More trouble for Gmail as phishers attack
When it rains, it pours. Convincing phishing attacks target Gmail after its outage earlier this week.
Gmail was hit with more trouble this week as its users were targeted with a phishing campaign that spread through the connected real-time Google Talk IM system.
The issue came soon after Gmail had been knocked offline for two-and-a-half hours due to a problem with an overloaded data centre, which had a knock-on effect on other data centres.
The phishing attack used a social engineering technique whereby GTalk users were tricked into clicking a link directing them to a ViddyHo login page asking for login credentials.
Once the victim entered their Google account information, the criminal could then use it to break into their account and send the link to other users in the victim's address book or buddy list.
In a statement to the Wall Street Journal, Google confirmed that it was a phishing attempt, and encouraged users to be very careful when sharing information.
Graham Cluley, security consultant at Sophos, said: "If you were unfortunate enough to fall for this scam- make sure you change your Gmail password immediately."
"In fact, also change your passwords on any other site where you might be using the same password as on Gmail."
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
He claimed that around 41 per cent of people used the same password for every site they accessed, which meant that an attack like this could have disastrous consequences.
-
What does modern security success look like for financial services?Sponsored As financial institutions grapple with evolving cyber threats, intensifying regulations, and the limitations of ageing IT infrastructure, the need for a resilient and forward-thinking security strategy has never been greater
-
Yes, legal AI. But what can you actually do with it? Let’s take a look…Sponsored Legal AI is a knowledge multiplier that can accelerate research, sharpen insights, and organize information, provided legal teams have confidence in its transparent and auditable application
-
Google says reports of a 'huge' Gmail breach affecting millions of users are false, againNews Reports of a major Gmail affecting millions of users have been flooding the web this week – Google says they're "false" and you've nothing to worry about.
-
Thousands of exposed civil servant passwords are up for grabs onlineNews While the password security failures are concerning, they pale in comparison to other nations
-
Gen Z has a cyber hygiene problemNews A new survey shows Gen Z is far less concerned about cybersecurity than older generations
-
Google hits back at 'entirely false' reports of major Gmail security breachNews Reports of a massive Gmail hack affecting billions of users have been denied by Google
-
Passwords are a problem: why device-bound passkeys can be the future of secure authenticationIndustry insights AI-driven cyberthreats demand a passwordless future…
-
LastPass just launched a tool to help security teams keep tabs on shadow IT risksNews Companies need to know what apps their employees are using, so LastPass made a browser extension to help
-
The NCSC wants you to start using password managers and passkeys – here’s how to choose the best optionsNews New guidance from the NCSC recommends using passkeys and password managers – but how can you choose the best option? ITPro has you covered.
-
I love magic links – why aren’t more services using them?Opinion Using magic links instead of passwords is safe and easy but they’re still infuriatingly underused by businesses