Urgent warning from Google to 2 billion users: Do not click this email
Google has warned its 2 billion Gmail users worldwide against a serious cyberattack. Personal information is being targeted through emails sent from a fake “[email protected]” address. This new type of attack, which uses the pretext of a “legal process” to commit fraud, aims to infiltrate accounts via OAuth access permissions by mimicking Google's infrastructure. Google has issued three important warnings for users to avoid clicking links and to protect their data.
Google has warned its approximately 2 billion Gmail users worldwide about a serious cyberattack.
According to the company's statement, scammers are sending fake emails that appear to come from the address “[email protected]” in an attempt to deceive users. It is emphasized that these messages are not sent by Google under any circumstances.
FAKE EMAIL REQUESTS INFORMATION UNDER THE PRETEXT OF A "LEGAL PROCESS"
The new fraud method is being called a “no-reply email attack.” The emails, which give the impression of being sent from Google's security department, state that information in the users' accounts is being requested.
The message claims that this request is being made as part of a "legal process" and includes links that redirect to a fake Google support page.
Google has stated that such emails are completely fake and are designed to seize users' account information.
CLICKING THE LINK CAN PUT YOUR DATA AT RISK
The attackers' goal is to convince users to click on fake links. When these links are clicked, either fake documents are downloaded or malicious software infects the user's device. In some cases, even viewing the fake documents can give scammers limited access to the users' Gmail content and Drive files.
Through this software, passwords, bank account information, and other sensitive data can be stolen.
THEY ARE DECEIVING USERS VIA GOOGLE OAUTH
Software developer Nick Johnson, who explained the technical aspect of the attack, stated that the scammers are abusing the OAuth access tool located within Google's own infrastructure.
According to Johnson, attackers create fake web addresses and applications that resemble Google, presenting these applications as legitimate to request permission from the user. Thus, the user grants access to their account without realizing it.
“The biggest mistake is trusting these emails and clicking the links,” said Johnson, emphasizing that users should not click on any links other than official Google notifications.
3 RECOMMENDATIONS FROM GOOGLE
Google has offered the following 3 pieces of advice to users:
Approach requests that come with phrases such as "security", "account verification", or "legal action" in the email content with suspicion.
Always check the sender's address. Real Google notifications contain authentication and in-system links. Check the URL before clicking on an incoming link.
Delete suspicious emails immediately and report them to Google.
To protect their digital security, it is recommended that users regularly check the applications granted access to their Gmail accounts and enable two-factor authentication.
News Source: 12punto
Most Read
Historic words from Özgür Özel at the CHP group meeting
Air Force Academy student Veli Bilgin has died
Tuncer Bakırhan calls for a framework law
Here are the names that will be in Özgür Özel's new party!
How did the newspapers view Özgür Özel's farewell to the CHP?
Major crisis in CHP
He killed his wife by slitting her throat: Their children witnessed the moments
AKP mayor held responsible
Kılıçdaroğlu's 'controlled' shopkeeper visit
Güler leaves questions regarding Özgür Özel unanswered