A sophisticated phishing attack is Eng Subracing across the internet, and may already have hit your inbox.
The definitely not-legit email disguises itself as an official message from Google alerting you that someone wants to share a Google Doc with you. Notifications of this sort are common and often wouldn't raise an eyebrow.
However, clicking through this particular link and taking the requested steps will open up your inbox — and potentially everyone on your contact list — to an as-of-yet unknown attacker.
This Tweet is currently unavailable. It might be loading or has been removed.
And, like we said, the link looks real — complete with a little "Open in Docs" blue box.
This Tweet is currently unavailable. It might be loading or has been removed.
Just how widespread is this? Numerous reporters at Mashable have received the same phishing email, as have students at Columbia University— as a warning email sent out by a member of the Philosophy department shows. The scam may have even hit the Capitol.
This Tweet is currently unavailable. It might be loading or has been removed.
Google confirmed that it is aware of the problem and is looking into it.
According to one Reddit user, once a victim clicks on the fake Google Doc link, he or she is taken to a real Google page prompting you to select an account. After that, they are taken to a new page asking that they allow "Google Docs" to access the account.
If you click "allow," the attacker can access your account. And all your contacts will likely soon receive a fake Google Doc invite from you.
So, how to tell if that latest Google Doc your friend shared is real or fake? Thankfully, there are a few tell-tale warning signs. First, real Google Doc invites look different than the recent fake. Here's a legit one for comparison:
Notice the Google address at the bottom? And the box border formatting? The fake Google notification doesn't have that.
Second, expand the dropdown option in the menu bar next to the sender's name. Below is a real Google notification for a shared Google Doc.
Lastly, the spam email is also addressed to "[email protected]," which is an account with the disposable email service Mailinator.
If you did happen to click on the malicious link and allowed attackers into your account, you can revoke that access relatively easily. First, go to your Google permissions page. There you will find a list of all the apps that have account access. One app, titled Google Docs, is the offender. Revoke its permission immediately, and then change your password.
This Tweet is currently unavailable. It might be loading or has been removed.
So now that you know what's up, pay extra attention to any Google Docs coming your way. And, well, to anything asking you to click a link and enter your password or share account permission.
Topics Cybersecurity Google
Fox News actually runs a poll showing how little people trust themIdentifying a lower‘Mean Girls’ on Broadway is fun and fetch: ReviewThis is what Meryl Streep's character will look like in 'Big Little Lies 2'I'm an LA native, and I couldn't bring myself to hate Bird eDespite Bitcoin's volatility, these companies say it's the way to goThe best part of Mark Zuckerberg appearing in front of Congress was the memesHere's why JayYouTube accused of violating child privacy law that killed 'Silicon Valley' chat appEveryone is terrified to eat popcorn during 'A Quiet Place'Elon Musk warns that AI could become an 'immortal dictator'Apple launches red iPhone 8 and 8 PlusDemolition of silo goes wrong way, accidentally falling on libraryThis surreal AI creature meets humans, then decides whether it wants to play with themThere's a glaring weakness in electric vehicles. (It's range anxiety.)Netflix's 'Wild Wild Country' is insanely grippingIndian officials deal blow to cryptocurrenciesEvery hidden detail you missed from new horror hit 'A Quiet Place'There's a glaring weakness in electric vehicles. (It's range anxiety.)Apple's revamped Mac Pro won't launch until 2019, but that's OK Best smartwatch deal: Save up to 24% on watches from Apple, Garmin, and Samsung New York Liberty vs. Dallas Wings 2024 livestream: Watch WNBA for free Discover Samsung Fall Sale: All of the best live deals Watch SpaceX's Polaris Dawn mission conduct the first all Apple iOS 18 release date today: When you can download it Bournemouth vs. Chelsea 2024 livestream: Watch Premier League for free NYT mini crossword answers for September 14 Dolphins vs. Bills 2024 livestream: How to watch NFL for free Wordle today: The answer and hints for September 15 Broncos vs. Steelers 2024 livestream: How to watch NFL for free NYT mini crossword answers for September 16 There's a record number of humans in space right now, NASA announces SpaceX shows views of the first private spacewalk on Polaris Dawn mission Meet o1: OpenAI's advanced reasoning 'Strawberry' model Taylor Swift's voter registration link saw over 337,000 visitors NYT mini crossword answers for September 12 NYT mini crossword answers for September 13 Apple's iPhone 16 Pro: Replacing the battery is a lot pricier than before Elon Musk 'jokes' about President Biden and Kamala Harris assassination on X Scientists are collecting pee from SpaceX travelers. There's a good reason.