@rcombs in general: there are 10-100s active full-time criminal groups targeting Google users at all times. Some are interested in stealing SSNs and passport photos from gmail. Some are interested in stolen credit cards (via reselling tradeable in-game items in Play Store games, for example). Some deploy cryptolockers on Google Drive.
Often they either have credentials, phish them, or have session tokens stolen by malware on device. Passkey/2FA helps, but doesn't prevent the latter.
@rcombs Google isn't just fighting that on one front, they've been strongly pushing for 2FA for years. They were the first to deploy Security Keys for a reason.
There's been many efforts to try and bind session tokens to devices too. Example: Channel ID. Unfortunately not successful.
The "defense front" you're seeing is trying to detect suspicious actions coming from non legitimate devices. If someone gmail-searches "SSN" and you can detect it's not a real browser, you can issue a challenge.