Just encountered one of the most convincing Google account takeover scams Iโve seen.
Perfect American accent. Calm. Professional.
They start the call by saying someone tried to hack your Google account using a fake death certificate, then ask if you recognize a recovery email or phone number.
They ask if youโve received any recent Google emails about an account you donโt recognize trying to recover access.
And sure enough, thereโs a legit Google security email.
Hereโs the trick.
The attacker isnโt trying to hack your account.
They create a throwaway Google account, set your email as the recovery email, then try to recover that account. Google sends you a real security email.
The scammer calls you live, references the email, and even tells you to verify the headers since it comes directly from Google.
The headers are real. Thatโs the point.
Then they tell you theyโre locking down your account and that youโll get a recovery prompt on your phone. You just need to approve it to stay safe.
The giveaway was the device and location in the prompt didnโt match me. When I pushed back, they claimed it was from their servers, which obviously makes no sense.
At that point I hung up. I have a personal rule to never approve anything I didnโt initiate, especially while on the phone.
Extremely well executed social engineering. Iโm sure this works on a lot of people.
And if someone calls you about account security, assume itโs a scam