- Office of Consumer Affairs and Business Regulation
The unusual worm that landed in the mailboxes of Google’s Gmail users last week was a sophisticated identity phishing scam that quickly spread to various other contacts. Scammers were able to get users to open a malicious link using one the oldest tricks in the scamming playbook: sending it through an email from an existing contact. The email, which was very authentic looking, appeared to be a GoogleDocs link that your trusted contact wanted to share with the recipient.
Google acted quickly, deactivating the fake accounts and warning users via social media, still the malware spread quickly. Users who opened the link authorized a legit-looking app called “Google Docs” to manage your emails. The app, which isn’t associated with Google, gave scammers access to Gmail accounts. The link was then emailed to contacts. But what’s worse is that scammers could now potentially access anything linked to that account, giving them the opportunity to gather personal information, reset passwords, or take over Facebook or online bank accounts.
Tips for Gmail users:
- Look at the email address of the sender. Many scam-savvy users opened the address field and discovered the email was sent from an account ending in malinator.com. That’s a sure sign it’s a fake.
- Sign-up for two-factor verification.
- Take the time to change your Google password.
- Google recommends that users do the Google Security Checkup. This will allow you to check your settings and activity, as well as show you the apps you have approved. If you downloaded the fake app, be sure to delete it immediately.
- Activate spam filters. They are designed to detect and block emails sent from abnormal or faulty addresses. If you see that an apparently important message has been filtered as spam, check it carefully to ensure it is not from a spoof email address.
- When in doubt, ask the sender if they emailed a link. If they didn’t, delete it and report it to Google.
Google also maintains a list of common scams related to their business. Read about them here.