Google Drive phishing scam returns
Despite Google saying it had fixed the flaw allowing hackers to use Google Drive to phish for details, it's still open to attack


Despite claiming to have fixed a security hole in Google Drive last year, criminals are still making use of a Google Drive phishing scam that can steal your email address and password in just a few taps.
Last year, it was revealed hackers were using fake Google Drive documents to force you to enter your email and password, but this year's attack seems to be more sophisticated.
You may receive an email from one of your contacts, granting you access to a document stored in Google Drive. Click on the link and you're taken to the normal Google Drive sign-in screen.
Then, after entering your username and password, you're asked to enter your verification - either your mobile phone number if you have one associated to your account, or your secondary email address.
When you've entered this information, you're forwarded to your Google Drive, but there's no document in sight. You've just had your details phished.
Symantec investigated into the flaw last year and found out the login page is actually hosted on Google's servers and is served on SSL, making it seem very convincing.
"The scammers have simply created a folder inside a Google Drive account, marked it as public, uploaded a file there, and then used Google Drive's preview feature to get a publicly accessible URL to include in their messages," Symantec security expert Nick Johnston explained in a blog post.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
However, it was reportedly fixed soon after, with Google saying: "We've removed the fake pages and our abuse team is working to prevent this kind of spoofing from happening again. If you think you may have accidentally given out your account information, please reset your password."

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
CISA issues warning in wake of Oracle cloud credentials leak
News The security agency has published guidance for enterprises at risk
By Ross Kelly
-
Reports: White House mulling DeepSeek ban amid investigation
News Nvidia is caught up in US-China AI battle, but Huang still visits DeepSeek in Beijing
By Nicole Kobie
-
C-suites consider quantum a serious threat and "amazing" deepfake attacks are just 'months away'
News Deepfake technology has matured at a rapid rate, and video scams are likely to be a on par with the more convincing voice-only campaigns very soon, one expert says
By Rory Bathgate
-
Shiseido reportedly suffers data breach
News The Japanese cosmetics company has been accused of failing to notify affected staff of the leak
By Sabina Weston
-
Almost a quarter of all spam emails were sent from Russia in 2021
News Last year's spam emails mostly centred around money and investment, Bond and Spider-Man movie premieres, and the pandemic
By Sabina Weston
-
HMRC issues scam warning ahead of Self Assessment deadline
News The department stated that 2021 has already seen 797,010 tax-related scams reported
By Sabina Weston
-
Ofcom report reveals alarming uptick in smishing attacks
News Text-based scams now more common than phone calls among young adults
By Sabina Weston
-
Smishing attacks increased 700% in first six months of 2021
News Which? has urged businesses to play their part to protect people from text message scams
By Sabina Weston
-
Delivery scams become most common form of smishing
News Cyber security provider Proofpoint finds a major increase in the number of threat actors impersonating postal services
By Sabina Weston
-
NCSC simplifies Outlook scam-reporting tool
News Users are now able to report phishing emails with just one click
By Sabina Weston