New Gmail scam from... Google?

Not every account security email you receive is legitimate. And if you see an email from Google in your Gmail inbox, think twice. There's a new Gmail scam going around — and it looks like it's coming straight from Google.

Your Next Google Security Email Could Be a Scam

The campaign was discovered after developer Nick Johnson received a complex phishing email that appeared to come from Google. In a thread on X, Johnson explained that the email was sent from [email protected] and that it passed Google's DKIM signature check, meaning it was signed by accounts.google.com.

Because the email was signed from a legitimate Google website, Gmail did not raise any warnings. It stated that a subpoena had been sent to Google LLC asking the company to provide a copy of the recipient's Google account contents.

New Gmail scam from... Google?

The email contains a sites.google.com link to a fake support page. This fake page displays the status of a forensic investigation report with a document review attached and two buttons to upload additional documents or view the case. Clicking any of these buttons takes you to another fake login page also hosted on sites.google.com.

Johnson doesn’t take it any further, but it’s safe to assume that the fake login page is there to collect your Google account credentials before redirecting you to a real Google page or page to avoid detection. Since you’re already logged in to check your Gmail and therefore see the notification, most Google pages will automatically open even if you enter your password, creating the illusion of a real login.

New Gmail scam from... Google?
Fake Gmail Legal Investigation Page

While the fake login page is an exact copy of the real Google page, you can easily tell the difference between the two if you look at the URL of the page. Legitimate Google login pages are hosted on accounts.google.com instead of sites.google.com. There are also two main red flags in the phishing email.

First, the email header shows that while the email is signed by accounts.google.com, it originated from a privateemail.com address and was sent to "[email protected]" . The second clue lies at the bottom of the email, where there is a lot of white space followed by text that says "Google Legal Support has been granted access to your Google account" , followed by the email address mentioned above.

Google domains become scam playgrounds

Given that the phishing email appears to originate from a legitimate Google site, the average Gmail user would think nothing of following the instructions provided in the email. Additionally, since the fake pages are hosted on sites.google.com , people will see the legitimate google.com domain and assume the page is real.

Google Sites is a legitimate service from Google that allows you to quickly create your own website and host it on a Google domain. While it is a handy tool, it allows users to run external scripts and embeds of their choice, which is a major security risk.

Using this service also makes it incredibly easy to create phishing pages. Even if a page is taken down by Google’s anti-abuse team, scammers can quickly put up another one in a short period of time. Email, however, is a bigger security concern for Google.

Johnson reported the email bug to Google, but the company closed the issue, stating that the feature worked as expected and adding that it did not consider it a security issue. This means we could see similar campaigns in the future. Keeping malicious emails out is one of the reasons people are abandoning Gmail for a more security-focused alternative.

Until Google gets things right, make sure you keep an eye on such emails. If in doubt, check the subject line and body of the email for any strange email addresses or unusual text that wouldn’t appear in an official email.

Sign up and earn $1000 a day ⋙

Leave a Comment

Google develops AI algorithm that can diagnose skin diseases and tuberculosis

Google develops AI algorithm that can diagnose skin diseases and tuberculosis

Google has been increasingly showing interest in the field of artificial intelligence applications in medicine.

Google confirms issue with second-generation Chromecast and Chromecast Audio

Google confirms issue with second-generation Chromecast and Chromecast Audio

After a few days of confusion, Google has officially confirmed the issue with both the second-generation Chromecast and Chromecast Audio.

Google Accidentally Published Documentation on How Search Works

Google Accidentally Published Documentation on How Search Works

On Monday, internal documents describing the factors Google Search considers when ranking and displaying web results were leaked.

How to enable and use Google Assistant on Chrome Android

How to enable and use Google Assistant on Chrome Android

Google is gradually phasing out its old voice recognition technology and replacing it with its virtual assistant Assistant.

Samsung launches 3D Eclipsa Audio sound technology, competing directly with Dolby Atmos

Samsung launches 3D Eclipsa Audio sound technology, competing directly with Dolby Atmos

Samsung Electronics has announced plans to integrate Eclipsa Audio, a brand new 3D audio technology, developed through a partnership with Google, into its 2025 lineup of TVs and soundbars.

Google Announces 6 New Features Coming to Android Phones

Google Announces 6 New Features Coming to Android Phones

Google today announced six new features coming to Android smartphones.

What is Privacy Dashboard on Android 12? Why is it considered a breakthrough for privacy?

What is Privacy Dashboard on Android 12? Why is it considered a breakthrough for privacy?

Security and privacy are increasingly becoming major concerns for smartphone users in general.

ChatGPT Search or Google is better?

ChatGPT Search or Google is better?

Many people have been trying for a long time to see if they can actually replace Google with the ChatGPT Search Chrome extension.

Google Officially Removes Manifest V2 Extensions in Chrome

Google Officially Removes Manifest V2 Extensions in Chrome

It has been a long time coming and the day has finally come. People are reporting that their old Manifest v2 extension is being removed from Chrome. So what happens now?

Google rolls out December Pixel update, most of it Gemini-related

Google rolls out December Pixel update, most of it Gemini-related

This latest update introduces improvements related to the camera, audio and visual tools, and most importantly, Gemini, Google's AI assistant.

9 Useful Google Apps That Dont Come Pre-Installed on Android Phones

9 Useful Google Apps That Dont Come Pre-Installed on Android Phones

If you love Google services, these lesser-known apps can add surprising value to your device.

Google splits with Qualcomm, opts for MediaTeks 5G modem for Pixel 10 series

Google splits with Qualcomm, opts for MediaTeks 5G modem for Pixel 10 series

Google has decided to end its long-standing partnership with Qualcomm and instead use MediaTek's T900 modem in the Pixel 10 series.

Perplexitys Social Search Needs These 3 Features to Compete with Google

Perplexitys Social Search Needs These 3 Features to Compete with Google

Perplexity’s regular search engine is great, but its Social Search feature leaves a lot to be desired. Before Perplexity can even think about competing with Google in this area, it needs these new features.

This little change will make accessing your Google passwords much easier!

This little change will make accessing your Google passwords much easier!

While Google's Password Manager is a reliable solution, to access it you have to dig through Chrome's settings.

Geminis Free Version Just Removed a Major Limitation

Geminis Free Version Just Removed a Major Limitation

As one of the most powerful text-to-image AI models, Google's Imagen 3 is already available on Gemini apps, but only to a certain extent.

My deepest and most sincere thanks to my father.

My deepest and most sincere thanks to my father.

Below are the most profound and meaningful words of thanks to father, please refer to them to express your love and care for your father, your beloved father, who has always accompanied and silently sacrificed for his children.

What is an integer? What is a positive integer? What is a negative integer?

What is an integer? What is a positive integer? What is a negative integer?

What is an integer? What is a positive integer? This article will give you the answer.

Instructions on how to draw a diagram in Word

Instructions on how to draw a diagram in Word

Using drawing models in Word content will help readers have a better overview and understanding of the content, as well as increase the liveliness of the content of the article.

How to use Google Gemini Memory

How to use Google Gemini Memory

Gemini can remember things about your life, hobbies, work details, concerns,... thanks to the new Gemini Memory feature.

6 key differences between the Galaxy Z Fold 6 and Z Fold 5

6 key differences between the Galaxy Z Fold 6 and Z Fold 5

The Galaxy Z Fold 6 may not seem like a huge upgrade over the Z Fold 5, but Samsung has improved the hardware and added some nifty features to make for a better experience.

Cerebras makes the worlds largest AI chip with 2.6 trillion transistors and nearly 1 million cores

Cerebras makes the worlds largest AI chip with 2.6 trillion transistors and nearly 1 million cores

Cerebras Systems has unveiled the largest AI chip based on the 7nm process, called Wafer Scale Engine 2.

Tech company teaches computers to... taste wine

Tech company teaches computers to... taste wine

A California tech startup is teaching computers how to taste wine. The company is using the technology to help winemakers improve their products and attract new customers.

Google develops AI algorithm that can diagnose skin diseases and tuberculosis

Google develops AI algorithm that can diagnose skin diseases and tuberculosis

Google has been increasingly showing interest in the field of artificial intelligence applications in medicine.

How to set public Telegram account profile picture

How to set public Telegram account profile picture

If you don't like the avatar with your name's abbreviation, you can set a public Telegram profile picture, hide your Telegram avatar from someone but they can still see your public Telegram profile picture.

7 Useful Changes Microsoft Should Make to File Explorer

7 Useful Changes Microsoft Should Make to File Explorer

File Explorer is still an important part of Windows, and with a few smart updates, Microsoft could improve things even more for users.

The latest Thieu Hiep Xin Dung Buoc game code and how to redeem code for rewards

The latest Thieu Hiep Xin Dung Buoc game code and how to redeem code for rewards

Thieu Hiep Xin Dung Buoc will also help you by giving giftcodes and you can use this code to redeem rewards.

Details of DTCL season 14 champions and skills, gameplay

Details of DTCL season 14 champions and skills, gameplay

Leaving aside all the season 13 champions, we will come to the season 14 champions of Truth Arena: Technology City.

6 Ways to Fix Media Creation Tool Not Working

6 Ways to Fix Media Creation Tool Not Working

The Media Creation Tool allows you to reinstall Windows using a USB or DVD.

Apple updates AirPods Max, making these headphones really worth buying!

Apple updates AirPods Max, making these headphones really worth buying!

The expensive AirPods Max are actually getting better. Apple just announced that both lossless audio and ultra-low latency audio will soon be available on its premium headphones.

Google Maps deletes location history from user accounts due to technical issues

Google Maps deletes location history from user accounts due to technical issues

There's some bad news for Google Maps users. The popular Timeline data, formerly known as Location History, may have been deleted from your account.