Summary

  • A new scam has emerged that sees hackers sending fake Google account security emails to users in a bid to extract personal details from them.
  • The method presents a particularly menacing threat as the email apparently originates from a legitimate Google website, thereby not triggering any alarm bells with Gmail.
  • The email claims that Google has received a subpoena requiring it to disclose copies of the recipient’s account details.
  • This prompts users to access a fake support page that is hosted on Google Sites, a legitimate Google service that allows users to create their own websites.
  • The page has the legitimate Google domain, but the page’s URL gives it away, however, as it will not be hosted on the standard sign-in domain of accounts.google.com.
  • Furthermore, the email header shows that the email was sent from a private email account.
  • Until Google addresses the issue, users are advised to check the headers and text in the emails they receive for anything suspicious.

By Yadullah Abidi

Original Article