Web_Logo
Remote Support
Google Workspace: Chrome Now Blocks Account Takeover Attacks
Home » Google Workspace Updates  »  Google Workspace: Chrome Now Blocks Account Takeover Attacks

Google Workspace: Chrome Now Blocks Account Takeover Attacks

Google has activated a new security layer called Device Bound Session Credentials (DBSC) for all Google Workspace users. Rolled out automatically from early June 2026, the change protects business accounts against one of the most common account takeover techniques — stolen session cookies — without requiring any action from administrators or end users.

  • What it is: When you log in to Google Workspace via Chrome, your browser creates a session cookie that keeps you logged in. Attackers can steal this cookie using malware and use it to access your account from a different device — bypassing your password and MFA entirely. DBSC defeats this by cryptographically binding your session to the specific device you logged in from, using your computer's hardware security chip (such as the Trusted Platform Module on Windows). A stolen cookie is useless on any other device.
  • Who is affected: All Google Workspace users accessing accounts through Chrome on Windows. The protection is automatic and enabled by default for all Workspace customers.
  • What risk is being addressed: Session cookie theft is used in sophisticated phishing and malware attacks, including techniques that bypass multi-factor authentication. DBSC significantly raises the difficulty of this class of attack.
  • What action is needed: None — this protection is on by default and requires no configuration. Admins can monitor DBSC binding events through the Google Workspace security investigation tool. Ensure Chrome is kept up to date on all business devices to receive the protection. Source: Google Workspace Updates Blog.

No configuration is required to benefit from this update. We recommend ensuring Chrome is kept current on all business devices — if your organisation manages Chrome via policy, check that auto-updates are not being blocked.