapps community, the app uses a Mac’s Force Touch trackpad to trigger a subtle vibration when your cursor hovers over links, buttons, and input fields in the browser. So you can quite literally "feel" parts of a web page before you click them. It is a small idea, but it has the kind of obvious-in-hindsight cleverness that makes you wonder why macOS does not already do this.

So how does this work?

Read more
ChatGPT and Gemini could be quietly affecting your voting decisions, analysis shows
Your AI chatbot also has a political lean
AI Apps installed on iPhone Gemini DeepSeek Claude ChatGPT Auren

It's already pretty common to ask AI chatbots for help with emails, homework, travel plans, and so much more. So it was only a matter of time before politics entered the chat. A new analysis from The Washington Post suggests that major AI chatbots may not be as politically neutral as they often sound. The Post tested models behind OpenAI’s ChatGPT, Google’s Gemini, Anthropic’s Claude, DeepSeek, xAI’s Grok, and Gab’s Arya using a set of political questions designed to measure how chatbots handle hot-button issues.

According to the Post, OpenAI’s model gave one-sided left-leaning answers in 80% of responses, while Google’s Gemini mostly took a both-sides approach, giving left- and right-leaning arguments in more than 90% of its answers.

Read more
Gemini in Chrome can now see exactly what you’re looking at on screen
Google's new "Select from screen" tool makes it easier to ask Gemini questions about text and images in a browser tab.
Google Chrome Gemini Featured

Google is making Gemini a lot more aware of what's happening inside Chrome. The company has started rolling out a new "Select from screen" feature that lets users highlight specific text or images from a webpage and send them directly to Gemini, making conversations with the AI assistant far more contextual.

Gemini can now focus on exactly what users want to ask about

Read more