If you have a Gmail account, you should be on the lookout for an "extremely sophisticated" scam that could leave your account at risk.
The scam involves cybercriminals creating emails that appear to be official messages coming from Google. They use those emails to persuade people into handing over their Google account credentials and take over their accounts.
The fraud was initially detected and disseminated by Nick Johnson, who leads the development of the Ethereum Name Service (ENS). He described the assault as "highly intricate." Additionally, he cautioned that due to its exploitation of a vulnerability within Google’s framework, further such incidents might be imminent.
"Recently I was targeted by an extremely sophisticated phishing attack, and I want to highlight it here. It exploits a vulnerability in Google's infrastructure, and given their refusal to fix it, we're likely to see it a lot more," Johnson wrote in his post on X.
The email that Johnson forwarded seemed to caution possible targets about a supposed subpoena, urging them to click on a link within the message.
The purpose of this notification is to inform you that a subpoena has been served to Google LLC by law enforcement authorities seeking access to information within your Google Account," stated the message from the cyber criminals. "Should you wish to review the case documents or initiate actions to file an objection, kindly proceed via the associated Google Support Case.
Johnson points out that the email led individuals to the URL sites.google.com rather than accounts.google.com. Although they appear quite alike, there is a crucial distinction: anybody with a Google account has the ability to set up a website on sites.google.com. This feature was exploited by cyber criminals who used it to replicate the legitimate Google site.
If the victim clicked either “Upload additional documents” or “View case”, they were redirected to an exact copy of the Google sign-in page designed to steal their login credentials.
In order to avoid scams like this, Malwarebytes Labs had a few suggestions:
- Don’t follow links in unsolicited emails or on unexpected websites
- Carefully look at the email headers when you receive an unexpected mail
- Confirm the validity of these emails via an alternative, independent means.
- Avoid using your Google account—or Facebook for that matter—to sign in elsewhere online. Rather, make an individual account directly with each service.
So next time you get an email like this, be careful before clicking any links or entering your login credentials.