I was actually sitting at dinner with a client, for whom we have been providing web portal services for years. We were not providing email services for them because they were "using the largest email provider in the world: Google," and felt safe and secure (in spite of Google skimming their emails for marketing data as described in this blog article).
Just as we received our meals, my client's iPad lit up with several new emails. Upon reviewing them, his face appeared very perplexed. He excused himself, stating that he had a rather odd and urgent matter to look into.
After fiddling with his iPad for several minutes, he returned his attention to me and asked if I was familiar with Google's email recovery process. I asked why, and he explained that someone had apparently logged in and changed the administrator's password, locking him out of the account. Then, apparently, they changed all of the password recovery information, so that any attempt to regain control of the account would be directed to them.
I said that I was only familiar with GMail to the extent that we compete with them, but that there must be some sort of support number he could call to have the problem resolved. After spending an inordinate amount of time surfing around Google's help and support, he found a phone number.
Great - problem solved, right?
Upon calling the phone number provided, and navigating through the auto-attendant tree, he was told by the friendly, recorded voice that Google does not provide phone support for email, and that he must get support through their website. Continuing to try and navigate their support website, even with my help, simply led in circles. Multiple and varying explanations or questions about what assistance was needed, merely led back to the password recovery page, which did nothing more than send a password change request to the hacker's own GMail account.
Finally, the next day, my client dug even more into Google's site, and finally found a form that allowed him to request recovery of the account without emailing the hacker. He simply had to verify a few security questions and provide an explanation why he needed the account recovered, and proving that he was the owner of it.
Well, being able to show his name listed with the Secretary of State and on their corporate website as the president should be adequate proof of ownership, right? Notsomuch. The hacker apparently changed the security questions and was able to verify the other necessary information to claim that they were in fact the account owner!
The Happy Ending
These stories always have one, right? Well, so far my client has not been able to regain access to his company's GMail accounts. Google has denied him the ability to recover ownership, and has merely suggested that he chock this up to a lesson learned and create new accounts. This, of course, has brought up a number of other concerns:
1. He has no idea whether any undesirable emails have been sent out to his clients by this hacker.
2. None of his employees are able to access their email.
3. Even if he is ever able to regain access, any sensitive contacts, emails, or other information were likely downloaded.
4. We cannot migrate any of their historical email to our system, because access has been denied.
I guess the one silver lining is that this client is now entrusting us with their email, so this type of issue will never happen again. Even if a hacker were able to compromise their admin password, one simple phone call or email would have their account recovered to its rightful owner.
Clearly, I am biased with regard to email hosting, but I never expected to see anything like this from Google, and am justifiably appalled. There are clearly some major disadvantages to trusting giants like Google, and even Yahoo! or AOL with your email. Unfortunately, once your account is hacked, it's too late to be "better prepared."