Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

More than a million people were affected by the Google Docs phishing attack

A small percentage of Gmail users — which is still a lot of users — were affected.

Preparations Are Made To Commemorate The 950th Anniversary Of The Battle of Hastings
Preparations Are Made To Commemorate The 950th Anniversary Of The Battle of Hastings
Leon Neal / Getty

The Google Doc phishing scam that started spreading Wednesday compromised more than one million Gmail users.

“We have taken action to protect users against an email spam campaign impersonating Google Docs, which affected fewer than 0.1 percent of Gmail users,” a spokesperson said in a statement. “We were able to stop the campaign within approximately one hour.”

There were one billion active Gmail users every month as of February 2016, a figure that has undoubtedly increased since.

Gmail users started tweeting on Wednesday about the scam, in which email address hhhhhhhhhhhhhhhh@mailinator.com sent messages to users under the name of someone in their address book, inviting them to view what appeared to be a Google Doc.

If you clicked, the hacker gained access to your emails and email contacts, and was able to send and delete emails in your account, according to the Electronic Frontier Foundation.

Google responded Wednesday by releasing a new security feature for Gmail on Android that warns users when they click on a suspicious link in an email.

The hack highlighted a flaw in Google’s security design. When you look at the list of apps with access to your Gmail account, the page doesn’t distinguish between apps that are made by Google and apps that aren’t.

In a case where the app in question is masquerading as a Google product such as Google Docs, this design creates problems.

Here’s the full statement from a Google spokesperson about the extent of the attack:

“We realize people are concerned about their Google accounts, and we’re now able to give a fuller explanation after further investigation. We have taken action to protect users against an email spam campaign impersonating Google Docs, which affected fewer than 0.1% of Gmail users. We protected users from this attack through a combination of automatic and manual actions, including removing the fake pages and applications, and pushing updates through Safe Browsing, Gmail, and other anti-abuse systems. We were able to stop the campaign within approximately one hour. While contact information was accessed and used by the campaign, our investigations show that no other data was exposed. There’s no further action users need to take regarding this event; users who want to review third party apps connected to their account can visit Google Security Checkup.”

Additional reporting by April Glaser.


This article originally appeared on Recode.net.

More in Technology

Podcasts
Are humanoid robots all hype?Are humanoid robots all hype?
Podcast
Podcasts

AI is making them better — but they’re not going to be doing your chores anytime soon.

By Avishay Artsy and Sean Rameswaram
Future Perfect
The old tech that could help stop the next airborne pandemicThe old tech that could help stop the next airborne pandemic
Future Perfect

Glycol vapors, explained.

By Shayna Korol
Future Perfect
Elon Musk could lose his case against OpenAI — and still get what he wantsElon Musk could lose his case against OpenAI — and still get what he wants
Future Perfect

It’s not about who wins. It’s about the dirty laundry you air along the way.

By Sara Herschander
Life
Why banning kids from AI isn’t the answerWhy banning kids from AI isn’t the answer
Life

What kids really need in the age of artificial intelligence.

By Anna North
Culture
Anthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque messAnthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque mess
Culture

“Your AI monster ate all our work. Now you’re trying to pay us off with this piece of garbage that doesn’t work.”

By Constance Grady
Future Perfect
Some deaf children are hearing again because of a new gene therapySome deaf children are hearing again because of a new gene therapy
Future Perfect

A medical field that almost died is quietly fixing one disease at a time.

By Bryan Walsh