{"id":316532,"date":"2017-05-04T15:35:23","date_gmt":"2017-05-04T15:35:23","guid":{"rendered":"http:\/\/citifmonline.com\/?p=316532"},"modified":"2017-05-04T15:35:23","modified_gmt":"2017-05-04T15:35:23","slug":"google-docs-users-hit-by-phishing-scam","status":"publish","type":"post","link":"https:\/\/citifmonline.com\/?p=316532","title":{"rendered":"Google Docs users hit by phishing scam"},"content":{"rendered":"<p class=\"story-body__introduction\">Google says it has stopped a phishing email that reached about a million of its users.<\/p>\n<p>The scam claimed to come from Google Docs &#8211; a service that allows people to share and edit documents online.<\/p>\n<p>Users who clicked a link and followed instructions, risked giving the hackers access to their email accounts.<\/p>\n<p>Google said it had stopped the attack &#8220;within approximately one hour&#8221;, including through &#8220;removing fake pages and applications&#8221;.<\/p>\n<p>&#8220;While contact information was accessed and used by the campaign, our investigations show that no other data was exposed,&#8221; Google said in an updated statement.<\/p>\n<p>&#8220;There&#8217;s no further action users need to take regarding this event; users who want to review third party apps connected to their account can visit Google Security Checkup.&#8221;<\/p>\n<p>During the attack, users were sent a deceptive invitation to edit a Google Doc, with a subject line stating a contact &#8220;has shared a document on Google Docs with you&#8221;.<\/p>\n<p>The email address hhhhhhhhhhhhhhhh@mailinator[.]com was also copied in to the message; Mailinator, a free email service provider has denied any involvement.<\/p>\n<p>If users clicked on the &#8220;Open in Docs&#8221; button in the email, they were then taken to a real Google-hosted page and asked to allow a seemingly real service, called &#8220;Google Docs&#8221;, to access their email account data.<\/p>\n<figure class=\"media-landscape has-caption full-width\"><span class=\"image-and-copyright-container\"><img loading=\"lazy\" decoding=\"async\" class=\"responsive-image__img js-image-replace\" src=\"https:\/\/ichef.bbci.co.uk\/news\/624\/cpsprodpb\/115BB\/production\/_95899017_image3.png\" alt=\"Email of phishing scam email\" width=\"976\" height=\"549\" data-highest-encountered-width=\"624\" \/><\/span><\/figure>\n<p>By granting permission, users unwittingly allowed hackers to potentially access to their email account, contacts and online documents.<\/p>\n<p>The malware then e-mailed everyone in the victim&#8217;s contacts list in order to spread itself.<\/p>\n<p>&#8220;This is a very serious situation for anybody who is infected because the victims have their accounts controlled by a malicious party,&#8221; Justin Cappos, a cyber security professor at NYU, told Reuters.<\/p>\n<p class=\"story-body__crosshead\"><strong>&#8216;Too widespread&#8217;<\/strong><\/p>\n<p>According to PC World magazine, the scam was more sophisticated than typical phishing attacks, whereby people trick people into handing over their personal information by posing as a reputable company.<\/p>\n<p>This is because the hackers bypassed the need to steal people&#8217;s login credentials and instead built a third-party app that used Google processes to gain account access.<\/p>\n<p>The Russian hacking group Fancy Bear has been accused of using similar attack methods, but one security expert doubted their involvement.<\/p>\n<p>&#8220;I don&#8217;t believe they are behind this&#8230; because this is way too widespread,&#8221; Jaime Blasco, chief scientist at security provider AlienVault, told PC World.<\/p>\n<p>Google said the spam campaign affected &#8220;fewer than 0.1%&#8221; of Gmail users. That works out to about one million people affected.<\/p>\n<p>Last year, an American man pleaded guilty to stealing celebrities&#8217; nude pictures by using a phishing scam to hack their iCloud and Gmail accounts.<\/p>\n<p>And in 2013, Google said it had detected thousands of phishing attacks targeting email accounts of Iranian users ahead of the country&#8217;s presidential election.<\/p>\n<p>&#8211;<\/p>\n<p>Source: BBC<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google says it has stopped a phishing email that reached about a million of its users. The scam claimed to come from Google Docs &#8211; a service that allows people to share and edit documents online. Users who clicked a link and followed instructions, risked giving the hackers access to their email accounts. Google said [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jnews-multi-image_gallery":[],"jnews_single_post":[],"jnews_primary_category":[],"jnews_social_meta":[],"jnews_override_counter":[],"footnotes":""},"categories":[106],"tags":[225,6805],"class_list":["post-316532","post","type-post","status-publish","format-standard","hentry","category-technology","tag-google","tag-phising-scam"],"_links":{"self":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts\/316532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=316532"}],"version-history":[{"count":0,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts\/316532\/revisions"}],"wp:attachment":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=316532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=316532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=316532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}