Google Docs phishing scams are on the rise

Cybersecurity software company Check Point has identified a worrying new Google Docs phishing scam that is bypassing usual detection measures to get straight into victims’ inboxes.

The researchers refer to the phishing scam as an evolution of BEC (business email compromise) 3.0, or one that maliciously uses legitimate sites to get access to a target’s mailbox.

With so many companies now favoring Google Workspace’s office software, the scam’s potential for reaching workers in especially troubling.

Google Drive phishing scam

Analysts say that all a threat actor needs to do is create a Google Doc. Inside the file, they can place any sort of attack they desire, including phishing links and URLs that redirect to malware

From there, the Doc just needs to be shared with a victim via the typical Google Drive sharing process. Because the email then arrives via a genuine Google email address and domain, and not one that belongs to the scammer, victims are less likely to identify it as an attack.

Furthermore, detection and prevention tools are also more likely to trust emails from genuine services like Google.

Check Point says that this type of BEC attack uses a form of social engineering, leveraging a trusted service provider (in this case, Google) and a trusted process (document sharing).

Google was reportedly informed about the discovery earlier in July, which it says is not a novel attack method, and as such, it already has strong protections to combat these types of tactics. A company spokesperson told TechRadar Pro:

“We have numerous layers of protections that protect our users from this class of attack, such as built-in warnings in Docs, and automatic scans in Drive that block the vast majority of phishing attempts.”

In the meantime, CheckPoint advises security professionals to implement new and advanced measures that use artificial intelligence to spot multiple phishing indicators. File scanning software is also a good idea, as is URL protection.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Yuga Labs vs. Bungie – finding the Web3 delta thumbnail

Yuga Labs vs. Bungie – finding the Web3 delta

If the endgame for Yuga Labs (creators of the notorious Bored Ape Yacht Club) is essentially a Web3 videogame, and that does appear to be what signs point towards, it seems like an opportunity to examine the closest Web2 equivalent and see what can be learned. Bungie, who were acquired by Sony at a $3.6B valuation in February, seem…
Read More
Why Rust is emerging as developers’ favourite programming language thumbnail

Why Rust is emerging as developers’ favourite programming language

While programming languages like JavaScript, HTML/CSS, and Python remain the most commonly used languages among developers, some interesting trends have emerged over the last few years. Stack Overflow’s 2023 Annual Developer Survey found that, although Rust is in 14th place in the list of most commonly used languages, it ranks number one as the “most
Read More
Realme GT 5G gets Android 12 closed beta in China thumbnail

Realme GT 5G gets Android 12 closed beta in China

The Android 12 floodgate is open and most smartphone brands are rushing to offer up their own take on Google’s new OS. One such offering is Realme UI 3.0 which is officially coming to devices from October 13 but owners of Realme GT 5G in China are already able to sign up for the Android…
Read More
Index Of News