A sophisticated phishing attack leveraged Google's infrastructure to send seemingly legitimate emails from [email protected], bypassing security checks. The emails, mimicking legal subpoenas, directed recipients to fraudulent Google Sites pages designed to steal credentials. The attack exploited a DKIM replay and a legacy Google Sites feature allowing arbitrary scripts. Google has since implemented fixes, urging users to enable two-factor authentication and passkeys for enhanced protection against such attacks. This follows similar recent attacks using Proofpoint vulnerabilities and SVG attachments.
Prepared by Jonathan Pierce and reviewed by editorial team.
Comments