Breaking
February 3, 2025

Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen | usagoldmines.com


  • A new phishing scam has targeted a Google programmer
  • The attack was worryingly convincing, and has made Google tighten defenses in response
  • Not sure how to spot a phishing scam? Follow our tips

A new ultra-realistic phishing scam reported by a Google programmer could make a lot of us a little uneasy.

Zach Latta, warned in a recent blog post, “Someone just tried the most sophisticated phishing attack I’ve ever seen. I almost fell for it. My mind is a little blown.”

Starting with a phone call from the Caller ID ‘Google’, this phishing attempt was enough to convince a Google programmer into being one button press away from disaster – here’s what we know so far.

A convincing story

On the other side of Latta’s phone call, which is a genuine number associated with Google Assistant calls, was a ‘Google engineer’ called Chloe.

The connection was ‘super clear’, with Latta noting the scammer had an American accent, and claimed to be from Google Workspace – asking if he had recently attempted to log into his account from Frankfurt, Germany.

From there, the programmer asked if ‘Chloe’ could confirm this by emailing from an official Google email. Worryingly, the scammer obliged, and sent Latta an incredibly official looking email with a case number.

Not only was the email sent, but it was sent from the address ‘workspace-noreply@ google.com’, and related to his ‘password for important.g.co’ which the attacker claimed was an internal Google subnet. This is important, because even our own TechRadar phishing advice identifies this as a serious indication of risk.

But g.co is an official Google URL – which is confirmed by Google and even has its own Wikipedia page. Latta, being a tech worker, knew to verify the phone number, so Googled the number – and was encouraged to do so by the scammer, who advised him to quote his case number if he called. The number is listed on google.com pages, which was enough to placate Latta enough.

The scammer was encouraging Latta to carry out a ‘sessions reset’, on his device, which rang alarm bells for the programmer. The scam’s first stumbling block came when Latta checked his Google Workspace logs himself, and of course, didn’t find any suspicious activity.

When pressed, the scam began to unravel – with the attacker transferring to a manager who further encouraged Latta to log out from all devices and reset his password. Shockingly, the scammer was able to provide the genuine MFA code that was sent to Latta, which, if entered, would’ve given the attackers access to Latta’s account.

Thankfully, Latta was able to spot the red flags and by this point, was already suspicious enough to avoid handing his account over – but the scammer got close, Latta admitted.

“Literally 1 button press from being completely pwned. And I’m pretty technical!”

This particular attack has made Google up its defenses in response.

“We’ve suspended the account behind this scam, which abused an unverified Workspace account to send these misleading emails” a Google spokesperson told TechRadarPro.

“We have not seen evidence that this is a wide scale tactic, but we are hardening our defenses against abusers leveraging g.co references at sign up to further protect users.”

Google also reiterated: “Google will not call you to reset your password or troubleshoot account issues.”

The news follows a trend of cybercriminals deploying smarter and more frequent attacks, in part enabled by the advent of AI. This particular scam even bypassed MFA and used a legitimate Google domain, so even the most tech-savvy among us should be on the lookout.

Escaping phishing attacks

What’s concerning about this scam in particular is that it has found workarounds for some of the classic tell-tale signs of a scam. As Latta said,

“The thing that’s crazy is that if I followed the 2 “best practices” of verifying the phone number + getting them to send an email to you from a legit domain, I would have been compromised.”

Checking the legitimacy of the email and phone number is pretty much the first recommendation for any unexpected communications – and that’s still good advice, but clearly it will only filter out the lower level attacks at this point. If you’re not sure what exactly a phishing attack is, we’ve put together an explainer.

That said, remaining suspicious of any and all unknown communications, especially those urging action, really is the best defense against phishing attacks.

In the kindest way possible, it’s unlikely you’re important enough for Google to be concerned enough to call you about your personal email account – so be very wary of anyone reaching out to you out of nowhere.

A Google spokesperson told TheRegister, “As a reminder, Google will not call users to reset their passwords or troubleshoot account issues, so feel free to treat any incoming calls as the garbage they are.”

Look out for any obvious markers, like bad spelling or grammar – and be mindful of which organizations would already know your name – it’s unlikely your bank would start an email with ‘Dear customer’.

Alongside that, avoid clicking any links on emails from people you don’t know, and don’t open attachments or scan QR codes either. If you’d like more detail, take a look at our full phishing defense and how to stop it.

Another layer of defense against scams, is using the best identity theft protection, which can help if you do accidentally click the wrong thing.

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

ChatGPT’s advanced AI costs $200/mo. It’s now free for Windows users | usagoldmines.com

Best PC computer deals: Top picks from desktops to all-in-ones | usagoldmines.com

Best VPN deals: Protect your privacy for the lowest prices | usagoldmines.com

Severance season 2 episode 3 recap: The baby goats return! lucy.buglass@futurenet.com (Lucy Buglass)...

An Nvidia GeForce RTX 5090 with 96GB of GDDR7 memory? No, this is almost certainly the RTX 6000 Blac...

Forget the RTX 5090 – the RTX 5070 is the best gift Nvidia has given PC gamers in ages christian.guy...

AppleCare+ Policy Change Coming to Apple Stores Joe Rossignol | usagoldmines.com

Get Apple Watch SE for Just $169 During Amazon's Weekend Sale Mitchel Broussard | usagoldmines.com

Amazon Takes $299 Off Apple Studio Display, Available From $1,299.99 Mitchel Broussard | usagoldmine...

AirPods 4 Hit New $99.99 Low Price on Amazon, Plus Big Discounts on ANC Model and AirPods Pro 2 Mitc...

Apple May Launch New iCloud Feature Codenamed 'Confetti' This Week Joe Rossignol | usagoldmines.com

The OnePlus Open 2 rumored to get a camera upgrade even the Samsung Galaxy S25 Ultra doesn't have |...

Apple Expected to Announce Powerbeats Pro 2 on February 11 With These New Features Joe Rossignol | u...

Everything new on Apple TV Plus in February 2025: The Gorge, Surface season 2, and more tom.power@fu...

NYT Strands hints and answers for Monday, February 3 (game #337) | usagoldmines.com

Quordle hints and answers for Monday, February 3 (game #1106) | usagoldmines.com

NYT Connections hints and answers for Monday, February 3 (game #603) | usagoldmines.com

Apple is rumored to have taken another key step towards making a foldable iPhone | usagoldmines.com

Canon compact cameras tipped for a big return with rumored Powershot V1 – and I think that's Canon's...

Eat this, Raspberry Pi 5: Here are 3 powerful AMD Ryzen Mini PCs that sell for under $180 and trounc...

I can’t stop rewatching this dark Australian comedy drama series on Disney Plus that hardly anyone k...

Ditch Microsoft 365’s recent price hike for its lifetime counterpart | usagoldmines.com

Mine's bigger than yours: Mysterious hyperscaler plans to build Europe's largest cloud and AI data c...

Quordle today – my hints and answers for Sunday, February 2 (game #1105) | usagoldmines.com

NYT Strands today — my hints, answers and spangram for Sunday, February 2 (game #336) | usagoldmine...

NYT Connections today — my hints and answers for Sunday, February 2 (game #602) | usagoldmines.com

It seems the FAA office overseeing SpaceX’s Starship probe still has some bite Stephen Clark | usago...

India's richest person wants to build the world's largest data center, five times the capacity of Mi...

OpenAI responds to the DeepSeek buzz by launching its latest o3-mini reasoning model for all users ...

What does a $2500 GPU get you? Let’s check out MSI’s liquid-cooled RTX 5090 | usagoldmines.com

Sonos Offers Up to 25% Off Home Theater Audio Equipment Ahead of Super Bowl Mitchel Broussard | usag...

The Samsung Galaxy S25 Edge could mark a new era for smartphones – but I hope Samsung gets the balan...

Top Stories: iOS 18.3 Released, AirPods News, and More MacRumors Staff | usagoldmines.com

Everything new on Disney Plus in February 2025: Pixar's Win or Lose, A Thousand Blows, and more tom....

Nvidia giving away free AI courses worth up to $90 and no, it's got nothing to do with DeepSeek's as...

We may have a name for the upcoming Samsung tri-fold phone | usagoldmines.com

To help AIs understand the world, researchers put them in a robot Jacek Krywko | usagoldmines.com

Your streaming videos and brand new 4K TV are to blame for surging global CO2 emission, experts say ...

Rivian says it will offer hands-off autonomous driving later this year, with eyes-off coming in 2026...

Samsung’s Galaxy S25 Ultra brings in the camera upgrade I’ve been waiting for – Apple should be taki...

Squid Game season 3: what we know so far about the hit Netflix show's return | usagoldmines.com

Windows 11 Pro unlocks surprising benefits for PC gamers | usagoldmines.com

Stop annoying ads from ruining your internet experience | usagoldmines.com

ICYMI: the week's 7 biggest tech stories from DeepSeek rocking the AI world to Garmin's major outage...

$2000 Nvidia Geforce RTX 5090 gets tested on creative software and AI and obliterates absolutely eve...

Squarespace's 2025 Super Bowl ad features Saltburn star and a donkey, in a pub | usagoldmines.com

Only two weeks in and AI phenomenon DeepSeek is officially growing faster than ChatGPT luke.hughes@f...

I used the OpenAI Operator rival Browser Use and it's impressive, but takes some technical skill to ...

This Experimental Google Feature Lets You Send Robocalls to Local Businesses Michelle Ehrhardt | usa...

How to Claim Your Piece of Apple's $20 Million Watch Settlement Michelle Ehrhardt | usagoldmines.com

This tiny 2TB microSD card is at its lowest price ever, and Newegg is even willing to take an offer ...

NYT Strands today — my hints, answers and spangram for Saturday, February 1 (game #335) | usagoldmi...

NYT Connections today — my hints and answers for Saturday, February 1 (game #601) | usagoldmines.co...

Quordle today – my hints and answers for Saturday, February 1 (game #1104) | usagoldmines.com

Another Healthcare Data Breach Compromised a Million Patients' Information Emily Long | usagoldmines...

OpenAI Launches o3-mini, a Cost-Efficient Reasoning Model Rivaling DeepSeek Juli Clover | usagoldmin...

I got a first look at the new Lego flower sets in a botanical garden, and the Mini Orchid should be ...

FDA approves first non-opioid pain medicine in more than 20 years Beth Mole | usagoldmines.com

uBlock Origin is dead for Chrome, but its successor still lives on | usagoldmines.com

OpenAI's Newest Reasoning Model Is Rolling Out Jake Peterson | usagoldmines.com

This Chrome Extension Hides Google's AI Junk Pranay Parab | usagoldmines.com

Google Pixel 4a’s ruinous “Battery Performance” update is a bewildering mess Kevin Purdy | usagoldmi...

FCC demands CBS provide unedited transcript of Kamala Harris interview Jon Brodkin | usagoldmines.co...

This Free Browser Extension Lets You Bookmark Bluesky Posts Pranay Parab | usagoldmines.com

10 Movies About Architects to Watch After ‘The Brutalist’ and ‘Megalopolis’ Ross Johnson | usagoldmi...

Report: Apple is stopping work on a pair of smart glasses that would have connected to the Mac jacob...

5G connectivity on your smart ring or Meta's future Ray-Bans? This eSIM solution smaller than a grai...

How I save big money on streaming services: Ruthless disloyalty | usagoldmines.com

What's New on Prime Video in February 2025 Emily Long | usagoldmines.com

The Best Game Day Snacks You Can Make in the Air Fryer Allie Chanthorn Reinmann | usagoldmines.com

Apple Cancels Mac-Connected AR Smart Glasses Juli Clover | usagoldmines.com

Tesla promises more affordable EVs and could start its Robotaxi service in June – but I've heard th...

OpenAI hits back at DeepSeek with o3-mini reasoning model Kyle Orland | usagoldmines.com

Amazon hiked Music Unlimited prices. Here’s why Apple and YouTube are next | usagoldmines.com

T-Mobile Starlink Sent Out a Lot of Invites to Pixel 9 Owners Kellen | usagoldmines.com

The 'Now Bar' Is Samsung's Take on iOS' Live Activities David Nield | usagoldmines.com

A look at the unbelievable Nvidia GPU that powers DeepSeek's AI global ambition waynewilliams@onmail...

A new Chrome browser highjacking attack could affect billions of users - here's how to fight it alli...

Amazon Music Unlimited just got a price hike – giving you no reason to choose it over Spotify or App...

Aosu SolarCam P1 SE System review: A budget-priced winner | usagoldmines.com

Microsoft’s latest AI feature may just stop working. Here’s why | usagoldmines.com

How to Mute Words and Phrases on Your Bluesky Feed Khamosh Pathak | usagoldmines.com

These Sennheiser Earbuds Are at Their Lowest Price Right Now Pradershika Sharma | usagoldmines.com

Apple Wants to Help Google Defend Search Engine Deal Worth Billions Juli Clover | usagoldmines.com

Best Apple Deals of the Week: Apple Watch Series 10 Hits Record Low $329 Price, Plus Savings on MacB...

Dell risks employee retention by forcing all teams back into offices full-time Scharon Harding | usa...

Buoy meets satellite soulmate in Love Me Jennifer Ouellette | usagoldmines.com

Musk’s DOGE clashes with Treasury over access to payment system, report says Jon Brodkin | usagoldmi...

Best gaming laptops under $1,000: Expert picks that won’t break the bank | usagoldmines.com

Yes, you can still use floppy disks with Windows 11! Here’s how | usagoldmines.com

This compact OLED gaming laptop with RTX 4060 is $500 off today | usagoldmines.com

Best gaming laptops 2025: What to look for and highest-rated models | usagoldmines.com

Pre-Orders Did Arrive Early, But Galaxy S25 Ultra Still $900 Off With Free Storage Upgrade Kellen | ...

I Can’t Get Enough of This One-Pot Crispy Chicken and Rice Dish Allie Chanthorn Reinmann | usagoldmi...

The Aventon Pace 500.3 E-Bike Is Beginner Friendly but High Performing Stephen Johnson | usagoldmine...

The MacRumors Show: Latest iPhone SE 4 Rumors Hartley Charlton | usagoldmines.com

You Can Now Read 'The You You Are' Book From Apple TV+ Show Severance Juli Clover | usagoldmines.com

Nvidia's DLSS 4 is amazing – here's what AMD's FSR 4 needs to do to take it on | usagoldmines.com

Over 2 million risky Android apps were blocked from the Play Store last year | usagoldmines.com

Kate Hudson really does look like the new Ted Lasso in Netflix’s trailer for sports comedy series Ru...

Leave a Reply