Google Docs users hit by phishing attack

The attack was disguised as a Google Doc but was, in fact, a third-party app

Gmail app icon

Google Docs users were hit yesterday by a phishing attack which lets an attacker obtain contact lists and access Gmail accounts to spread spam messages on a large scale.

Reddit user JakeSteam detailed the process and wrote that the attack was disguised as an email from a person on a user's contact list, which invited them to edit a file in Google Docs. But clicking on the link wouldn't take users to a Google Doc. Instead, it would give a third-party app access to the user's emails and potentially perform a password reset too.

It would then replicate itself by sending emails to the user's contacts. It's also particularly dangerous as it bypasses any 2-factor authentication the user has set up.

Clicking on "Open in Docs" takes users to a new page and prompts them to sign in to continue to "Google Docs". By clicking on its name in "to continue to Google Docs" users were able to detect that it wasn't a genuine Google Doc. It then asked for permission to read, send, delete and manage users' email as well as managing their contacts. You can see this in the gif below:

Google responded to the scam within an hour of it launching and manage to stop it before it got out of hand.

"We realise people are concerned about their Google accounts, and we're now able to give a fuller explanation after further investigation. We have taken action to protect users against an email spam campaign impersonating Google Docs, which affected fewer than 0.1% of Gmail users," a Google spokesperson told IT Pro. 

They continued: "We protected users from this attack through a combination of automatic and manual actions, including removing the fake pages and applications, and pushing updates through Safe Browsing, Gmail, and other anti-abuse systems. We were able to stop the campaign within approximately one hour.

"While contact information was accessed and used by the campaign, our investigations show that no other data was exposed. There's no further action users need to take regarding this event; users who want to review third party apps connected to their account can visit Google Security Checkup."

Featured Resources

Unleashing the power of AI initiatives with the right infrastructure

What key infrastructure requirements are needed to implement AI effectively?

Download now

Achieve today. Plan tomorrow. Making the hybrid multi-cloud journey

A Veritas webinar on implementing a hybrid multi-cloud strategy

Download now

A buyer’s guide for cloud-based phone solutions

Finding the right phone system for your modern business

Download now

The workers' experience report

How technology can spark motivation, enhance productivity and strengthen security

Download now

Recommended

TikTok vulnerability exposed private user data
data protection

TikTok vulnerability exposed private user data

26 Jan 2021
SonicWall hacked via zero-day flaw in remote access tools
Security

SonicWall hacked via zero-day flaw in remote access tools

25 Jan 2021
Best ransomware removal tools
ransomware

Best ransomware removal tools

22 Jan 2021
Gmail vs Outlook.com: Which one is better?
email providers

Gmail vs Outlook.com: Which one is better?

22 Jan 2021

Most Popular

WhatsApp could face €50 million GDPR fine
General Data Protection Regulation (GDPR)

WhatsApp could face €50 million GDPR fine

25 Jan 2021
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

21 Jan 2021
What is a 502 bad gateway and how do you fix it?
web hosting

What is a 502 bad gateway and how do you fix it?

12 Jan 2021