Has Someone Randomly Shared A Google Doc With You? Beware, It Might Be A Phishing Attack

Alphabet Inc (GOOGL.O) warned its users to beware of emails from known contacts asking them to click on a link to Google Docs after a large number of people turned to social media to complain that their accounts had been hacked.

Google said on Wednesday that it had taken steps to protect users from the attacks by disabling offending accounts and removing malicious pages.

b’Google said its abuse team “is working to prevent this kind of spoofing from happening again.” | Source: Reuters’

The attack used a relatively novel approach to phishing, a hacking technique designed to trick users into giving away sensitive information, by gaining access to user accounts without needing to obtain their passwords. They did that by getting an already logged-in user to grant access to a malicious application posing as Google Docs.

“This is the future of phishing,” said Aaron Higbee, chief technology officer at PhishMe Inc. “It gets attackers to their goal … without having to go through the pain of putting malware on a device.”

He said the hackers had also pointed some users to another site, since taken down, that sought to capture their passwords.

b’Anybody who granted access to the malicious app unknowingly also gave hackers access to their Google account data including emails, contacts and online documents, according to security experts who reviewed the scheme. | Source: Reuters’

Google said its abuse team “is working to prevent this kind of spoofing from happening again.”

Anybody who granted access to the malicious app unknowingly also gave hackers access to their Google account data including emails, contacts and online documents, according to security experts who reviewed the scheme.

“This is a very serious situation for anybody who is infected because the victims have their accounts controlled by a malicious party,” said Justin Cappos, a cyber security professor at NYU Tandon School of Engineering.

b’The attack used a relatively novel approach to phishing, a hacking technique designed to trick users into giving away sensitive information, by gaining access to user accounts without needing to obtain their passwords. | Source: Reutersxc2xa0′

Cappos said he received seven of those malicious emails in three hours on Wednesday afternoon, an indication that the hackers were using an automated system to perpetuate the attacks.

He said he did not know the objective, but noted that compromised accounts could be used to reset passwords for online banking accounts or provide access to sensitive financial and personal data.

(Feature image source: Reuters)

You might also like
Delhi Air Pollution: Stage IV Curbs to Now Apply at Stage III Under New GRAP Rejig — Full List of Restrictions
Seven Maoists Killed in Andhra Pradesh Encounter a Day After Madvi Hidma’s Elimination
Delhi Air Quality Deteriorates to ‘Severe’; Construction Halted, Schools Shift to Hybrid Mode up to Class 5
Dare. Drop. Win. The Creator Rebellion Rides With Pulsar Underground
Snabbit Bags $30Mn in Third Fundraise This Year, Clocks Over 3 Lakh Jobs in October
₹1.2 Crore Delhi Cloud Seeding Trial Fails to Produce Artificial Rain; AAP Takes ‘Lord Indra’ Dig