Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    RJD urges PM Modi to convene special session of Parliament

    May 10, 2025

    CG Crime: Body trade busted, three women in police custody

    May 10, 2025

    IndiGo Offers Free Rebooking, Relief Flights For Stranded Passengers Amid Airport Closures |

    May 10, 2025
    Facebook X (Twitter) Instagram
    News Analysis India
    Facebook X (Twitter) Instagram
    Member Login
    • World
    • India
    • States
      • Chhattisgarh
      • Madhya Pradesh
    • Politics
    • Sports
    • Technology
    • Entertainment
    • Articles
    News Analysis India
    Home»Technology»Warning for Gmail Users: New Scam Uses Google Subdomains To Steal Login Details — How To Stay Safe |
    Technology

    Warning for Gmail Users: New Scam Uses Google Subdomains To Steal Login Details — How To Stay Safe |

    News Analysis IndiaBy News Analysis IndiaApril 21, 20253 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Copy Link Email
    Follow Us
    Google News Flipboard
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Google Gmail Scam: Beware Gmail Users! Tech giant Google has issued an important warning to all Gmail users. This warning has come following the discovery of a highly sophisticated phishing campaign that exploits Google’s own security checks to trick users into handing over their account credentials.  

    This phishing attack is dangerous because it appears to come from Google itself and even shows up in the same email thread as real and genuine alerts from Google. However, Google has acknowledged the phishing campaign and confirmed that it exploited OAuth and DKIM mechanisms in a novel way.  

    Recently I was targeted by an extremely sophisticated phishing attack, and I want to highlight it here. It exploits a vulnerability in Google’s infrastructure, and given their refusal to fix it, we’re likely to see it a lot more. Here’s the email I got: pic.twitter.com/tScmxj3um6
    — nick.eth (@nicksdjohnson) April 16, 2025

    Google Email Look Real? 

    The scam was initially discovered by software developer Nick Johnson, who detailed his experience on X (formerly Twitter). He received an email from no-reply@google.com, stating that a subpoena had been issued for his account data. The email appeared legitimate and contained a link resembling a genuine Google support page.  

    However, the link redirected to a fake Google sign-in page hosted on sites.google.com—Google’s own platform. The aim was to deceive users into entering their login credentials, allowing hackers to steal their Gmail account information. It is important to note that the phishing email uses the company’s branding, has the correct logo, and includes language that sounds official. 

    How Google Email Scam Works? 

    Step 1: You get an official-looking email from no-reply@google.com, claiming a subpoena has been issued against your account. 

    Step 2: The email includes a link that appears to lead to a legitimate Google support page, urging you to log in to respond. 

    Step 3: The link takes you to a cloned Google login page, hosted on a Google subdomain (like sites.google.com), making it look authentic. 

    Step 4: Once you enter your login details, they’re captured by hackers—giving them full access to your Gmail and all connected Google services. 

    How Can Gmail Users Stay Safe From Scam? 

    Step 1: Don’t trust unexpected emails asking you to take urgent action, even if they appear to come from Google or other trusted sources. 

    Step 2: Avoid clicking on links within such emails. These links may lead to fake login pages designed to steal your credentials.

    Step 3: Always visit your Gmail or any other service by typing the official URL (like www.google.com) directly into your browser. 

    Step 4: Add an extra layer of security to your account by enabling 2FA, which requires a second verification step beyond just your password. 

    Step 5: Activate passkeys wherever supported to further protect your account from phishing and credential theft. 

    Gmail Gmail Users Google Google Email Google emails Google Sign In
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Telegram Email Copy Link

    Related Posts

    Operation Sindoor: IT Ministry Shares Do’s And Don’ts For Internet Users Amid India-Pakistan Tensions |

    By News Analysis IndiaMay 10, 2025

    India-Pakistan Tensions: Must-Have Safety Apps And Websites For Every Indian |

    By News Analysis IndiaMay 10, 2025

    Samsung Galaxy S25 Edge India Launch Confirmed, Could Debut With 200MP Primary Camera; Check Expected Specs, Price |

    By News Analysis IndiaMay 9, 2025

    Amid India-Pakistan Tensions, Government Issues ‘National Security Warning’ To Airtel, Jio; THIS Service Halted Immediately: Reports |

    By News Analysis IndiaMay 9, 2025

    India-Pakistan War Goes Digital: Your WhatsApp, Facebook, Telegram At Cyber Attack Risk; Here’s How To Stay Safe |

    By News Analysis IndiaMay 9, 2025

    Elon Musk-Led X To Block Over 8,000 Accounts In India After Government Order |

    By News Analysis IndiaMay 9, 2025
    -Advertisement-
    Advertisement
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    News Analysis India
    Facebook Instagram YouTube WhatsApp
    • About
    • Contact
    • Terms & Conditions
    • Privacy Policy
    © 2025 News Analysis India. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.