Office of Information Technology
September 2, 2022
Tags Legitimate Email

Critical Security Alert from <no-reply@accounts.google.com>

Phish Bowl Alerts

This is a legitimate notification from Google, sent from no-reply@accounts.google.com (can verify by looking at its full header details) and a verification links directing you to your account. It also provides an alternative method to independently navigate to the provided URL.

The notification indicates that Google found a large cache of exposed passwords online, and is simply warning recipients that "Your Google Account is not affected. To secure your accounts, Google Password Manager recommends changing your passwords now."

OIT recommends that since it is common for individuals to reuse passwords, as well as to use their Brown Gmail address for non-Brown business, that when exposures like this one are reported, let it serve as a reminder to:

  1. Use a unique password for your Brown network access/Gmail. Since your Brown network password is now also used for Gmail (along with Shibboleth authentication), it is even more important to not use it anywhere else, such as accessing your financial accounts or your personal email. Should it be exposed, this prevents the others from being exposed as well. If you aren't sure that your password is unique, we suggest changing it now (at brown.edu/myaccount).
  2. Limit the use of your Brown email address to Brown-related communications and activities.

=======================================================
From: Google <no-reply@accounts.google.com>
Date: Fri, Sep 2, 2022 at 1:27 PM
Subject: Critical security alert
To: <josiah_carberry@brown.edu>

Google

Some of your saved passwords were found online
    josiah_carberry1@brown.edu
Some of your saved passwords were found in a data breach from a site or app that you use. Your Google Account is not affected.

To secure your accounts, Google Password Manager recommends changing your passwords now.

[ Check passwords ]

You can also see security activity at https://myaccount.google.com/notifications

You received this email to let you know about important changes to your Google Account and services.
© 2022 Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Screenshot of Google Criticial Security Alert, with text displayed above