Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

CousinIT

(9,225 posts)
Wed May 3, 2017, 08:46 PM May 2017

Did Someone Just Share a Random Google Doc With You? DO NOT CLICK ANY LINKS IN IT.

Journalists in newsrooms across the United States are swapping warnings about what appears to be a widespread phishing attack, sent via a particularly sneaky invitation to a fake Google Doc.

The scope of the attack is not limited to news organizations, but appears to be spreading on a massive scale through people’s contacts. If you’re concerned your account has been compromised, you can go to Google’s security page to adjust permissions. (Look for “manage apps,” and revoke access to untrusted apps.)

Several IT experts are describing the attack as huge, startlingly fast-moving, and perplexing. Just in the course of writing this short post, I received two separate emails that appear to be part of the attack. In one Reddit thread, where people are trading information about the attack, someone describes the scam as “almost undetectable.” But there are clues to look out for—both of the suspicious emails I received were sent to an odd email address, hhhhhhhhhhhhhhhh@mailinator.com, with me blind-copied.

There are two big reasons why this thing is so tricky. For one, it looks legit: An invitation to view a Google Document appears to come from an existing contact. But when a person clicks on the link, the attack immediately replicates itself—meaning, it has the potential to spam all of that person’s contacts with the same message. The second reason it’s so tricky is that it’s unclear what the attack is attempting to do. Phishing is often a way for bad actors to gain unauthorized access to a person’s email or other private accounts, but it’s not yet clear what’s motivating this attack.



https://www.theatlantic.com/technology/archive/2017/05/did-someone-just-share-a-random-google-doc-with-you/525279/?utm_source=atltw
4 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Did Someone Just Share a Random Google Doc With You? DO NOT CLICK ANY LINKS IN IT. (Original Post) CousinIT May 2017 OP
K&R 2naSalit May 2017 #1
Our campus was hit with this today. It is VERY REAL!!! Coventina May 2017 #2
Thanks. k and r oasis May 2017 #3
Simple rule SchrodingersCatbox May 2017 #4
Latest Discussions»General Discussion»Did Someone Just Share a ...