Google needs to address a specific and serious security failure in my account takeover case.
An attacker gained control of an authenticated Google session. They then changed my password, recovery email, recovery phone, Authenticator configuration, and added their own passkeys/security keys. I still possess the original passkey/security key that I used every day, but it is now useless for recovering the account.
This exposes a critical problem: Google treats a newly registered passkey as complete proof of identity, allowing it to authorize sensitive security changes and replace previously established authentication factors.
I am not asking whether passkeys are resistant to phishing. I am asking:
How could a compromised session register a new passkey and then use that credential to replace every existing security and recovery method without confirmation from a pre-existing physical key?
Changes involving passwords, recovery methods, Authenticator, passkeys, and security keys should require:
- Confirmation using a previously registered physical security key.
- A security delay before newly added credentials can modify other credentials.
- Immediate alerts through independent recovery channels.
- An emergency freeze option for Cloud and AI Studio resources.
- A complete audit trail showing when, where, and how each security factor was changed.
This takeover affects Google Cloud production infrastructure, Google AI Studio API credentials, and integrations connected to multiple projects. This is not a forgotten-password case.
Google must investigate how the new credentials were registered, preserve the relevant session and security logs, restore access to the legitimate owner, remove unauthorized credentials, and coordinate the case across Google Account Security, Google Cloud, and AI Studio.
I have the original security key, project files, GitHub history, billing records, resource metadata, screenshots, device evidence, and an open Google Cloud Support case.
Generic account recovery instructions are not an answer. Google’s authentication system allowed all established recovery methods to be replaced, and Google needs to explain what protection exists for the legitimate owner when this happens.