Gmail phishing attack: Google blocks scam and rolls out important app update

The company says it blocked the sophisticated exploit in approximately an hour

Aatif Sulleyman
Thursday 04 May 2017 07:27 EDT
Comments
According to Google, the attacker only managed to make off with contact information
According to Google, the attacker only managed to make off with contact information

Your support helps us to tell the story

From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.

At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.

The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.

Your support makes all the difference.

Google has tackled a sophisticated phishing attack designed to trick users into exposing their accounts to cyber criminals.

The web giant says it managed to stop the attack within “approximately one hour”, and claims that fewer than 0.1 per cent of Gmail users were affected.

The scam worked by sending users an invitation to edit an innocent-looking Google Doc, which appeared to have come from a trusted contact.

Clicking it would take you to a Google page prompting users to permit a legitimate-looking service, called Google Docs, to access their email data.

The party behind the attack could then take over an account and distribute the links to even more email addresses.

According to Google, the attacker only managed to steal contact information, and Gmail users don’t need to take any further action to protect themselves.

That said, this isn’t the first convincing Gmail scam we’ve seen over recent months, and users should remain vigilant and only click on links they know to be safe.

It’s also worth visiting Google’s Security Checkup page to review account permissions.

Another Gmail phishing attack spotted in January tricked users by analysing and mimicking their past messages, and using the data to compose convincing emails.

Google has also released a security update for the Android version of its Gmail app, designed to protect users from phishing attacks.

“When you click on a suspicious link in a message, Gmail will show a warning prompt helping you keep your account safe,” the company announced.

The update is being rolled out gradually, and should be available to most users this week.

Join our commenting forum

Join thought-provoking conversations, follow other Independent readers and see their replies

Comments

Thank you for registering

Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in