Widespread Google Docs spam emails carry phishing attack

COLUMBUS (WCMH) – If you receive an email sharing a Google Docs document with you, do not open it.

The emails come appear to come from a legitimate email address and provide a link that appears to be a legitimate Google address.

Gizmodo reports reporters from BuzzFeed, Hearst, New York Magazine and Vice magazine have received the invitations. The NBC4 newsroom has even received several copies of the scam email.

Clicking the link brings you to a screen that looks nearly identical to a legitimate Google login screen. Allowing going further allows the scammers to have full access to your Google account.

A video showing how the attack progresses was posted to Twitter Wednesday afternoon.

If you are affected, and still have access to your account, you can take steps to remove the permissions of the fake app.
  1. Go to https://myaccount.google.com/permissions
  2. Find the app called “Google Docs”
  3. Revoke all permissions

After removing permissions for the app, change your password.

To avoid the possibility of a phishing attack affecting you, you can set up a security key or two step authentication to increase your Google account’s security.



WFLA.com provides commenting to allow for constructive discussion on the stories we cover. In order to comment here, you acknowledge you have read and agreed to our Terms of Service. Commenters who violate these terms, including use of vulgar language or racial slurs, will be banned. Please be respectful of the opinions of others and keep the conversation on topic and civil. If you see an inappropriate comment, please flag it for our moderators to review.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s