I Almost Helped a Scammer Take Over My Google Account

I had a close call today, and I want to explain what happened because the scheme was much more convincing than the usual phishing attempt. Nothing was ultimately hacked, and I did not lose control of my email. I did not click the link, approve the request, or give anyone a verification code. Still, the sequence of events was believable enough that I could understand how someone could fall for it.

A real email from Google does not mean the person calling you works for Google.

It started when I received an email security alert that came from Google. The subject line was, “Security alert for [email protected].” The message stated that my email address had been set as the recovery email for that Gmail account. I do not know Brian McCabe, and I did not recognize the email address, so I ignored it.

The message said that the recovery email for Brian’s account had been changed and that the account holder should review the activity if the change was not authorized. It included a link to Google’s account notification page. I did not click it, but at that point, I viewed the message as strange rather than immediately dangerous.

Shortly afterward, I received an automated telephone call asking whether I had attempted to change my recovery email. That caught my attention because it seemed connected to the Google message I had just received. I acknowledged that I did not try to change my recovery email by pressing 1.

Then I received another call, this time from a live person who said he was calling from Google. The person was very articulate, intelligent-sounding, and convincing.

He told me that the recovery email on my own Google account had been changed. He claimed that the Brian McCabe Gmail address had been added as the recovery address for my account and that once he verified my account, they could correct it. The problem was that this was not what the email said. The very slight nuance was a bit confusing.

The email said that my address had been added as the recovery email for Brian’s account. The caller was saying that Brian’s address had been added to mine. Those are two different events, and the contradiction immediately bothered me.

The caller then asked me to open the Google app on my phone and approve something. I told him that I was not comfortable approving a request based on an incoming telephone call. Anyone can call you and claim to represent Google, your bank, or another company.

Then, when I turned down that request, he sent me a text message containing a six-digit code from Google. The caller asked me to read the code back to him. I refused. At this point, I became fairly certain that he was trying to access my account and needed me to complete a security step he could not complete himself.

Any time you feel rushed, pressured, or even a hint of discomfort that something doesn’t feel right, TRUST YOUR INSTINCT!

The caller then tried to increase the pressure. He claimed that the person attempting the change had provided my Social Security number. He said that if I did not verify my identity, the change to my recovery email would likely go through. That statement made even less sense. Google does not normally resolve account security issues via unsolicited phone calls that involve Social Security numbers.

I did not click anything in the email. I did not approve the request in the Google app. I did not provide the six-digit code, nor did I give the caller any personal information. I told him that his explanation did not match the email I had received and that I was not going to take action based on an unsolicited call.

The email, app message, and text messages ALL actually came from Google! But they were prompted by actions from a scammer.

After looking more closely at the email header, it appears that the original email was actually sent by Google. The sending servers and authentication records looked legitimate. That is what made the scheme more sophisticated.

My best understanding is that the attacker may have added my email address as the recovery address for a Gmail account he controlled. That action could have caused Google to send me a genuine security notification. He then called me and cited a real Google message to make his story sound credible.

While he had me on the phone, he may have initiated a login attempt, an account recovery process, or a security change involving my account. That could have caused Google to send the prompt and the six-digit code. In other words, he may not have been impersonating Google through email at all. He may have been manipulating Google’s real systems to generate messages and codes, then trying to convince me to complete the process for him.

That is the part people need to understand. The attacker did not necessarily need to break Google’s security. He needed to convince me to bypass it and allow him to change my recovery email to one that he controlled. By doing that, he would be able to access my email account, change the password, and lock me out.

I changed my Google password afterward and reviewed my recent security activity. I checked the devices signed into my account, my recovery email and phone number, my passkeys, and my two-step verification settings. I also reviewed Gmail forwarding, filters, and delegation settings to make sure nothing unfamiliar had been added. Because my account has Google Workspace administrative access, I reviewed those settings as well.

I found no evidence that the attacker succeeded.

My advice is to trust your discomfort when something does not add up. The caller sounded calm and professional until I refused his requests. The timing of the calls made him appear connected to the email. The email itself may have been genuine. But the story the caller told me did not exactly match the message I received, and then he asked me to approve a request and read him a security code.

Never approve a login request just because someone on the phone tells you to. Never read a verification code to an unsolicited caller. It does not matter what the caller ID says or how professional the person sounds. Google does not solve these problems by calling clients. Neither do banks and financial institutions.

A verification code is meant to protect you. Anyone who calls and asks you to provide it may be trying to take control of your account. By the way, after the incident, I verified on Google that this is going on…

https://support.google.com/faqs/answer/17170932

Be careful.

About Joe Alagna

Joe Alagna is the CSO for it.com Domains LTD. He is also an independent insurance broker offering home and business insurance in southern California. He is an international expert in all aspects of the domain name business, including domain name investing, new gTLDs, registrars, and registries. Joe can be reached by phone at +1 (909) 606-9175 or via email using the contact form on this site.
This entry was posted in Domain Name News, Personal, Plain Interesting, Security, Tech News and Views. Bookmark the permalink.