Hacking a Google Account Without the Password
Back in October 2023, using an AI digital risk platform, security firm CloudSEK spotted that a threat actor called PRISMA had announced a “potent 0-day solution addressing challenges with incoming sessions of Google accounts” on their Telegram channel.
As of January 2024, Google is yet to roll out a comprehensive solution to the flaw, CloudSEK says.
What to do if Your Google Account has Been Compromised
A simple password reset can't be used to beat this attack technique alone. CloudSEK recommends that users who believe their account may have been hacked first log out of all devices and browsers.
Only after following this step can a password reset involving a sufficiently complex and unique password be used to invalidate the threat actor's old tokens.
https://tech.co/news/google-accounts-hacked-without-passwords