Heads Up: Google Inactive Account Deletion Notifications

Stu Sjouwerman | Jul 31, 2023

Heads Up: Google Inactive Account Deletion NotificationsGoogle announced an update to their inactive account policies in May. Accounts that have been inactive for a period of two years or more will start being deleted in December 2023, at the earliest.

This policy change is meant to enhance security, as abandoned accounts are more likely to be compromised and 10x less likely to have multi-factor authentication enabled. The policy applies to content within Google Workspace (Gmail, Docs, Drive, Meet, Calendar) and Google Photos.

A few ways to keep an account status active include reading or sending an email, using Google Drive, watching a YouTube video, downloading an app on the Google Play Store, using Google Search and more. Google's announcement post gives more details around affected accounts, backup instructions, and more.

While account deletion isn't set to begin for several months, notification emails have started going out to account owners. We haven't seen them yet, but this is prime fodder for phishing attacks that impersonate Google. It's only a matter of time before cybercriminals use this news to scam people into going to malicious websites, where their Google account credentials can be harvested.

You should warn your users now to keep them aware of potential attacks. Any urgent account alert emails should be scrutinized closely. Instead of clicking a link in an email, it's best to go directly to Google accounts that could be affected by this policy change.

New-school security awareness training can give your employees a healthy sense of suspicion so they can avoid falling for social engineering attacks.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.