Sophisticated phishing attack used Google Docs to gain access to your contacts

Be wary of unexpected Google Docs Several news outlets are reporting on receiving spam emails from an elaborate phishing scheme. The scam ...

Be wary of unexpected Google Docs

Several news outlets are reporting on receiving spam emails from an elaborate phishing scheme. The scam masquerades as Google Docs to gain access to your contacts and address book. It starts with an email that appears to be from one of your contacts. The email invites you to edit a document on Google Docs.

The link in the email is “somewhat suspicious,” according to one Redditor who almost fell victim to the ploy, but is “still reasonably Google based.”

Clicking on the link takes you to a real Google login screen where you can select the account with which you want to login to Google Docs. Once logged in, it prompts you to continue to Google Docs. This is where the effects of the scam take place.

When you click the link, you are asked to grant permission to Google Docs to “Read, send, delete, and manage your email” and to “Manage your contacts.”

Doing this grants permission to a “malicious third-party.” The Verge reports that the thing asking for permissions is nothing more than a web app named “Google Docs.” The reason it is so tricky is that the login page that it takes you to is an actual Google login screen, so looking at the URL does not give it away. The only real clue that it is not what it appears to be is the email address that is linked to the developer credentials of the bogus app.

JakeSteam on Reddit says that if you “click ‘Google Docs,' it shows [you] it's actually published by a random gmail account, so that user would receive full access to [your] emails.”

It is not known how far this scam was spread, but it raised eyebrows across the web due to the sheer number of people that appear to have received the emails. Google has since tweeted it has put the situation under control by disabling offending accounts, removing the fake pages, and pushing updates through Safe Browsing, among others.

If you have fallen for the scheme, go to Google’s “Connected Apps and Sites” page and revoke privileges from the app called "Google Docs." In the meantime, be cautious of emails asking to share a Google document with you, even if it is from a trusted contact. Check first and be sure they are the ones who sent it.


http://www.techspot.com/news/69181-sophisticated-phishing-attack-uses-google-docs-gain-access.html
Name

English News techspot.com
false
ltr
item
Techno - Gampong IT - Reference Information Technology: Sophisticated phishing attack used Google Docs to gain access to your contacts
Sophisticated phishing attack used Google Docs to gain access to your contacts
http://www.techspot.com/images2/news/bigimage/2017/05/2017-05-03-image-16.jpg
Techno - Gampong IT - Reference Information Technology
http://techno.gampongit.com/2017/05/sophisticated-phishing-attack-used.html
http://techno.gampongit.com/
http://techno.gampongit.com/
http://techno.gampongit.com/2017/05/sophisticated-phishing-attack-used.html
true
7281475864779722461
UTF-8
Tidak ditemukan artikel apapun LIHAT SEMUA Selengkapnya Balas Batal Balas Hapus Oleh Beranda HALAMAN ARTIKEL Lihat Semua REKOMENDASI LABEL ARSIP SEARCH SEMUA ARTIKEL Tidak ditemukan posting yang sesuai dengan permintaan Anda Halaman Utama Minggu Senin Selesa Rabu Kamis Jumat Sabtu Min Sen Sel Rab Kam Jum Sab Januari Februari Maret April Mei Juni Juli Agustus September Oktober November Desember Jan Feb Mar Apr Mei Jun Jul Agu Sep Okt Nov Des baru saja 1 menit lalu $$1$$ minutes ago 1 jam lalu $$1$$ hours ago Kemarin $$1$$ days ago $$1$$ weeks ago lebih dari 5 minggu yang lalu Pengikut Ikuti KONTEN PREMIUM Silakan share untuk membuka Salin Semua Code Pilih Semua Code Semua kode disalin ke clipboard Anda Tidak dapat menyalin kode/teks, silakan tekan [CTRL] + [C] (atau CMD + C dengan Mac) untuk menyalin