Login-stealing phishing sites conceal their evil with lots of hyphens in URL

Researchers at PhishLabs recently spotted a trend emerging in malicious web sites presented to customers: mobile-focused phishing attacks that attempt to conceal the true domain they were served from, by padding the subdomain address with enough hyphens to push the actual source of the page outside the address box on mobile browsers. “The tactic we’re seeing […]

Google beefs up Gmail security to fight phishing attempts

Google has just added a bunch of new security features in order to protect Gmail users from spam and phishing messages. Though they didn’t say as much, the bumped-up protection is likely in response to the phishing scam that went around earlier this month. The attack peddled a bogus Google Docs file in attempts to […]

Google revises app review process following phishing attacks

In the wake of the Google Docs phishing debacle last week, Google has added a few new safeguards to better protect us from these types of attacks. The Gmail app for Android scans for suspect links and Google has tightened up its policies on third party authentication to help keep phishing scams from even getting […]

Google explains how it’s preventing future email phishing scams

That massive Google Docs phishing attack from May 3rd was more than a little disconcerting, but Google is trying to set minds at ease. It just outlined how it responds to this email trickery — including how it intends to prevent incidents like the one that just wreaked havoc. It’s shoring up its defenses by […]

Google phishing attack was foretold by researchers—and it may have used their code

Enlarge (credit: Sean Gallup / Getty Images) The “Google Docs” phishing attack that wormed its way through thousands of e-mail inboxes earlier this week exploited a threat that had been flagged earlier by at least three security researchers—one raised issues about the threat as early as October of 2011. In fact, the person or persons behind the attack […]

Everything You Need to Know About This Week's Massive Phishing Worm

Image: Gizmodo / Google Over a million Gmail users got hit by a phishing worm on Wednesday afternoon, sending the security world into a cacophony of screams and laughter. Screams, because the attack looked like it came from Google itself. Laughter, because the attack looked like it came from Google itself. While some chin-scratching observers […]

‘Google Docs’ phishing scam spreads across web through disguised emails

Google Docs users came across a new sophisticated type of phishing scam after many clicked a well-disguised link sent to Gmail accounts. The fraudulent invitations spread like wildfire before they were finally stopped, but many questions remain. On Wednesday, several Gmail users received emails from known contacts, asking them to click on a link to […]

All your Googles are belong to us: Look out for the Google Docs phishing worm

Enlarge / Don’t click. A widely reported e-mail purporting to be a request to share a Google Docs document is actually a well-disguised phishing attack. It directs the user to a lookalike site and grants the site access to the target’s Google credentials. If the victim clicks on the prompt to give the site permission […]