ZME Science
No Result
View All Result
ZME Science
No Result
View All Result
ZME Science

Home → Science → News

Here’s how to stay safe from the latest phishing scam plaguing Gmail

Stay safe.

Alexandru MicubyAlexandru Micu
January 18, 2017
in News, Tech
A A
Share on FacebookShare on TwitterSubmit to Reddit

A phishing scam that’s so convincing it even fooled experienced technical users is going around on Gmail, trying to get a hold of your login details.

Image credits Gerd Altmann / Pixabay.

It looks like a genuine email one of your friends sent you. There’s even an attachment — something important that he or she is sending you. When you try to download it, you’re taken to a page requesting your log-in credentials. Huh. Must be those wacky Google geeks, always working hard to improve security. You log in.

Congratulations my friend, you’ve just hacked yourself.

How to spot it

The scam is one of the most convincing ever made, and works to trick users into giving up their user credentials, thus allowing the attacker full access to their inbox. It all starts with one email containing a rogue PDF attachment. This message will come from people in your own address book and it’s extremely convincing, even copying their style of writing and to a certain extent, personal touches such as commonly used idioms or smiley faces.

Once you click on the attachment, you will be redirected to a phishing page that looks like the Google sign-in. The scam doesn’t seem to trigger Google’s HTTPS security warnings which usually tell you you’ve reach a shady page. Immediately after you log in, the attackers access your account and use one of your own attachments and subject lines to form a malicious email that is sent to your entire contact list.

A HackerNews user reported on the scam:

“They went into one student’s account, pulled an attachment with an athletic team practice schedule, generated the screenshot, and then paired that with a subject line that was tangentially related, and emailed it to the other members of the athletic team.”

“It may be automated or they may have a team standing by to process accounts as they are compromised.”

Thankfully, Mark Maunder of Wordfence, the company that provides security services for WordPress, discovered the scam.

RelatedPosts

Google to run 100% on renewable energy in 2017
“Zoom in. Now… enhance.” Well, Google just turned this old TV trick into reality
Google Maps adds COVID-19 layer to alert about cases
Apple and Google ban GPS tracking in contact-tracing apps

“Once they have access to your account, the attacker also has full access to all your emails including sent and received at this point and may download the whole lot,” he wrote on Wordfence.

“Now that they control your email address, they could also compromise a wide variety of other services that you use by using the password reset mechanism including other email accounts, any SaaS services you use and much more.”

How not to be phished

Maunder recommends enabling two-factor authentication for your account so no one else can access it even if your credentials are compromised. He also says you should keep an eye out for “data:text/html” in the browser location bar, as it’s a clear sign of a fake page.

“You should also take special note of the green colour and lock symbol that appears on the left. If you can’t verify the protocol and verify the hostname, stop and consider what you just clicked on to get to that sign-in page.”

Tags: EmailgmailGooglePhishing

ShareTweetShare
Alexandru Micu

Alexandru Micu

Stunningly charming pun connoisseur, I have been fascinated by the world around me since I first laid eyes on it. Always curious, I'm just having a little fun with some very serious science.

Related Posts

blocky image of minecraft
Future

An AI Called Dreamer Learned to Mine Diamonds in Minecraft — Without Being Taught

byTudor Tarita
4 weeks ago
Future

Google Trends data can predict football player’s market value

byFermin Koop
2 years ago
Computer Science & IT

What is a Chromebook and why you might love one

byAlexandra Gerea
2 years ago
Health

Google says it will delete abortion clinic visits from users’ history — and it’s really sad they have to do this

byMihai Andrei
3 years ago

Tesla’s Sales in Europe Are Plummeting Because of Elon Musk’s Borderline Fascist Politics

May 7, 2025

How dogs and cats are evolving to look alike and why it’s humans’ fault

May 6, 2025

Mathematicians Just Solved a 125-Year-Old Problem That Unites Three Major Theories of Physics

May 6, 2025
  • About
  • Advertise
  • Editorial Policy
  • Privacy Policy and Terms of Use
  • How we review products
  • Contact

© 2007-2025 ZME Science - Not exactly rocket science. All Rights Reserved.

No Result
View All Result
  • Science News
  • Environment
  • Health
  • Space
  • Future
  • Features
    • Natural Sciences
    • Physics
      • Matter and Energy
      • Quantum Mechanics
      • Thermodynamics
    • Chemistry
      • Periodic Table
      • Applied Chemistry
      • Materials
      • Physical Chemistry
    • Biology
      • Anatomy
      • Biochemistry
      • Ecology
      • Genetics
      • Microbiology
      • Plants and Fungi
    • Geology and Paleontology
      • Planet Earth
      • Earth Dynamics
      • Rocks and Minerals
      • Volcanoes
      • Dinosaurs
      • Fossils
    • Animals
      • Mammals
      • Birds
      • Fish
      • Amphibians
      • Reptiles
      • Invertebrates
      • Pets
      • Conservation
      • Animal facts
    • Climate and Weather
      • Climate change
      • Weather and atmosphere
    • Health
      • Drugs
      • Diseases and Conditions
      • Human Body
      • Mind and Brain
      • Food and Nutrition
      • Wellness
    • History and Humanities
      • Anthropology
      • Archaeology
      • History
      • Economics
      • People
      • Sociology
    • Space & Astronomy
      • The Solar System
      • Sun
      • The Moon
      • Planets
      • Asteroids, meteors & comets
      • Astronomy
      • Astrophysics
      • Cosmology
      • Exoplanets & Alien Life
      • Spaceflight and Exploration
    • Technology
      • Computer Science & IT
      • Engineering
      • Inventions
      • Sustainability
      • Renewable Energy
      • Green Living
    • Culture
    • Resources
  • Videos
  • Reviews
  • About Us
    • About
    • The Team
    • Advertise
    • Contribute
    • Editorial policy
    • Privacy Policy
    • Contact

© 2007-2025 ZME Science - Not exactly rocket science. All Rights Reserved.