By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Warning to all 1.8bn Gmail users over ‘hidden danger’ that steals your password
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Warning to all 1.8bn Gmail users over ‘hidden danger’ that steals your password
News

Warning to all 1.8bn Gmail users over ‘hidden danger’ that steals your password

News Room
Last updated: 2025/07/17 at 11:05 AM
News Room Published 17 July 2025
Share
SHARE

AN URGENT warning has been issued for over a billion Gmail users amid a “hidden danger” which is stealing passwords – and this is what you need to watch out for.

The new type of attack has been flying under the radar, attacking an eye-watering 1.8 billion Gmail users without them even noticing.

2

Malicious actors are targeting 1.8 billion Gmail users through an email scamCredit: Getty

Users therefore need to make sure they follow the correct instructions in order to combat the malicious activity.

Thieving hackers are using Google Gemini – the company’s AI built-in tool – to trick users into giving over their credentials.

Cybersecurity experts have found that bad actors are sending emails with concealed instructions that cause Gemini to generate fake phishing warnings.

These tricks users into sharing personal account information, or visiting malicious websites.

The emails are usually constructed in a manner which makes them appear urgent – and occasionally from a business.

Shady hackers will craft these emails by setting the font size to zero and the text colour to white – before inserting prompts invisible to users but picked up by Gemini.

GenAI bounty manager Marco Figueroa demonstrated how such a dangerous prompt could falsely alert users that their email account has been compromised.

These warnings would urge victims to call a fake “Google support” phone number provided, in order to resolve the issue. 

To fight these prompt injection attacks, experts have made a number of recommendations that users should act on immediately.

They firstly suggested that companies configure email clients to detect and neutralise hidden content in message bodies. 

Google adds AI upgrade to your Gmail that writes emails for you – find it in seconds if you’re eligible for freebie

This should help counter hackers sending invisible text within emails.

Security experts also recommended that users implement post-processing filters to scan inboxes for suspicious elements like “urgent messages”, URLs, or phone numbers.

This action could bolster defences against threats.

The scam was brought to light after research, spearheaded by Mozilla’s 0Din security team, showed proof of one of the hostile attacks last week.

The report showed how hackers tricked Gemini into showing a fake security alert.

It warned users their password had been stolen – but the message was fake and designed to steal their info.

The trick works by hiding a secret size zero font prompt in white text that matches the email background.

So when someone clicks “summarise this email” using Gemini, the tool reads the hidden message – not just the visible bit.

This form of manipulation is named “indirect prompt injection”, and it takes advantage of AI’s inability to differentiate between a user’s question and a hacker’s embedded message.

AI cannot tell the difference, as both messages look like text, and it will usually follow whichever comes first – even if it is malicious.

As Google have failed to patch this method of scamming victims, the door is still open for hackers to exploit this technique.

Sneaking in commands that the AI may follow will be an effective method of leaking sensitive data until users are properly protected against the threat.

AI is also incorporated into Google Docs, Calendar, and outside apps – widening the scope of the potential risk.

Google has reminded users amid this scamming crisis that it does not issue security alerts through Gemini summaries.

So if a summary tells you that your password is at risk, or prompts you with a link to click – users should always treat it as suspicious and delete the email.

Gmail logo on a smartphone.

2

Users need to follow the steps to protect against the scamCredit: Alamy

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Hackers Exploit Apache HTTP Server Flaw to Deploy Linuxsys Cryptocurrency Miner
Next Article Wacom’s new MovinkPad drawing tablet doesn’t need a PC
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Games Without Ads, Interruptions, or In-App Purchases
News
Getting Into My Top Picks at the Right Time Just Got a Whole Lot Easier…
News
House passes crypto market structure bill after GOP revolt 
News
Heatmap and Accuracy Results from Medical Image Classification Models | HackerNoon
Computing

You Might also Like

News

Games Without Ads, Interruptions, or In-App Purchases

0 Min Read
News

Getting Into My Top Picks at the Right Time Just Got a Whole Lot Easier…

12 Min Read
News

House passes crypto market structure bill after GOP revolt 

3 Min Read

GwsSnsnbyxnngsswNFs

0 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?