Wednesday, March 25, 2015

Phishing attack on my gmail - Google drive scam is back!

Phishing is the attempt to acquire sensitive information such as usernames, passwords, and credit card details (and sometimes, indirectly, money) by masquerading as a trustworthy entity in an electronic communication.
Attached email is a phish I received today on my gmail inbox from my doctor -
I called the doctor's office to inform about the spam, they told me his account was hacked.
I tried to look up related articles- found a couple and believe they are related-
 
http://blog.emsisoft.com/2014/03/14/alert-google-drive-phishing-scam/

http://www.symantec.com/connect/blogs/sophisticated-google-drive-phishing-scam-returns

According to the blogs, upon clicking the link it takes us to a fake google signin link that is hosted on Google and has SSL. Users who enter their information and “Sign in” are redirected to an actual Google Doc containing irrelevant information.  At the same time, and in the background, the user’s Google log-in credentials are sent to the scammer’s web server.

---------- Forwarded message ----------
From: FirstName LastName at gmail (dot) com>
Date: Wed, Mar 25, 2015 at 3:41 PM
Subject: Report
To:


I tried to contact you yesterday but didn't get a reply. You need to see this report, I uploaded it using google drive because I'm having problems with attachments.

https (colon) //  googledrive (dot) com /  host / 0B16U6o6sGxNieWpIakN5eC1NaXc /  index (dot)  htm

Please check and get back to me this is very important.

[His entire signature including his addresses, email, phone, fax, etc was in here]

No comments: