Google warns: the miners are using hacked cloud accounts
The company claimed that 86% of the 50 recently hacked Google Cloud accounts were used to mine cryptocurrency
01.12.2021 - 14:30
686
1 min
0
What’s new? Google has warned that the majority of the hacked Google Cloud accounts are being used by the attackers for mining. The search giant's cybersecurity service has released a detailed report called “Threat Horizons.”
What does the report say? Google said that 86% of the 50 recently hacked accounts were used to mine cryptocurrency. In most cases, the mining software was downloaded within 22 seconds of being hacked. About 10% of the compromised accounts were also used to scan other public resources on the Internet, and another 8% were used to attack other websites.
How did the attackers gain access to the accounts? Google claims that the attackers were able to gain access to the Google Cloud accounts by taking advantage of the weak protection from the service's customers. Almost half of the compromised accounts had a weak password without two-factor authentication. About a quarter of the hacks involved vulnerabilities in third-party software that users had installed.
What else did Google claim? Seth Rosenblat, the security editor at Google Cloud, added that in late September the company blocked a phishing attack by the Russian hacker group APT28/Fancy Bear. The Google researchers also uncovered the North Korean government-backed group of hackers posing as Samsung employees to send malware within South Korea.
Useful material?
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Incidents
According to Blockaid, the attack may have been carried out by the same hacker behind the 1inch Fusion V1 exploit.
May 7, 2026
Incidents
The attacker gained administrative access and altered contracts to drain user funds
Apr 30, 2026
Telegram
Twitter