If you possess a Gmail account, keep an eye out for a highly advanced scam that might jeopardize the security of your account.
The fraud entails cyber criminals generating emails that seem like they come directly from Google. These emails trick individuals into providing their Google account details, allowing the criminals to seize control of these accounts.
The fraud was initially detected and disseminated by Nick Johnson, who leads the development of the Ethereum Name Service (ENS). He described the assault as “highly intricate.” Additionally, he cautioned that since this exploit takes advantage of a vulnerability within Google’s framework, we might witness an increase in such assaults.
“I recently encountered a highly advanced phishing attempt and wanted to bring attention to it. This exploit takes advantage of a flaw within Google’s systems, and considering their reluctance to address it, we can expect this issue to become much more prevalent,” Johnson stated in his post on X.
The email that Johnson forwarded seemed to caution possible targets about a supposed subpoena, urging them to click on a link within the message.
“This notice is to alert you that a subpoena was issued to Google LLC by a law enforcement that seeks retrieval of information contained in your Google Account,” the email from the Cybercriminals read. “To examine the case materials or take measures to submit a protest, please do so in the provided Google Support Case.”
As Johnson explains, the email directed people to the URL sites.google.com instead of accounts.google.com. They look similar, but there is a very important difference: anyone with a Google account can create a website on sites.google.com, which is what the cybercriminals did to try to mimic the official Google site.
If the victim clicked either “Upload additional documents” or “View case”, they were redirected to an exact copy of the Google sign-in page designed to steal their login credentials.
In order to avoid scams like this,
Malwarebytes Labs
had a few suggestions:
- Don’t follow links in unsolicited emails or on unexpected websites
- Thoroughly examine the email headers when you get an unsolicited message.
- Confirm the validity of these emails via an alternative, independent approach.
- Avoid using your Google account—or Facebook for that matter—to sign in elsewhere online. Rather, set up an individual account directly with each service.
The next time you receive such an email, proceed with caution before clicking any links or submitting your login information.