A "new device sign in" notification is a freaky message to get, because it means that someone else has already successfully signed in to your account. Gmail informed users to change their passwords "right away."
Authentication using only a phone number, while convenient, is less securethan the other available methods, because possession of a phone numbercan be easily transferred between users. Also, on devices with multiple userprofiles, any user that can receive SMS messages can sign in to an account usingthe device's phone number.
Gmail mistakenly sends ‘new device signed in’ messages to users