时间:2024-11-22 07:08:45 来源:网络整理编辑:焦點
A sophisticated phishing attack is racing across the internet, and may already have hit your inbox.
A sophisticated phishing attack is racing across the internet, and may already have hit your inbox.
The definitely not-legit email disguises itself as an official message from Google alerting you that someone wants to share a Google Doc with you. Notifications of this sort are common and often wouldn't raise an eyebrow.
However, clicking through this particular link and taking the requested steps will open up your inbox — and potentially everyone on your contact list — to an as-of-yet unknown attacker.
Tweet may have been deleted
And, like we said, the link looks real — complete with a little "Open in Docs" blue box.
DON'T CLICK.Credit: mashableTweet may have been deleted
Just how widespread is this? Numerous reporters at Mashable have received the same phishing email, as have students at Columbia University— as a warning email sent out by a member of the Philosophy department shows. The scam may have even hit the Capitol.
Oops.Credit: MashableTweet may have been deleted
Google confirmed that it is aware of the problem and is looking into it.
According to one Reddit user, once a victim clicks on the fake Google Doc link, he or she is taken to a real Google page prompting you to select an account. After that, they are taken to a new page asking that they allow "Google Docs" to access the account.
Just don't.Credit: Jake SteamIf you click "allow," the attacker can access your account. And all your contacts will likely soon receive a fake Google Doc invite from you.
So, how to tell if that latest Google Doc your friend shared is real or fake? Thankfully, there are a few tell-tale warning signs. First, real Google Doc invites look different than the recent fake. Here's a legit one for comparison:
Lunch!Credit: MashableNotice the Google address at the bottom? And the box border formatting? The fake Google notification doesn't have that.
Second, expand the dropdown option in the menu bar next to the sender's name. Below is a real Google notification for a shared Google Doc.
Credit: mashableLastly, the spam email is also addressed to "[email protected]," which is an account with the disposable email service Mailinator.
If you did happen to click on the malicious link and allowed attackers into your account, you can revoke that access relatively easily. First, go to your Google permissions page. There you will find a list of all the apps that have account access. One app, titled Google Docs, is the offender. Revoke its permission immediately, and then change your password.
Tweet may have been deleted
So now that you know what's up, pay extra attention to any Google Docs coming your way. And, well, to anything asking you to click a link and enter your password or share account permission.
TopicsCybersecurityGoogle
U.S. pole vaulter skids to a halt for national anthem2024-11-22 07:04
看完曼城大戰利物浦 理解了什麽是“人類高質量足球”2024-11-22 06:48
魯媒 :青島海牛隊已敲定4名內援 下一個目標球員勞烈斯2024-11-22 06:42
加納媒體 :韓國隊小組實力最弱 但仍舊不可忽視2024-11-22 06:38
U.S. government issues warning on McDonald's recalled wearable devices2024-11-22 06:37
韓喬生點評郭田雨首秀:中國球員需要提高的就是這種態度2024-11-22 05:51
姐姐聲援C羅 :不用證明任何事 以後再讓所有人閉嘴2024-11-22 05:41
四川九牛官宣亞泰中場周大地加盟 曾多次入選U19U22等國字號2024-11-22 05:32
Singapore gets world's first driverless taxis2024-11-22 04:58
卡薩諾 :C羅每天都該祈禱 感謝皇馬時有本澤馬幫他2024-11-22 04:56
Katy Perry talks 'Rise,' her next batch of songs, and how to survive Twitter2024-11-22 06:52
媒體人:國足主帥存在很大不確定性 極有可能開始新一輪選帥2024-11-22 06:47
利物浦也搶他?克洛普看中1點 無關曼聯曼城心頭好2024-11-22 06:33
卸磨殺驢?曝曼聯高層越來越相信 今夏應讓C羅離隊2024-11-22 06:12
Olympics official on Rio's green diving pool: 'Chemistry is not an exact science'2024-11-22 06:01
亞足聯官方 :上海海港退出2022亞冠聯賽2024-11-22 05:38
滬媒:有些中國球員並不職業 金泰延樸成曾被拍到吞雲吐霧2024-11-22 05:25
武磊破門入選西甲本輪最佳陣容 比肩巴薩絕殺英雄2024-11-22 05:21
Donald Trump's tangled web of Russian influence2024-11-22 05:01
瓜帥:梅西對我意味著一切 就像喬丹成就了禪師2024-11-22 04:38