The closest I've ever come to falling for a Gmail phishing attack
21–30 of 289 posts
Re: The closest I've ever come to falling for a Gmail phishing attack
#22It does point out a major problem. Email used to be text only. Then we added attachments that needed to be saved as a file and read with whatever app. Then we went to automatically displaying attached images and having live HTML links. All of these things we do for convenience make this sort of attack more possible.
Re: The closest I've ever come to falling for a Gmail phishing attack
#23For example, they went into one student's account, pulled an attachment with an athletic team practice schedule, generated the screenshot, and then paired that with a subject line that was tangentially related, and emailed it to the other members of the athletic team.
They were using bit.ly to obscure the address (in Russia). We had to take our whole mail system down for a few hours while we cleaned it up.
Re: The closest I've ever come to falling for a Gmail phishing attack
#241. Watermark all images on the in-email preview. 2. You should be able to design a mail scanner which would detect images that look too much like gmail elements and flag them.
Re: The closest I've ever come to falling for a Gmail phishing attack
#25I'm surprised that with Google's image detection technology that Gmail doesn't do image recognition on images with links where the image look like popular document attachment, and send them to spam. Or perhaps they do but the phishers are able to evade it.
Re: The closest I've ever come to falling for a Gmail phishing attack
#26That's scary. Would having 2FA enabled on your Gmail account protect you from this kind of attack?
Re: The closest I've ever come to falling for a Gmail phishing attack
#27The only two things that I think could have prevented me from falling for this is: I don't have images loaded by default for unknown senders, and LastPass wouldn't match the domain and therefore wouldn't show the button to autocomplete on the password box. Depending on how observant I'd be at the moment, I might check the URL bar and see something fishy. But I could fall for this, which is worrying.
It's still a good idea to have an analog backup of really important passwords. Like if you use Gmail and it is the password reset email for everything else, print out the generated password and put it somewhere safe. Just incase your password manager becomes insolvent one day.
Re: The closest I've ever come to falling for a Gmail phishing attack
#28That's scary. Would having 2FA enabled on your Gmail account protect you from this kind of attack?
Re: The closest I've ever come to falling for a Gmail phishing attack
#29Why would you need to sign in if you're already in your gmail? Not to say there's anything obviously wrong, one could easily go there. It does point out a major problem. Email used to be text only. Then we added attachments that needed to be saved as a file and read with whatever app. Then we went to automatically displaying attached images and having live HTML links. All of these things we do for convenience make th…
Re: The closest I've ever come to falling for a Gmail phishing attack
#30To stop being phished always check the domain name and for HTTPS before entering passwords.
(The exception is some sites like Amazon that prompt for a password on certain actions. I wonder if I should worry about something weird happening like a tab left alone a long time impersonating Amazon when I get back to it.)