Technology News Worldwide

Beware of this sneaky Google phishing scam

beware-of-this-sneaky-google-phishing-scam

Scammers are exploiting Google and PayPal’s tools to create fake emails that pass security checks.

Scammers are exploiting Google and PayPal’s tools to create fake emails that pass security checks.

Illustration of a pixelated key next to a padlock and chain, implying online data security.

Illustration of a pixelated key next to a padlock and chain, implying online data security.

Cath Virginia / The Verge | Photo: Getty Images

Umar Shakir

Umar Shakir is a news writer fond of the electric vehicle lifestyle and things that plug in via USB-C. He spent over 15 years in IT support before joining The Verge.

Attackers are sending phishing emails that appear to be from “no-reply@google.com,” presented as an urgent subpoena alert about “law enforcement” seeking information from the target’s Google Account. Bleeping Computer reports that the scam utilizes Google’s “Sites” web-building app to create realistic-looking phishing websites and emails that aim to intimidate victims into giving up their credentials.

As explained by EasyDMARC, an email authentication company, the emails manage to bypass the DomainKeys Identified Mail (DKIM) authentication that would normally flag fake emails, because they came from Google’s own tool. The scammers simply entered the full text of the email as the name of their fake app, which autofills that text into an email sent by Google to their own chosen address.

When forwarded from the scammer to a user’s Gmail inbox, it remains signed and valid since DKIM only checks the message and headers. PayPal users were similarly targeted using the DKIM relay attack last month. Finally, it links to a real-looking support portal on sites.google.com instead of accounts.google.com, hoping the recipient won’t catch on.

Etherem Name Service developer Nick Johnson received the same Google phishing scam and reported the attackers’ misuse of Google OAuth applications as a security bug to Google. The company initially brushed it off as “working as intended,” but then backtracked and is now working on a fix.

Installer

A weekly newsletter by David Pierce designed to tell you everything you need to download, watch, read, listen to, and explore that fits in The Verge’s universe.

Related posts

OpenAI debuts its GPT-4.1 flagship AI model

LiveKit’s tools power real-time communications, including OpenAI’s Voice Mode | TechCrunch

Microsoft has a new strategy chief to navigate its AI era