{"id":9184,"date":"2017-05-04T16:55:10","date_gmt":"2017-05-04T23:55:10","guid":{"rendered":"http:\/\/blog.hellotech.com\/?p=9184"},"modified":"2021-11-18T02:43:31","modified_gmt":"2021-11-18T10:43:31","slug":"google-docs-phishing-scam","status":"publish","type":"post","link":"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam","title":{"rendered":"What You Need to Know (and Do) About the &#8216;Google Docs&#8217; Phishing Scam"},"content":{"rendered":"\n<p>If you\u2019ve got a Gmail account, you\u2019re vulnerable to the latest, massive cyber threat. A phishing scam is sweeping the Web at the moment and your Gmail (and all online accounts you pair it with) could be susceptible. It may not be clear who is pulling the strings behind this latest, rapidly spreading Google Docs phishing scam and what their motivation may be, but one thing is for sure: a million accounts may have already been compromised.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-massive-possible-damage\">Massive Possible Damage<\/h2>\n\n\n\n<p>This phishing scam is no ordinary threat, by any means. People whose emails have been compromised are highly susceptible because the \u2018worm\u2019 gives hackers the power to take over the account.<\/p>\n\n\n\n<p>Based on what has been observed from this threat so far, it\u2019s pretty capable of accessing a user\u2019s personal details and information. For those who\u2019ve already been affected by this Google Docs phishing scam, the damage could potentially be massive.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-the-google-docs-phishing-scam-spread\">How the Google Docs Phishing Scam Spread<\/h2>\n\n\n\n<p>The scam often begins with you getting an email from someone you know, asking you to check out an attached GDocs (Google Docs) file. Make the mistake of clicking on the infected link in the said email and you\u2019ll then be taken to a real Google security page, where you\u2019d be asked to give permission to the fake app\u2014posing as a Google Docs\u2014to manage your email account.<\/p>\n\n\n\n<p>If you fell for it completely and gave permission to the disguised worm, it will gain access to your email and turn your account into a tool for spreading the hack further. The worm consequently then sends itself out to all of your contacts, whether they\u2019re in Gmail or not, reproducing itself hundreds of times over every time someone fell for its trickery.<\/p>\n\n\n\n<p>To be honest, this identity phishing campaign is a common one. The worm that was released yesterday, however, was anything but that.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-worm-s-sophisticated-construction\">The Worm\u2019s \u2018Sophisticated\u2019 Construction<\/h2>\n\n\n\n<p>According to reports, the scam affected \u201cfewer than 0.1 percent of Gmail users\u201d. Because Gmail roughly has around 1 billion users worldwide, this figure may easily mean that the Google Docs phishing scam has successfully cracked at least a million accounts.<\/p>\n\n\n\n<p>Millions of users fell for the trap because of the phishing scam\u2019s unusually sophisticated construction. Not only is the malicious link in the email remarkably realistic, the email itself also came from someone you already know. It even manipulated Google\u2019s real login system.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-a-potential-for-a-disaster\">A Potential for a Disaster<\/h2>\n\n\n\n<p>\u201cWhile contact information was accessed and used by the campaign, our investigations show that no other data was exposed,\u201d a Google spokesperson revealed to NBC News an hour after such scary attack got exposed via social media.<\/p>\n\n\n\n<p>Even if Google has \u201cdisabled\u201d the malicious accounts affected by the worm, it could have easily been a disaster for the unsuspecting victim. Gaining full control of your Gmail meant that scammers could\u2019ve retrieved personal data you\u2019ve sent or received using the compromised email. You could be handing over access to your Facebook, Amazon, and other accounts, including online bank accounts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-a-key-giveaway\">A Key Giveaway<\/h2>\n\n\n\n<p>By now, you can see a red warning appearing on the malicious email, saying it could be a phishing attack. If there isn\u2019t any warning shown, be on the lookout for one obvious giveaway: a fake email address in the main recipient field.<\/p>\n\n\n\n<p>While there isn\u2019t anything suspicious about the email at first glance, look over at the main recipient field and you\u2019ll see that the message has been sent to a fake email address\u2014 <em>hhhhhhhhhhhhhhhh@mailinator.com<\/em>. You\u2019ll likely see your address in the BCC field.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-to-do-next\">What to Do Next<\/h2>\n\n\n\n<p>At this point, we highly recommend that you only click on Google Doc links from emails you were expecting. Be absolutely sure that you are supposed to receive such a link from a contact before even attempting to open the email.<\/p>\n\n\n\n<p>If you have received this Gmail message (the one with the mailinator.com address as the main recipient), report it as phishing immediately. Click the down arrow beside the reply button and select \u201cReport phishing\u201d option. Afterward, delete the email.<\/p>\n\n\n\n<p>In case you\u2019ve inadvertently clicked on the link, go to <a href=\"https:\/\/myaccount.google.com\/security?pli=1#connectedapps\">Google connected sites console<\/a> and revoke access to Google Docs. This should hopefully keep hackers from being granted permission to access your email via GDocs. It might be a good idea to revoke permission for any other listed apps that you don\u2019t recognize while you\u2019re checking out the page.<\/p>\n\n\n\n<p>For good measure, we encourage you to change the password to your Gmail account, too.<\/p>\n\n\n\n<p>Expect even more phishing hacks to land in your Gmail inbox this year. And if you\u2019re wondering how to fortify your Google account\u2019s defenses against cyber threats like these\u2026 we\u2019ve got <a href=\"https:\/\/www.hellotech.com\/gmail-more-secure\/\">7 tips and tricks to make Gmail more secure<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you\u2019ve got a Gmail account, you\u2019re vulnerable to the latest, massive cyber threat. A phishing scam is sweeping the Web at the moment and your Gmail (and all online accounts you pair it with) could be susceptible. It may not be clear who is pulling the strings behind this latest, rapidly spreading Google Docs phishing scam and what their motivation may be, but one thing is for sure: a million accounts may have already been compromised. Massive Possible Damage [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":9191,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[17587,17593],"tags":[],"class_list":["post-9184","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-staying-safe"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v20.10 (Yoast SEO v20.10) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>What You Need to Know (and Do) About the &#039;Google Docs&#039; Phishing Scam - The Plug - HelloTech<\/title>\n<meta name=\"description\" content=\"It&#039;s not clear who is pulling the strings behind this latest, rapidly spreading Google Docs phishing scam or what their motivation may be.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What You Need to Know (and Do) About the &#039;Google Docs&#039; Phishing Scam - The Plug - HelloTech\" \/>\n<meta property=\"og:description\" content=\"If you\u2019ve got a Gmail account, you\u2019re vulnerable to the latest, massive cyber threat. A phishing scam is sweeping the Web at the moment and your Gmail\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam\" \/>\n<meta property=\"og:site_name\" content=\"The Plug - HelloTech\" \/>\n<meta property=\"article:publisher\" content=\"http:\/\/www.facebook.com\/hellotech\" \/>\n<meta property=\"article:published_time\" content=\"2017-05-04T23:55:10+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-11-18T10:43:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hellotech.com\/blog\/wp-content\/uploads\/2017\/05\/googledocscam-min.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"640\" \/>\n\t<meta property=\"og:image:height\" content=\"426\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@HelloTech\" \/>\n<meta name=\"twitter:site\" content=\"@HelloTech\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/#\/schema\/person\/dec00225dd888a509740ace5e4d9de6c\"},\"headline\":\"What You Need to Know (and Do) About the &#8216;Google Docs&#8217; Phishing Scam\",\"datePublished\":\"2017-05-04T23:55:10+00:00\",\"dateModified\":\"2021-11-18T10:43:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam\"},\"wordCount\":825,\"publisher\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/#organization\"},\"articleSection\":[\"News\",\"Staying Safe\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam\",\"url\":\"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam\",\"name\":\"What You Need to Know (and Do) About the 'Google Docs' Phishing Scam - The Plug - HelloTech\",\"isPartOf\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/#website\"},\"datePublished\":\"2017-05-04T23:55:10+00:00\",\"dateModified\":\"2021-11-18T10:43:31+00:00\",\"description\":\"It's not clear who is pulling the strings behind this latest, rapidly spreading Google Docs phishing scam or what their motivation may be.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.hellotech.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What You Need to Know (and Do) About the &#8216;Google Docs&#8217; Phishing Scam\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/#website\",\"url\":\"https:\/\/www.hellotech.com\/blog\/\",\"name\":\"The Plug - HelloTech\",\"description\":\"Turn to The Plug for informative tech news that you can use. \",\"publisher\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.hellotech.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/#organization\",\"name\":\"HelloTech\",\"url\":\"https:\/\/www.hellotech.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.hellotech.com\/blog\/wp-content\/uploads\/2018\/11\/HT-logo-revised-final.png\",\"contentUrl\":\"https:\/\/www.hellotech.com\/blog\/wp-content\/uploads\/2018\/11\/HT-logo-revised-final.png\",\"width\":1000,\"height\":174,\"caption\":\"HelloTech\"},\"image\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"http:\/\/www.facebook.com\/hellotech\",\"https:\/\/twitter.com\/HelloTech\",\"http:\/\/www.instagram.com\/hello_tech\",\"https:\/\/www.youtube.com\/channel\/UCIR-fbAKRfVuAbciDr2z4nQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/#\/schema\/person\/dec00225dd888a509740ace5e4d9de6c\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/cbb537d18df244ad7d57a3639d94ede5cd90bf1fb742392af5731beaf11ffeb1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/cbb537d18df244ad7d57a3639d94ede5cd90bf1fb742392af5731beaf11ffeb1?s=96&d=mm&r=g\",\"caption\":\"admin\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"What You Need to Know (and Do) About the 'Google Docs' Phishing Scam - The Plug - HelloTech","description":"It's not clear who is pulling the strings behind this latest, rapidly spreading Google Docs phishing scam or what their motivation may be.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam","og_locale":"en_US","og_type":"article","og_title":"What You Need to Know (and Do) About the 'Google Docs' Phishing Scam - The Plug - HelloTech","og_description":"If you\u2019ve got a Gmail account, you\u2019re vulnerable to the latest, massive cyber threat. A phishing scam is sweeping the Web at the moment and your Gmail","og_url":"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam","og_site_name":"The Plug - HelloTech","article_publisher":"http:\/\/www.facebook.com\/hellotech","article_published_time":"2017-05-04T23:55:10+00:00","article_modified_time":"2021-11-18T10:43:31+00:00","og_image":[{"width":640,"height":426,"url":"https:\/\/www.hellotech.com\/blog\/wp-content\/uploads\/2017\/05\/googledocscam-min.jpg","type":"image\/jpeg"}],"author":"admin","twitter_card":"summary_large_image","twitter_creator":"@HelloTech","twitter_site":"@HelloTech","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam#article","isPartOf":{"@id":"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam"},"author":{"name":"admin","@id":"https:\/\/www.hellotech.com\/blog\/#\/schema\/person\/dec00225dd888a509740ace5e4d9de6c"},"headline":"What You Need to Know (and Do) About the &#8216;Google Docs&#8217; Phishing Scam","datePublished":"2017-05-04T23:55:10+00:00","dateModified":"2021-11-18T10:43:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam"},"wordCount":825,"publisher":{"@id":"https:\/\/www.hellotech.com\/blog\/#organization"},"articleSection":["News","Staying Safe"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam","url":"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam","name":"What You Need to Know (and Do) About the 'Google Docs' Phishing Scam - The Plug - HelloTech","isPartOf":{"@id":"https:\/\/www.hellotech.com\/blog\/#website"},"datePublished":"2017-05-04T23:55:10+00:00","dateModified":"2021-11-18T10:43:31+00:00","description":"It's not clear who is pulling the strings behind this latest, rapidly spreading Google Docs phishing scam or what their motivation may be.","breadcrumb":{"@id":"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.hellotech.com\/blog\/google-docs-phishing-scam#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hellotech.com\/blog\/"},{"@type":"ListItem","position":2,"name":"What You Need to Know (and Do) About the &#8216;Google Docs&#8217; Phishing Scam"}]},{"@type":"WebSite","@id":"https:\/\/www.hellotech.com\/blog\/#website","url":"https:\/\/www.hellotech.com\/blog\/","name":"The Plug - HelloTech","description":"Turn to The Plug for informative tech news that you can use. ","publisher":{"@id":"https:\/\/www.hellotech.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hellotech.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hellotech.com\/blog\/#organization","name":"HelloTech","url":"https:\/\/www.hellotech.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hellotech.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.hellotech.com\/blog\/wp-content\/uploads\/2018\/11\/HT-logo-revised-final.png","contentUrl":"https:\/\/www.hellotech.com\/blog\/wp-content\/uploads\/2018\/11\/HT-logo-revised-final.png","width":1000,"height":174,"caption":"HelloTech"},"image":{"@id":"https:\/\/www.hellotech.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["http:\/\/www.facebook.com\/hellotech","https:\/\/twitter.com\/HelloTech","http:\/\/www.instagram.com\/hello_tech","https:\/\/www.youtube.com\/channel\/UCIR-fbAKRfVuAbciDr2z4nQ"]},{"@type":"Person","@id":"https:\/\/www.hellotech.com\/blog\/#\/schema\/person\/dec00225dd888a509740ace5e4d9de6c","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hellotech.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/cbb537d18df244ad7d57a3639d94ede5cd90bf1fb742392af5731beaf11ffeb1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/cbb537d18df244ad7d57a3639d94ede5cd90bf1fb742392af5731beaf11ffeb1?s=96&d=mm&r=g","caption":"admin"}}]}},"_links":{"self":[{"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/posts\/9184","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/comments?post=9184"}],"version-history":[{"count":0,"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/posts\/9184\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/media\/9191"}],"wp:attachment":[{"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/media?parent=9184"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/categories?post=9184"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/tags?post=9184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}