/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google sent users 40K warnings about phishing or malware attempts from nation-states in 2019, a 25% drop YoY; journalist and news outlet impersonations up

Google's Threat Analysis Group (TAG) works to counter targeted and government-backed hacking against Google and the people who use our products.

The Keyword Toni Gidwani

Context & Ripple Effects

This 2019 Threat Analysis Group report is the baseline for what became a recurring public metric: Google counting how many Gmail users it warns about government-backed phishing and malware. The 25% year-over-year drop to 40K warnings looked like a lull at the time, but the arc since runs the other way — by late 2021 TAG was reporting 50K+ alerts, up roughly a third year over year.

The more telling signal in this report is the composition shift: journalist and news outlet impersonations were climbing even as total warnings fell. That presaged both the Indian hack-for-hire firms spoofing WHO Gmail accounts TAG flagged months later and Google's eventual decision to hand out over 10,000 free security keys to journalists and other high-risk users.

First-order effects

  • Gmail users targeted by nation-state operators received 40,000 direct warnings in 2019 — each one a user who now knows a government-backed actor tried to compromise their account.
  • Journalists and news organizations face a rising share of these campaigns via impersonation rather than raw volume, making them the fastest-growing target class even in a down year.

Second-order effects

  • Impersonation pressure on the press pushed Google beyond passive alerting into hardware-level protection, culminating in the free security key program for high-risk users announced in 2021.
  • As TAG published its counts and campaign breakdowns, the warning number itself became a public yardstick — one that showed alerts rebounding sharply by 2021 and forced continued visibility into specific operations like the suspected North Korean campaign targeting infosec researchers.

Third-order effects

  • If the pattern holds, consumer platforms become de facto early-warning infrastructure for state-backed cyber activity, with their threat groups' disclosures shaping which targets — press, researchers, NGOs — get defensive resources first.
  • Routine public attribution of government hacking by private companies normalizes platform-level counterintelligence as a standing function, not an incident response.

The trend: Nation-state phishing against consumer email is hardening into a persistent, publicly tracked threat category, pushing platforms like Google from user warnings toward dedicated protection programs for journalists and other high-risk users.

Discussion

  • @weldpond Chris Wysopal on x
    This does seem impressive. S. Korea on the cyber map. https://twitter.com/...
  • @camillefrancois Camille Franois on x
    In an exciting move, Google's TAG just shared details on government backed hacking activity they observed in 2019. Full post by @t_gidwani here: https://blog.google/... I hope this pioneers a new type of annual transparency report across the industry. A few highlights below. http…
  • @freedomofpress @freedomofpress on x
    “Upon reviewing phishing attempts since the beginning of this year, we've seen a rising number of attackers, including those from Iran and North Korea, impersonating news outlets or journalists.” https://blog.google/...
  • @thehackersnews @thehackersnews on x
    — In 2019, Google's Threat Analysis Group (TAG) discovered several zero-day vulnerabilities affecting #Android, Chrome, #iOS, Internet Explorer and Windows. Read Google's report here: https://blog.google/...
  • @stshank Stephen Shankland on x
    The new hotness for trying to plant misinformation: pretend to be a journalist then contact analysts or real journalists. New Google stats. (Also, ouch, Ukraine is just one big target.) https://www.blog.google/...