Gmail adds blue check mark to verify “reputable” senders
For a long time, with the development and popularity of social networking platforms, the "blue tick" has gradually become one of the most powerful characters in the internet world.
Not every account security email you receive is legitimate. And if you see an email from Google in your Gmail inbox, think twice. There's a new Gmail scam going around — and it looks like it's coming straight from Google.
Your Next Google Security Email Could Be a Scam
The campaign was discovered after developer Nick Johnson received a complex phishing email that appeared to come from Google. In a thread on X, Johnson explained that the email was sent from [email protected] and that it passed Google's DKIM signature check, meaning it was signed by accounts.google.com.
Because the email was signed from a legitimate Google website, Gmail did not raise any warnings. It stated that a subpoena had been sent to Google LLC asking the company to provide a copy of the recipient's Google account contents.
The email contains a sites.google.com link to a fake support page. This fake page displays the status of a forensic investigation report with a document review attached and two buttons to upload additional documents or view the case. Clicking any of these buttons takes you to another fake login page also hosted on sites.google.com.
Johnson doesn’t take it any further, but it’s safe to assume that the fake login page is there to collect your Google account credentials before redirecting you to a real Google page or page to avoid detection. Since you’re already logged in to check your Gmail and therefore see the notification, most Google pages will automatically open even if you enter your password, creating the illusion of a real login.
While the fake login page is an exact copy of the real Google page, you can easily tell the difference between the two if you look at the URL of the page. Legitimate Google login pages are hosted on accounts.google.com instead of sites.google.com. There are also two main red flags in the phishing email.
First, the email header shows that while the email is signed by accounts.google.com, it originated from a privateemail.com address and was sent to "[email protected]" . The second clue lies at the bottom of the email, where there is a lot of white space followed by text that says "Google Legal Support has been granted access to your Google account" , followed by the email address mentioned above.
Google domains become scam playgrounds
Given that the phishing email appears to originate from a legitimate Google site, the average Gmail user would think nothing of following the instructions provided in the email. Additionally, since the fake pages are hosted on sites.google.com , people will see the legitimate google.com domain and assume the page is real.
Google Sites is a legitimate service from Google that allows you to quickly create your own website and host it on a Google domain. While it is a handy tool, it allows users to run external scripts and embeds of their choice, which is a major security risk.
Using this service also makes it incredibly easy to create phishing pages. Even if a page is taken down by Google’s anti-abuse team, scammers can quickly put up another one in a short period of time. Email, however, is a bigger security concern for Google.
Johnson reported the email bug to Google, but the company closed the issue, stating that the feature worked as expected and adding that it did not consider it a security issue. This means we could see similar campaigns in the future. Keeping malicious emails out is one of the reasons people are abandoning Gmail for a more security-focused alternative.
Until Google gets things right, make sure you keep an eye on such emails. If in doubt, check the subject line and body of the email for any strange email addresses or unusual text that wouldn’t appear in an official email.
For a long time, with the development and popularity of social networking platforms, the "blue tick" has gradually become one of the most powerful characters in the internet world.
Google's Chromecast line has long been a popular choice if you want to replace your smart TV experience or turn any TV into a smart TV.
Google is adding a small but long-awaited new feature to the Play Store.
After years of neglect, Google has finally decided to refocus its investment on extended reality (XR) devices like headsets and glasses.
While not as widely discussed as some of its competitors, Google's Gemini AI has a lot going for it — and here are five reasons why Gemini deserves your attention.
There are many Android manufacturers, but not all of them pay attention to software updates. Although the situation has improved over the past decade, not all smartphone manufacturers provide great software support.
Recently, some users noticed that Google Gemini has been giving repetitive text, weird characters, and complete nonsense in some responses.
The Google app for iPhone is about to become a little less useful as Google recently removed access to Gemini AI from that app.
Losing access to your Google account can have serious consequences beyond not being able to send and receive email.
Google has just announced that users can now create videos using artificial intelligence through its Gemini chatbot and the recently launched experimental tool Whisk.
Whether you're taking your first steps into the workforce or transitioning to a new industry, Google's experimental Career Dreamer is designed to connect you with compatible roles.
Last year, Google introduced an AI-powered shopping assistant in Search that allows users to get a visual idea of how a piece of clothing would look on a specific body type.
Google has been increasingly showing interest in the field of artificial intelligence applications in medicine.
After a few days of confusion, Google has officially confirmed the issue with both the second-generation Chromecast and Chromecast Audio.
On Monday, internal documents describing the factors Google Search considers when ranking and displaying web results were leaked.
Smart TVs have really taken the world by storm. With so many great features and the ability to connect to the Internet, technology has changed the way we watch TV.
Refrigerators are familiar appliances in families. Refrigerators usually have 2 compartments, the cool compartment is spacious and has a light that automatically turns on every time the user opens it, while the freezer compartment is narrow and has no light.
Wi-Fi networks are affected by many factors beyond routers, bandwidth, and interference, but there are some smart ways to boost your network.
If you want to go back to stable iOS 16 on your phone, here is the basic guide to uninstall iOS 17 and downgrade from iOS 17 to 16.
Yogurt is a great food. Is it good to eat yogurt every day? What will happen to your body when you eat yogurt every day? Let's find out together!
This article discusses the most nutritious types of rice and how to maximize the health benefits of whichever rice you choose.
Establishing a sleep schedule and bedtime routine, changing your alarm clock, and adjusting your diet are some of the measures that can help you sleep better and wake up on time in the morning.
Rent Please! Landlord Sim is a simulation mobile game on iOS and Android. You will play as a landlord of an apartment complex and start renting out an apartment with the goal of upgrading the interior of your apartments and getting them ready for rent.
Get Bathroom Tower Defense Roblox game codes and redeem them for exciting rewards. They will help you upgrade or unlock towers with higher damage.
Let's learn about the structure, symbols and operating principles of transformers in the most accurate way.
From better picture and sound quality to voice control and more, these AI-powered features are making smart TVs so much better!
DeepSeek initially had high hopes. As an AI chatbot marketed as a strong competitor to ChatGPT, it promised intelligent conversational capabilities and experiences.
It's easy to miss important details when you're jotting down other essentials, and trying to take notes while chatting can be distracting. Fireflies.ai is the solution.
Axolot Minecraft will be a great assistant for players when operating underwater if they know how to use them.
A Quiet Place: The Road Ahead's configuration is rated quite highly, so you will need to consider the configuration before deciding to download.