PSA: Got a weird email from Google? Read this before opening.
Published on: 2025-04-24 03:40:55
Edgar Cervantes / Android Authority
TL;DR A new phishing email doing the rounds is actually signed by Google.
The email also directs users to a Google Sites page in order to capture a victim’s account credentials.
Google is reportedly addressing this authentication flaw.
Phishing has been a cat-and-mouse game for years now, as tech companies thwart various types of scams only for more to pop up. However, a new phishing email doing the rounds somehow appears to pass Google and Gmail checks.
Developer Nick Johnson revealed on Twitter that he was recently targeted by a complex phishing attack that appeared to originate from Google. Johnson noted that the email was sent from [email protected] and that it was actually signed by accounts.google.com. He also noted that Gmail didn’t show any warnings in the email.
Twitter/NicksDJohnson
The email then directs users to a sites.google.com link which turns out to be a fake support page. It’s worth noting that Google Sites is a Go
... Read full article.