By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Watch Out for This Sophisticated Phishing Email That Looks Like It’s From Google
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Watch Out for This Sophisticated Phishing Email That Looks Like It’s From Google
News

Watch Out for This Sophisticated Phishing Email That Looks Like It’s From Google

News Room
Last updated: 2025/04/17 at 1:23 PM
News Room Published 17 April 2025
Share
SHARE

Phishing emails are becoming increasingly difficult to differentiate from legitimate ones, as highlighted by developer Nick Johnson, who says he was “targeted by an extremely sophisticated phishing attack [that] exploits a vulnerability in Google’s infrastructure.”

The email he received came from [email protected], which “passes the DKIM [DomainKeys Identified Mail] signature check,” he notes. Gmail did not display any warning, and “even puts it in the same conversation as other, legitimate security alerts.”


This Tweet is currently unavailable. It might be loading or has been removed.

The email warned Johnson that Google had received a subpoena to produce a copy of his Google account. Clicking on a link inside the email “takes you to a very convincing ‘support portal’ page” hosted on sites.google.com. This tactic is “clever,” Johnson says, because “people will see the domain is http://google.com and assume it’s legit.”

Clicking “Upload additional documents” or “View case” takes you to sign-in page; if you enter your details, the scammers will “presumably…harvest your login credentials and use them to compromise your account,” he says.

How did the hackers spoof a valid email? Johnson blames “two vulnerabilities in Google’s [infrastructure] that they have declined to fix.” First, the legacy sites.google.com product dates back to “before Google got serious about security.” People can host content on a google.com subdomain, “and crucially, it supports arbitrary scripts and embeds,” he says.

“Obviously, this makes building a credential harvesting site trivial; they simply have to be prepared to upload new versions as old ones get taken down by Google’s abuse team,” Johnson says. “It helps the attackers that there’s no way to report abuse from the Sites interface, too.” He’s calling on Google to disable scripts and arbitrary embeds in Sites as it’s “too powerful a phishing vector.”

Get Our Best Stories!


Newsletter Icon

Stay Safe With the Latest Security News and Updates

Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.

By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.

Thanks for signing up!

Your subscription has been confirmed. Keep an eye on your inbox!

The email itself, meanwhile, which takes advantage of Google OAuth and Google’s practice of using “me” when referring to your own emails, is “much more sophisticated, and in my opinion much more obviously a security issue on Google’s part,” he says.

Johnson says he reported the issue to Google, which said it wasn’t a bug. However, later on, Google acknowledged the bug and promised to roll out a fix. 

Recommended by Our Editors

“We’re aware of this class of targeted attack from the threat actor, Rockfoils, and have been rolling out protections for the past week,” a Google spokesperson tells Newsweek. “These protections will soon be fully deployed, which will shut down this avenue for abuse.”

Until the fix arrives, Google recommends adopting multi-factor authentication and passkeys for stronger protection against phishing attacks.

And stay alert because anyone can be duped. This Gmail scam comes after a hacker managed to phish Troy Hunt, the creator of HaveIBeenPwned.com, tricking the security expert into clicking a malicious email while he was jetlagged.

About Jibin Joseph

Contributor

Jibin Joseph

Jibin is a tech news writer based out of Ahmedabad, India. Previously, he served as the editor of iGeeksBlog and is a self-proclaimed tech enthusiast who loves breaking down complex information for a broader audience.

Read Jibin’s full bio

Read the latest from Jibin Joseph

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Tencent’s 2024 anti-corruption report: dozens dismissed, more than 20 handed over to the police · TechNode
Next Article Best Microphone 2024: Our pick of the best
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Magic Cue on the Pixel 10 sounds like Pixel Screenshots on steroids
News
Tencent to shut down Honor of Kings: Breaking Dawn early access test · TechNode
Computing
Little-known 1-point rule that’s never happened in NFL history
News
France is building a high security megacárcel for its most dangerous prisoners. 7,000 kilometers from France
Mobile

You Might also Like

News

Magic Cue on the Pixel 10 sounds like Pixel Screenshots on steroids

3 Min Read
News

Little-known 1-point rule that’s never happened in NFL history

3 Min Read
News

FCC Chairman Carr uses his bully pulpit to threaten EchoStar and Boost Mobile

6 Min Read
News

Today's NYT Connections: Sports Edition Hints, Answers for June 15 #265

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?