• About
  • Landing Page
  • Buy JNews
Newsletter
Impact Crypto News
Advertisement
  • Home
  • DeFi News
  • EVM News
    • Avalanche Network
    • Ethereum
    • Fantom Opera Chain
    • Harmony Chain
    • Huobi Eco Chain
    • Polkadot Chain
    • Polygon Chain
  • NFT News
  • Altcoin News
  • Crypto News
    • Crypto Regulation News
    • Bitcoin
    • Blockchain
    • Crypto Exchanges
    • Crypto Mining
    • Metaverse
    • Scam News
    • Web 3.0
No Result
View All Result
  • Home
  • DeFi News
  • EVM News
    • Avalanche Network
    • Ethereum
    • Fantom Opera Chain
    • Harmony Chain
    • Huobi Eco Chain
    • Polkadot Chain
    • Polygon Chain
  • NFT News
  • Altcoin News
  • Crypto News
    • Crypto Regulation News
    • Bitcoin
    • Blockchain
    • Crypto Exchanges
    • Crypto Mining
    • Metaverse
    • Scam News
    • Web 3.0
No Result
View All Result
Impact Crypto News
No Result
View All Result
Home Crypto News Scam News

Phishing scammers now exploiting Google’s infrastructure to target crypto users

IMPACTCRYPTO by IMPACTCRYPTO
April 16, 2025
in Scam News
56 2
0
Phishing scammers now exploiting Google’s infrastructure to target crypto users
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter



Phishing scammers now exploiting Google’s infrastructure to target crypto users

Phishing scams targeting crypto users have become more advanced, with attackers abusing Google’s infrastructure to conduct highly convincing attacks.

On April 16, Nick Johnson, the founder and lead developer of Ethereum Name Service (ENS), raised concerns over a fresh method cybercriminals use to compromise Gmail accounts and potentially target associated crypto wallets.

How phishing attackers are using Google to their advantage

According to Johnson, the attackers exploit a loophole in Google’s ecosystem that allows them to send phishing emails that appear genuine security alerts from the tech giant itself.

These emails are signed with valid DomainKeys Identified Mail (DKIM) signatures, enabling them to bypass spam filters and appear authentic to recipients.

Once opened, these emails direct users to a counterfeit support portal hosted on a Google subdomain. This fake page prompts victims to log in and upload sensitive documents.

However, Johnson warned that the attackers are likely harvesting credentials, which could compromise Gmail accounts and any services linked to those emails.

The phishing sites are built using Google’s Sites platform, which allows custom scripts and embedded content.

While this flexibility benefits legitimate users, it also allows malicious actors to create convincing phishing portals. Even more concerning is that there’s currently no way to report abuse directly through the Google Sites interface, making it easier for attackers to keep their content online.

He said:

“Google long ago realised that hosting public, user-specified content on google.com is a bad idea, but Google Sites has stuck around. IMO they need to disable scrips and arbitrary embeds in Sites; this is too powerful a phishing vector.”

To further enhance the illusion of legitimacy, the scammers create a Google OAuth application that formats and shares the phishing message. These messages are always complete with structured text and what appears to be contact information for Google Legal Support.

Google’s response

Johnson reported that he submitted a bug report to Google about this vulnerability.

Still, the search engine giant reportedly stated that the features work as intended and do not constitute a security issue.

Johnson wrote:

“I’ve submitted a bug report to Google about this; unfortunately they closed it as ‘Working as Intended’ and explained that they don’t consider it a security bug.”

Nevertheless, he urged Google to consider limiting script and embedding functionality to help prevent future abuse.

This incident highlights the increasing sophistication of phishing campaigns within the crypto space. According to Scam Sniffer, nearly 6,000 users lost around $6.37 million to phishing scams in March 2025 alone. In the first quarter of the year, 22,654 victims suffered total losses of $21.94 million.

Mentioned in this article
Latest Alpha Market Report





Source link

Related articles

Binance CEO hacked by cell carrier exploit that likely leaves your own crypto exposed

Binance CEO hacked by cell carrier exploit that likely leaves your own crypto exposed

December 10, 2025
Silk Road crypto activity resurfaces as dormant Bitcoin wallets move again

Silk Road crypto activity resurfaces as dormant Bitcoin wallets move again

December 10, 2025
Tags: bitcoin newsCryptocrypto analysiscrypto newsEthoz EdgeExploitingGooglesInfrastructureLatest bitcoin newslatest crypto newsPhishingScammersTargetUsers
Share76Tweet47

Related Posts

Binance CEO hacked by cell carrier exploit that likely leaves your own crypto exposed

Binance CEO hacked by cell carrier exploit that likely leaves your own crypto exposed

by IMPACTCRYPTO
December 10, 2025
0

Binance co-CEO Yi He said her WeChat account was hijacked on Dec. 10 after a cell number tied to the...

Silk Road crypto activity resurfaces as dormant Bitcoin wallets move again

Silk Road crypto activity resurfaces as dormant Bitcoin wallets move again

by IMPACTCRYPTO
December 10, 2025
0

Silk Road-tagged wallets sent $3.14 million in Bitcoin across 176 transfers this week. The transactions are the most significant Silk...

Fake DBS crypto app scam exposes rising investor risks in India

Fake DBS crypto app scam exposes rising investor risks in India

by IMPACTCRYPTO
December 8, 2025
0

Retired engineer loses ₹1.28 crore to a fake trading app promoted through a WhatsApp investment group. Police warn of rising...

US crackdown exposes Burma crypto scam network using fake trading sites

US crackdown exposes Burma crypto scam network using fake trading sites

by IMPACTCRYPTO
December 3, 2025
0

DOJ seizes Burma-linked trading domains used for major crypto scam operations. Fraud network tied to Tai Chang compound used fake...

South Korea’s Upbit hack puts spotlight on Solana security and exchange safeguards

South Korea’s Upbit hack puts spotlight on Solana security and exchange safeguards

by IMPACTCRYPTO
November 27, 2025
0

About 54 billion won in tokens moved to an external wallet on Nov. 27. Around 12 billion won in Solaire...

Load More

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.
No Result
View All Result
  • Home
  • DeFi News
  • EVM News
    • Avalanche Network
    • Ethereum
    • Fantom Opera Chain
    • Harmony Chain
    • Huobi Eco Chain
    • Polkadot Chain
    • Polygon Chain
  • NFT News
  • Altcoin News
  • Crypto News
    • Crypto Regulation News
    • Bitcoin
    • Blockchain
    • Crypto Exchanges
    • Crypto Mining
    • Metaverse
    • Scam News
    • Web 3.0

© 2018 JNews by Jegtheme.