Skip to main content

Google account phishing scam hooks users with fake Google Drive login

google account phishing scam hooks users fake drive login
Image used with permission by copyright holder

There’s a really deceptive phishing scam going around that tricks users into giving hackers their Google login credentials using a script hiding in a Google Drive document. The scheme raised some eyebrows at security firm Symantec, who discovered and reported the scam on their official blog.

The scammers send out emails simply titled “documents,” which asks the reader to open an “important document.” Clicking on the link brings up a Google account sign-in page, and though it looks legitimate, it’s anything but. The official-looking login page is actually a preview page for a folder storing the phishing scam on Google Drive. Once the user signs in, a PHP script records their login info. Since the site is stored on Google Drive, the page address says “Google.com,” allowing it to pass a surface-level inspection. When it’s all over, the link sends the user to an actual document, reducing the chance that the user realizes what just happened.

googlelogin
Image used with permission by copyright holder

 Once the perpetrators have your Google login information, obviously anything stored on your accounts is compromised and could be stolen. If you feel that you’ve fallen victim to this scam, we recommend that you change your account password immediately. Refraining from opening links from unfamiliar email addresses could also help you go a long way towards avoiding such pitfalls.

Mike Epstein
Former Digital Trends Contributor
Michael is a New York-based tech and culture reporter, and a graduate of Northwestwern University’s Medill School of…
Google backtracks on controversial changes to Google Drive
Google Drive in Chrome on a MacBook.

Google had quietly established a file creation limit on Drive that capped the number of files you could create per account at 5 million.

After receiving some negative feedback about the changes on Reddit, the company posted on Twitter that it has since retracted the change to "explore alternative approaches."

Read more
Amazon shoppers warned of portable SSD drive scam
An ad for a product on Amazon.

Shoppers are being warned to be wary of items on Amazon that claim to show 16TB portable storage drives for $100 or less.

With his suspicions raised by the low price and obscurely named companies that sold the devices, Review Geek editor-in-chief Josh Hendrickson decided to take a closer look.

Read more
Hackers target your holiday shopping with new phishing scam
Woman using a laptop next to a latte.

It's easy to get fooled by this new and devious, holiday-themed phishing attack that offers free prizes. But the old caution that “if it sounds too good to be true, it probably is” continues to be proven correct in this case.

What makes this trick so effective is the elaborate methods used to conceal its nefarious purpose and to reassure you, the potential victim, that it’s perfectly OK to proceed. This phishing attack has actually been active since September and is ongoing, targeting holiday shoppers seeking special offers.

Read more