Categories: CyberCrimeSecurity

‘Highly Effective’ Phishing Scam Steals Gmail Login Details

A highly effective phishing attack is targeting Gmail users and attempting to steal login credentials, according to Mark Maunder, founder and CEO of WordPress security plugin Wordfence.

The attack works by the hacker first sending an email to your Gmail account, most likely from someone you know who has already had their account hacked, containing what looks like an image attachment.

Instead of showing a preview, clicking on the image opens a separate fully-functional yet fake Gmail page prompting you to sign in again which, if you do so, gives the attacker full access to your account.

Scam

Gmail scam

“The attackers signing into your account happens very quickly,” writes Maunder. “It may be automated or they may have a team standing by to process accounts as they are compromised.

“Once they have access to your account, the attacker also has full access to all your emails including sent and received at this point and may download the whole lot.”

Once logged in, the hacker will use an actual attachment from your email history, along with an actual subject line and send it on to people in your contact list. This of course will appear totally normal to the next set of unsuspecting victims, which is why phishing attacks such as this one generally have such high success rates.

To protect yourself against this attack, Mauder advises users to always check that the location bar in your browser starts with ‘https://…’ rather than anything else, something which has caught out several technical users in this attack specifically.

Furthermore, checking that only the green lock symbol and ‘https://’ appear before the hostname ‘accounts.google.com’ and enabling two-factor authentication will also help to defend against the phishing scam.

Mauder contacted Google for comment on the matter and received the following statement: “We’re aware of this issue and continue to strengthen our defenses against it. We help protect users from phishing attacks in a variety of ways, including: machine learning based detection of phishing messages, Safe Browsing warnings that notify users of dangerous links in emails and browsers, preventing suspicious account sign-ins, and more. Users can also activate two-step verification for additional account protection.”

The spokesman also indicated that there will be updates included in future releases of Chrome and Gmail to help defend against this type of attack.

Phishing attacks were all the rage in 2016 and, with reports of new scams targeting the likes of Netflix and McDonald’s emerging with worrying regularity, the trend looks set to continue in 2017.

Quiz: Test your cyber security mettle right here!

Sam Pudwell

Sam Pudwell joined Silicon UK as a reporter in December 2016. As well as being the resident Cloud aficionado, he covers areas such as cyber security, government IT and sports technology, with the aim of going to as many events as possible.

Recent Posts

Napster Sold And Will Return As Interactive Streaming Service

New chapter for famous name from Internet's early days, Napster, has been acquired and will…

10 hours ago

UK Proposes To Allow Satellites To Resolve UK Mobile Not-Spots

Solving not-spots? Ofcom proposal to make UK the first European country to allow ordinary smartphones…

11 hours ago

Waymo Confirms Washington DC Robotaxi Plan For 2026

Pioneering robotaxi service from Alphabet's Waymo to go live in Washington DC next year, as…

12 hours ago

US Adds 50 Chinese Firms To AI, Chip Blacklist

Dozens of Chinese firms added to US export blacklist, in order to hamper Beijing's AI…

14 hours ago

Tesla Europe Sales Plummet, As Owners Return EVs At Record Levels

Chinese rival BYD overtakes global revenues of Elon Musk's Tesla, as record number of Tesla…

16 hours ago

Signal App In Spotlight Amid Secret Chat Controversy Of US Officials

Messaging app Signal in the headlines after a journalist was invited to a top secret…

18 hours ago