Bitdefender has warned that hackers have been stealing Google account passwords in a new phishing attack.
The attack exploits the way Google Chrome and Firefox displays data in the form of URIs (uniform resource identifiers).
The e-mail reads: “This is a reminder that your e-mail account will be locked out in 24 hours. Due to not being able to increase your Email storage Quota. Go to the INSTANT INCREASE to increase your Email storage automatically.”
When clicking the INSTANT INCREASE link, users are redirected to a fake Google login page that asks for their credentials.
“With access to users’ Google accounts, hackers can buy apps on Google Play, hijack Google+ accounts and access confidential Google Drive documents,” said Catalin Cosoi, chief security strategist at Bitdefender. “The scam starts with an e-mail allegedly sent by Google, with ‘Mail Notice’ or ‘New Lockout Notice’ as a subject.
“What is interesting about this phishing attack is that users end up having the ‘data’: in their browser’s address bar, which indicates the use of a data URI scheme.”
A similar attack recently targeted Google Drive’s landing page to grab Gmail credentials.
TechCentral Reporters






Subscribers 0
Fans 0
Followers 0
Followers