Google said it warned more than 14,000 Gmail users that they were targeted in a late-September spear-phishing campaign attributed to APT28—also known as Fancy Bear—a state-sponsored group previously linked by the FBI and NSA to Russia’s GRU and military unit 26165. According to Google Threat Analysis Group director Shane Huntley, the operation accounted for 86% of the company’s warning notifications for that month, and Google said it blocked all emails used in the campaign.
The alerts are part of Google’s long-running warning system for suspected state-sponsored attacks, which the company says is based on internal monitoring, detailed analysis, and victim reports. Google emphasized that such notices indicate suspected targeting rather than confirmed account compromise, and advised affected users to harden defenses by using unique passwords, enabling 2-step verification, keeping software updated, and confirming sign-ins occur through https://accounts.google.com/.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Google detected a spear-phishing campaign in late September that it attributed to APT28, also known as Fancy Bear. The operation targeted Gmail users across a wide variety of industries, and Google said it blocked all emails used in the campaign.
Google announced a new warning shown to a subset of users it believed might be targets of state-sponsored attacks. The company said the alert indicated suspected targeting, such as phishing or malware, rather than necessarily a confirmed account compromise.
Google sent warning notifications to more than 14,000 Gmail users that they had been targeted by the APT28 spear-phishing campaign. Google said the alerts reflected targeting rather than confirmed compromise, and that the campaign accounted for 86% of that month's warnings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcesecurity.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.