What happened
Google Threat Intelligence and Citizen Lab jointly documented a campaign in June 2025 in which a Russian government-linked cluster tracked as UNC6293 persuaded targets to create Google application-specific passwords and hand them over. Victims included prominent academics and critics of Russia. The technique bypassed multi-factor authentication entirely and gave the attackers durable mailbox access.
How the deception worked
The operators impersonated US State Department officials and invited targets to private online consultations, sustaining polite, well-written correspondence over days or weeks and copying plausible-looking @state.gov addresses to make the exchange feel institutional. They then sent PDF instructions asking the target to generate a Google app-specific password, described as a way to join a secure State Department platform, and to send the sixteen-character string back. Because the victim generated it themselves inside their real Google account, nothing looked stolen and MFA was never challenged. The attackers used the password for ongoing, silent access to the mailbox.
The control that would have caught it· our reading, not a claim from the sources
Disable app-specific passwords for at-risk users, enrol them in Google's Advanced Protection Program, and treat any request to generate an account credential for a third party as a red flag regardless of who is asking.
Sources (2)
- Same Sea, New Phish: Russian Government-Linked Social Engineering Targets App-Specific PasswordsThe Citizen Lab·citizenlab.caOpen ↗
- Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing CampaignThe Hacker News·thehackernews.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.