Google Workspace is rolling out a security update to stop token stealing attacks

Google Workspace is launching a new security measure to help prevent the same type of account takeover attack that impacted Linus Tech Tips. The feature, which is rolling out in beta for Chrome users on Windows, is designed to block bad actors from remotely stealing the cookies that keep you logged in to your Workspace account.

Google calls the feature Device Bound Session Credentials (DBSC), and it does exactly what its name suggests: it protects users’ Workspace accounts by binding session cookies, the temporary files that websites use to remember user information, to their devices.

That makes it more difficult for attackers to carry out session token-stealing attacks, which often occur when a victim downloads information-stealing malware. From there, bad actors can exfiltrate a victim’s login credentials to a remote server, allowing them to sign in to their account from another device or sell their credentials.

“Because this theft occurs after a user has logged in, it bypasses many existing account protections like 2FA [two-factor authentication],” Google spokesperson Ross Richendrfer tells The Verge. “Existing protections for this type of attack aren’t very mature, so it’s low-hanging fruit for attackers.”

In 2023, a bad actor took over the YouTube channel for Linus Tech Tips, along with two other Linus Media Group accounts, after an employee downloaded a fake sponsorship offer file containing cookie-stealing malware. This week, YouTube issued a warning about a similar scam involving creators downloading phony brand deals. YouTube isn’t the only platform that we’ve seen impacted by cookie-stealing, either, as hackers hijacked several Chrome extensions last year, adding malware that exfiltrates session tokens for some websites.

Google says there’s been an “exponential rise” in cookie and authentication token theft over the past couple of years, and that this “trend has only intensified in 2025.” The company began working on DBSC last year, and said the verification platform Okta, as well as browsers like Microsoft Edge, have “expressed interest” in the concept. Along with DBSC, Google recommends that Workspace administrators enable passkeys as well, which is now available to over 11 million customers.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

Emma Roth
Read More

Latest

Study suggests fibroid rates in Latina women may be lower than previously thought

🛡️ Just a quick check We’re checking your connection to prevent automated abuse

Rimas Entertainment Presents SONAR: ‘A Record Label Where Artists Can Develop with Freedom’

The label's roster includes Cris MJ, Yan Block, Hades66 and more. Jesús Rodríguez, head of label, SONAR SONAR / Rimas Entertainment Español Rimas Entertainment officially unveils SONAR, a record label focused on the development and projection of artists within the Latin music market, Billboard can announce exclusively today (April 29). The initiative is part of

YouTube’s Tuma Basa to Exit as Director of Black Music & Culture

MusicAfter eight years at the streaming giant, the...

Feza – Khanyisa

MusicDOWNLOAD MP3 SONG...

Newsletter

Don't miss

Study suggests fibroid rates in Latina women may be lower than previously thought

🛡️ Just a quick check We’re checking your connection to prevent automated abuse

Rimas Entertainment Presents SONAR: ‘A Record Label Where Artists Can Develop with Freedom’

The label's roster includes Cris MJ, Yan Block, Hades66 and more. Jesús Rodríguez, head of label, SONAR SONAR / Rimas Entertainment Español Rimas Entertainment officially unveils SONAR, a record label focused on the development and projection of artists within the Latin music market, Billboard can announce exclusively today (April 29). The initiative is part of

YouTube’s Tuma Basa to Exit as Director of Black Music & Culture

MusicAfter eight years at the streaming giant, the...

Feza – Khanyisa

MusicDOWNLOAD MP3 SONG...

The Vogue Business Funding Tracker

Introducing the Vogue Business Funding Tracker, a running list highlighting the most notable and intriguing investment and M&A activity in fashion and beauty. From emerging disruptors to legacy giants undergoing major changes, we spotlight the deals that are shifting the dynamics of the sectors we cover, including fashion, beauty, tech and sustainability. April 2026 Icicle

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day