A sophisticated phishing attack is racing across the internet, and may already have hit your inbox.
The definitely not-legit email disguises itself as an official message from Google alerting you that someone wants to share a Google Doc with you. Notifications of this sort are common and often wouldn't raise an eyebrow.
However, clicking through this particular link and taking the requested steps will open up your inbox — and potentially everyone on your contact list — to an as-of-yet unknown attacker.
Tweet may have been deleted
And, like we said, the link looks real — complete with a little "Open in Docs" blue box.
DON'T CLICK.Credit: mashableTweet may have been deleted
Just how widespread is this? Numerous reporters at Mashable have received the same phishing email, as have students at Columbia University— as a warning email sent out by a member of the Philosophy department shows. The scam may have even hit the Capitol.
Oops.Credit: MashableTweet may have been deleted
Google confirmed that it is aware of the problem and is looking into it.
According to one Reddit user, once a victim clicks on the fake Google Doc link, he or she is taken to a real Google page prompting you to select an account. After that, they are taken to a new page asking that they allow "Google Docs" to access the account.
Just don't.Credit: Jake SteamIf you click "allow," the attacker can access your account. And all your contacts will likely soon receive a fake Google Doc invite from you.
So, how to tell if that latest Google Doc your friend shared is real or fake? Thankfully, there are a few tell-tale warning signs. First, real Google Doc invites look different than the recent fake. Here's a legit one for comparison:
Lunch!Credit: MashableNotice the Google address at the bottom? And the box border formatting? The fake Google notification doesn't have that.
Second, expand the dropdown option in the menu bar next to the sender's name. Below is a real Google notification for a shared Google Doc.
Credit: mashableLastly, the spam email is also addressed to "[email protected]," which is an account with the disposable email service Mailinator.
If you did happen to click on the malicious link and allowed attackers into your account, you can revoke that access relatively easily. First, go to your Google permissions page. There you will find a list of all the apps that have account access. One app, titled Google Docs, is the offender. Revoke its permission immediately, and then change your password.
Tweet may have been deleted
So now that you know what's up, pay extra attention to any Google Docs coming your way. And, well, to anything asking you to click a link and enter your password or share account permission.
TopicsCybersecurityGoogle
(责任编辑:時尚)
Cat gets stuck in the most awkward position ever
MashReads Podcast: Catching up with Neal Shusterman
Like Apple's HomePod, Sonos One and Amazon Echo Dot also leave marks
Enormous emotional support peacock denied seat on flight, owner not pleased
U.S. pole vaulter skids to a halt for national anthemThe five guys who climbed Australia's highest mountain, in swimwear
Climbing a freezing cold mountain is already hard enough work. But in briefs? Nope.。It's too late fo
...[详细]Jerry Seinfeld hints at 'possible' reunion for 'Seinfeld'
Seinfeldwas, famously, a show about "nothing." But if Jerry Seinfeld were ever to bring it back -- a
...[详细]Justin Timberlake really wants you to know 'Man of the Woods' isn't a country album
Don't let the flannel, the whiskey, the album art, the album teaser, the tracklist, or features fool
...[详细]Jennifer Lawrence's 'Red Sparrow': Movie review roundup
We now interrupt The Black Panther Showto take a moment for Red Sparrow, Francis Lawrence's upcoming
...[详细]Olympian celebrates by ordering an intimidating amount of McDonald's
It's no secret that Olympians have to eat clean for years to ensure they're at peak physical conditi
...[详细]The next generation of work perks ironically focus on work
While Amazon continues its search for the next North American city to host its second headquarters,
...[详细]Florida kid gets stuck in an arcade claw machine
Kids have a knack for getting into places that they probably shouldn't be able to get into. In the c
...[详细]Snapchat has a hidden Valentine's Day Easter egg
It's Valentine's Day, and that means one thing: the whole world has been plastered with love hearts.
...[详细]Balloon fanatic Tim Kaine is also, of course, very good at harmonica
You know the old saying: the people want a president they can drink a beer with and they also want a
...[详细]Elon Musk replies to Donald Trump's SpaceX Falcon Heavy tweet
President Donald Trump has congratulated Elon Musk's SpaceX for the successful launch of the Falcon
...[详细]Tesla's rumored P100D could make Ludicrous mode even more Ludicrous

These tiny baby octopuses hatching will brighten your miserable existence
