HomeTechnologyGoogle has an email scam warning, here’s what Gmail users need to know to stay safe

Google has an email scam warning, here’s what Gmail users need to know to stay safe

Gmail users face a phishing scam using verified Google email addresses and cloned support pages. The attack bypasses authentication, appearing legitimate. Google urges users to enable 2FA and use passkeys.

April 20, 2025 / 09:17 IST
Story continues below Advertisement
Gmail
Gmail

Google has issued an important warning to all Gmail users. The warning highlights a new phishing campaign that uses legitimate-looking emails to bypass security checks and trick recipients into handing over their account credentials.

Google has acknowledged the threat and is working to roll out protections. Still, users are urged to stay vigilant, especially when responding to emails that appear to come from trusted sources like Google.

Story continues below Advertisement

What is this scam?
The attack came to light when software developer Nick Johnson posted on X about receiving an official-looking email from “no-reply@google.com” that claimed a subpoena had been issued for his Google Account data. The email included a link to what appeared to be a legitimate Google support page. In reality, the page was a phishing site hosted on Google’s own platform, sites.google.com.

What made the email particularly convincing was that it passed Google’s authentication checks, including DomainKeys Identified Mail (DKIM). The phishing message was also delivered in the same Gmail conversation thread as real Google security alerts, adding to its perceived legitimacy.