Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Microsoft and Asus announce two Xbox Ally handhelds with new Xbox full-screen experience

    June 8, 2025

    How to Advocate for Trans Rights in Your Community

    June 8, 2025

    Gears of War: E-Day is coming in 2026

    June 8, 2025
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Beware of this sneaky Google phishing scam
    News

    Beware of this sneaky Google phishing scam

    News RoomBy News RoomApril 21, 20252 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email

    Attackers are sending phishing emails that appear to be from “[email protected],” presented as an urgent subpoena alert about “law enforcement” seeking information from the target’s Google Account. Bleeping Computer reports that the scam utilizes Google’s “Sites” web-building app to create realistic-looking phishing websites and emails that aim to intimidate victims into giving up their credentials.

    As explained by EasyDMARC, an email authentication company, the emails manage to bypass the DomainKeys Identified Mail (DKIM) authentication that would normally flag fake emails, because they came from Google’s own tool. The scammers simply entered the full text of the email as the name of their fake app, which autofills that text into an email sent by Google to their own chosen address.

    When forwarded from the scammer to a user’s Gmail inbox, it remains signed and valid since DKIM only checks the message and headers. PayPal users were similarly targeted using the DKIM relay attack last month. Finally, it links to a real-looking support portal on sites.google.com instead of accounts.google.com, hoping the recipient won’t catch on.

    Etherem Name Service developer Nick Johnson received the same Google phishing scam and reported the attackers’ misuse of Google OAuth applications as a security bug to Google. The company initially brushed it off as “working as intended,” but then backtracked and is now working on a fix.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleThe Best Blow-Dry Brushes
    Next Article This Massive Screen for Live Sports Puts You in the Best Seat in the Stadium

    Related Posts

    Microsoft and Asus announce two Xbox Ally handhelds with new Xbox full-screen experience

    June 8, 2025

    Gears of War: E-Day is coming in 2026

    June 8, 2025

    This is how Microsoft is combining Windows and Xbox for handheld PCs

    June 8, 2025

    Vivo’s telephoto extender makes the world’s best phone camera better

    June 8, 2025

    The Verge’s favorite summer gear for 2025

    June 8, 2025

    The most fun camera app I’ve used in forever

    June 8, 2025
    Our Picks

    How to Advocate for Trans Rights in Your Community

    June 8, 2025

    Gears of War: E-Day is coming in 2026

    June 8, 2025

    The Best Home Treadmills to Maintain Your Mileage

    June 8, 2025

    This is how Microsoft is combining Windows and Xbox for handheld PCs

    June 8, 2025
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Gear

    How to Buy a Bike Helmet

    By News RoomJune 8, 2025

    After more than a decade of study and design, Mips launched its first product, a…

    Vivo’s telephoto extender makes the world’s best phone camera better

    June 8, 2025

    Tech Up Your Sourdough With These Upper-Crust Baking Gadgets

    June 8, 2025

    The Verge’s favorite summer gear for 2025

    June 8, 2025
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.