Clever phishing scam of the day

Paulo Scardine
HackerNoon.com
Published in
2 min readJan 11, 2017

--

Received this message today, almost fell for it:

This links to a page with an encrypted parameter that seems to auto-fill my email address in the form.

I'm wondering how many people would follow instructions from a 3rd party claiming to be Google, and fill in sensitive information like security questions.

This is very clever:

  1. talk about a very serious matter
  2. sense of urgency (7 days deadline)
  3. email is not from google.com, but cc to due-diligence@google.com.

The website certificate looks legit, but it is not that hard to get one like this:

[update]

Even this message having the classic modus operandi of a phishing attack, I got a Google support ticket opened just in case. Turn out the message is legit!!! Seriously, Google?

Hacker Noon is how hackers start their afternoons. We’re a part of the @AMI family. We are now accepting submissions and happy to discuss advertising & sponsorship opportunities.

If you enjoyed this story, we recommend reading our latest tech stories and trending tech stories. Until next time, don’t take the realities of the world for granted!

--

--