Don't Open the 'Google Docs' Email You Just Got - and What to Do if You Did

Advertisement
By Brian Fung, The Washington Post | Updated: 4 May 2017 12:32 IST
Highlights
  • There was a Google Docs invitation with a link reaching Gmail users
  • It happened out to be a phishing scam
  • Google has taken action against this phishing scam

If you've received an invitation to join a shared Google Doc that you weren't expecting, you might want to steer clear of it. It's probably a phishing scam that could compromise your account.

Internet users everywhere are being spammed with what appear to be malicious invitations to log on to their Google accounts. Unlike your garden-variety cyber-attack, many of the telltale signs that could tip you off that something is awry are absent.

For example, the attack appears to work by tricking you into logging into your actual Google account, then granting a third party (your attacker) access to your account's data. Having gained permission to access your contacts, the attacker then fires off spam invites to everyone in your address book.

Advertisement

What makes this attack so tricky to detect is that it takes advantage of Google's legitimate tool for sharing data with responsible third-party apps. Since the bogus invitation is being routed through Google's real system, nothing is misspelled, the icons look accurate, and it's hard to know something's gone wrong until it's too late.

Advertisement

Google said Wednesday that it is working to ensure this type of "spoofing" doesn't happen again.

"We have taken action to protect users against an email impersonating Google Docs, and have disabled offending accounts," the company said in a statement.

Advertisement

Staff at The Washington Post, students at New York University and even workers at the US Agency for International Development have received warnings from IT administrators not to open the emails. Here is one such notice, obtained by The Post.

Here's one clue for identifying the fraudulent email: Included on the string of recipients is an email address that begins "hhhhhhhhhhhhhh" and ends in "mailinator.com," a website that lets visitors obtain a temporary and disposable email address.

Advertisement

So, until you hear otherwise, it's probably best to hold off on any Google Docs usage for now. If you've clicked the link in the malicious email, you can revoke the attacker's access by visiting ...

https://myaccount.google.com/permissions

... and deleting the "Google Docs" app - which is the one pretending to be legitimate.

© 2017 The Washington Post

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Kabul Streaming Now Online: Know Where to Watch This Thriller Series
  1. Curiosity Explores Polygon-Covered Rocks in Monte Grande Hollow During Sols 4743-4749
  2. Betelgeuse and the Crab Nebula Reveal Stellar Death and Rebirth in Multi-Telescope Views
  3. Hubble Captures Gas Escaping Sideways Spiral Galaxy NGC 4388 in Virgo Cluster
  4. NASA’s PUNCH Watches Comet Lemmon Respond to the Sun’s Powerful Influence
  5. All India Rankers Now Streaming on Netflix: What You Need to Know
  6. Andhra King Taluka OTT Release: When and Where to Watch Ram Pothineni’s Telugu Film
  7. Kabul Streaming Now on Lionsgate Play: Everything You Need to Know About Plot, Cast, and More
  8. Love Me Love Me OTT Release Date Revealed: Know When and Where to Watch it Online
  9. Pernikahan Dini Gen Z Now Streaming on OTT: A Teen Drama on Love, Choices, and Life-Changing Consequences
  10. A Misanthrope Teaches a Class for Demi-Humans To Stream Soon on Crunchyroll
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.