‼️‼️‼️ New
#scam scheme: a fake email from Google that looks like the real thing
Jameson Lopp, the founder of the crypto company Casa, personally encountered this attack and warned his subscribers.
• Scammers use the real
#Google form to request account recovery
• They insert a long message with a phishing link into this form, which is sent to the victim via email
• The email looks like a real notification from Google. The fake link is at the top, and the real Google elements are hidden at the bottom after several pages of empty space
• The first screenshot shows a fake email with a fake link. The second shows what the real Google notification looks like at the bottom of the same email
• If you click on the link and enter your data, the scammers will gain access to
#Gmail,
#exchanges, password managers,
#cryptowallets, and two-factor authentication
The rule is simple: never click on links in emails. If you receive a suspicious notification, open Google directly through your browser and check your account settings
Tricky new phishing technique someone just tried on me: abusing an actual google recovery contact request form and stuffing it with a really long message that contains a phishing link. The true message is shoved after several pages of blank space at the bottom.