IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Google Docs users hit by phishing attack

The attack was disguised as a Google Doc but was, in fact, a third-party app

Gmail and YouTube icons on a smartphone screen

Google Docs users were hit yesterday by a phishing attack which lets an attacker obtain contact lists and access Gmail accounts to spread spam messages on a large scale.

Reddit user JakeSteam detailed the process and wrote that the attack was disguised as an email from a person on a user's contact list, which invited them to edit a file in Google Docs. But clicking on the link wouldn't take users to a Google Doc. Instead, it would give a third-party app access to the user's emails and potentially perform a password reset too.

It would then replicate itself by sending emails to the user's contacts. It's also particularly dangerous as it bypasses any 2-factor authentication the user has set up.

Clicking on "Open in Docs" takes users to a new page and prompts them to sign in to continue to "Google Docs". By clicking on its name in "to continue to Google Docs" users were able to detect that it wasn't a genuine Google Doc. It then asked for permission to read, send, delete and manage users' email as well as managing their contacts. You can see this in the gif below:

Google responded to the scam within an hour of it launching and manage to stop it before it got out of hand.

"We realise people are concerned about their Google accounts, and we're now able to give a fuller explanation after further investigation. We have taken action to protect users against an email spam campaign impersonating Google Docs, which affected fewer than 0.1% of Gmail users," a Google spokesperson told IT Pro. 

They continued: "We protected users from this attack through a combination of automatic and manual actions, including removing the fake pages and applications, and pushing updates through Safe Browsing, Gmail, and other anti-abuse systems. We were able to stop the campaign within approximately one hour.

"While contact information was accessed and used by the campaign, our investigations show that no other data was exposed. There's no further action users need to take regarding this event; users who want to review third party apps connected to their account can visit Google Security Checkup."

Featured Resources

Big data for finance

How to leverage big data analytics and AI in the finance sector

Free Download

Ten critical factors for cloud analytics success

Cloud-native, intelligent, and automated data management strategies to accelerate time to value and ROI

Free Download

Remove barriers and reconnect with your customers

The $260 billion dollar friction problem businesses don't know they have

Free Download

The future of work is already here. Now’s the time to secure it.

Robust security to protect and enable your business

Free Download

Recommended

Singapore becomes a lightning rod for Google investment
Business operations

Singapore becomes a lightning rod for Google investment

23 Aug 2022
Record for the largest ever HTTPS DDoS attack smashed once again
Network & Internet

Record for the largest ever HTTPS DDoS attack smashed once again

19 Aug 2022
Google is now spending a staggering amount on blockchain
Business strategy

Google is now spending a staggering amount on blockchain

17 Aug 2022
Google urges Apple to embrace RCS as standard, ditch SMS for Android texts
Mobile

Google urges Apple to embrace RCS as standard, ditch SMS for Android texts

10 Aug 2022

Most Popular

How to secure your hybrid workforce
Advertisement Feature

How to secure your hybrid workforce

23 Sep 2022
What your hybrid workforce needs from their laptops
Advertisement Feature

What your hybrid workforce needs from their laptops

21 Sep 2022
Spain to attract remote workers with digital nomad visas
flexible working

Spain to attract remote workers with digital nomad visas

26 Sep 2022