Tagged: subpoena Toggle Comment Threads | Keyboard Shortcuts

  • Geebo 8:00 am on May 8, 2025 Permalink | Reply
    Tags: , , , , , subpoena   

    Google Spoof Scam Exposes Flaws 

    By Greg Collier

    Phishing has evolved far beyond clumsy scams riddled with typos and generic threats. It now wears the mask of legitimacy, often cloaked in branding and technical language convincing enough to fool even savvy users. A recent example of this growing trend involves an especially deceptive attack using Google’s own infrastructure as a weapon.

    Cybercriminals have been exploiting Google Sites and other services to distribute phishing emails that appear to originate from Google’s own domain. In this case, a message disguised as a legal request from law enforcement was sent to users, complete with references to subpoenas and the need to review case materials. The message urged the recipient to click on a link to a Google support page, which in reality led to a page designed to harvest login credentials.

    The trap is insidious. The phishing page is hosted on a subdomain of Google.com, lending a false sense of trust to unsuspecting users. Because the site is built with Google Sites, it carries the appearance of a legitimate Google interface. The attackers further muddy the waters by ensuring the phishing email lands in the same thread as previous legitimate security alerts, increasing the likelihood that users will trust it.

    The deeper issue lies in how Google has allowed this vulnerability to persist. The legacy version of Google Sites, still accessible today, permits anyone to publish content on a Google.com subdomain. This opens the door to abuses like malicious scripts and fake credential portals. Google has been warned about this gap in security, yet the core issues remain unresolved. While some reactive measures have been taken, the architecture still leaves room for repeat abuse.

    This raises a broader concern about corporate responsibility in digital security. Google has positioned itself as a cornerstone of online identity and infrastructure, and with that status comes the obligation to protect its users proactively. Allowing these phishing schemes to exploit the trust associated with the Google name creates not just a security risk, but an erosion of that trust.

    Google’s statement suggests users enable two-factor authentication and passkeys as a defense. While this is sound advice, it shifts the burden onto individuals to compensate for shortcomings in the platform’s safeguards. The more sustainable solution would be for Google to close the loopholes that allow bad actors to operate under its umbrella in the first place.

    As phishing continues to mimic trusted entities more convincingly, users must remain cautious. But the companies whose tools are being weaponized also bear responsibility. Until tech giants like Google take these exploits seriously and move swiftly to harden their platforms, the digital wolves will keep getting in, dressed in ever more convincing sheep’s clothing.

     
  • Geebo 8:00 am on September 20, 2023 Permalink | Reply
    Tags: , , , , , pump switching, , subpoena   

    Scam Round Up: The gas pump switching scam and more 

    Scam Round Up: The gas pump switching scam and more

    By Greg Collier

    There’s a new version of the advance fee scam circulating on Facebook Marketplace. An advance fee scam is when a scammer promises something valuable for free then asks for some type of payment for things like taxes or shipping.

    In this case, scammers are offering a free laptop, but it comes with a sob story. The ad claims the seller bought their spouse a new ‘laptop pro’, but they caught their spouse cheating and want to give the laptop away as a form of punishment.

    The ad almost tips itself off as being a scam, since the gender of the spouse switches back and forth in the description.

    “I am giving out this laptop Pro that I bought to surprise my husband for her birthday but then caught her cheating on me,” the scammer wrote. “I know I could sell it and get my money back, but I want to show her I gave it away for nothing like her is to me.”

    The catch is, once someone responds to the ad, the seller asks for a $70 shipping fee, and the laptop is never delivered. Scammers are also using hijacked Facebook accounts. So if you see a friend listing this for sale, you may want to let them know.

    ***

    A new version of the jury duty scam has popped up in Florida, and its targets are more vulnerable than the typical jury duty scam victim. Instead of just calling people at random and threatening them with arrest for supposedly missing jury duty, scammers are now targeting people who have actually been subpoenaed.

    Subpoenas are a matter of public record, and scammers are using these records to target their victims. Like the jury duty scam, the scammers are posing as the local police or court system and demanding cash from victims to avoid arrest. The scammers are asking their victims to meet them in person.

    However, also like the jury duty scam, no law enforcement agency or court will ever call you and threaten you with arrest if you don’t make an immediate payment. If any kind of legal fine ever needs to paid, a person would be notified by mail.

    ***

    Police in the Philadelphia area are warning consumers about a gas pump scam. They call it the pump switching scam, and it starts when someone approaches a victim at the gas pumps and insists on pumping their gas for them. According to the police, the scammers are quite insistent about it.

    If a victim agrees to this, the scammer won’t return the nozzle to the pump and will continue to fill the tanks of people who drive up for $20 cash. This will continue until the victim’s card hits its limit or the police arrive.

    To protect yourself from this scam, always return the nozzle to the pump and end the transaction. You can also prepay inside the gas station. If you do pay at the pump, also make sure you print out a receipt.

     
c
Compose new post
j
Next post/Next comment
k
Previous post/Previous comment
r
Reply
e
Edit
o
Show/Hide comments
t
Go to top
l
Go to login
h
Show/Hide help
shift + esc
Cancel