时间:2026-01-08 09:27:57 来源:网络整理编辑:知識
A sophisticated phishing attack is racing across the internet, and may already have hit your inbox.
A sophisticated phishing attack is racing across the internet, and may already have hit your inbox.
The definitely not-legit email disguises itself as an official message from Google alerting you that someone wants to share a Google Doc with you. Notifications of this sort are common and often wouldn't raise an eyebrow.
However, clicking through this particular link and taking the requested steps will open up your inbox — and potentially everyone on your contact list — to an as-of-yet unknown attacker.
Tweet may have been deleted
And, like we said, the link looks real — complete with a little "Open in Docs" blue box.
DON'T CLICK.Credit: mashableTweet may have been deleted
Just how widespread is this? Numerous reporters at Mashable have received the same phishing email, as have students at Columbia University— as a warning email sent out by a member of the Philosophy department shows. The scam may have even hit the Capitol.
Oops.Credit: MashableTweet may have been deleted
Google confirmed that it is aware of the problem and is looking into it.
According to one Reddit user, once a victim clicks on the fake Google Doc link, he or she is taken to a real Google page prompting you to select an account. After that, they are taken to a new page asking that they allow "Google Docs" to access the account.
Just don't.Credit: Jake SteamIf you click "allow," the attacker can access your account. And all your contacts will likely soon receive a fake Google Doc invite from you.
So, how to tell if that latest Google Doc your friend shared is real or fake? Thankfully, there are a few tell-tale warning signs. First, real Google Doc invites look different than the recent fake. Here's a legit one for comparison:
Lunch!Credit: MashableNotice the Google address at the bottom? And the box border formatting? The fake Google notification doesn't have that.
Second, expand the dropdown option in the menu bar next to the sender's name. Below is a real Google notification for a shared Google Doc.
Credit: mashableLastly, the spam email is also addressed to "[email protected]," which is an account with the disposable email service Mailinator.
If you did happen to click on the malicious link and allowed attackers into your account, you can revoke that access relatively easily. First, go to your Google permissions page. There you will find a list of all the apps that have account access. One app, titled Google Docs, is the offender. Revoke its permission immediately, and then change your password.
Tweet may have been deleted
So now that you know what's up, pay extra attention to any Google Docs coming your way. And, well, to anything asking you to click a link and enter your password or share account permission.
TopicsCybersecurityGoogle
Researchers create temporary tattoos you can use to control your devices2026-01-08 09:12
孫興慜:有人說我這腳射門像蒙的 但進球了就好2026-01-08 08:58
名記 :巴薩邊衛埃莫森將加盟熱刺 轉會費3000萬歐2026-01-08 08:53
國安副總:李明強調重視一線隊建設 俱樂部會越來越好2026-01-08 08:18
J.K. Rowling makes 'Harry Potter' joke about Olympics event2026-01-08 08:10
曝拜仁欲效仿去年再炫壓哨簽 正醞釀大手筆轉會2026-01-08 07:56
日本國腳乾貴士回歸加盟大阪櫻花 結束10年旅歐生涯2026-01-08 07:30
中乙衝甲組9月1日開賽青島海牛最被看好 首輪天王山之戰2026-01-08 07:06
Uber's $100M settlement over drivers as contractors may not be enough2026-01-08 06:58
孫興慜:有人說我這腳射門像蒙的 但進球了就好2026-01-08 06:55
Singapore gets world's first driverless taxis2026-01-08 09:05
官方:西漢姆聯簽下23歲中場 林皇前途危機預警2026-01-08 09:04
尤文官方:C羅轉會加盟曼聯 轉會費1500萬歐+800萬歐浮動2026-01-08 09:01
尤文官方 :C羅轉會加盟曼聯 轉會費1500萬歐+800萬歐浮動2026-01-08 08:51
PlayStation Now game streaming is coming to PC2026-01-08 08:35
英超名宿製止球迷群毆 “野蠻人”平息騷亂獲讚2026-01-08 08:25
曼聯集郵葡萄牙球星已成癮 再挖角一大腿現前兆2026-01-08 08:21
周最佳:萊萬戴帽奪MVP 國米新援首秀2球領強陣2026-01-08 08:20
Balloon fanatic Tim Kaine is also, of course, very good at harmonica2026-01-08 07:52
曝萊斯特和多特有意引進奧多伊 目前藍軍拒絕放人2026-01-08 07:49