Google appears to have shut down a phishing scam that this week tricked numerous Gmail users into accepting bogus invitations to share a Google Doc with people they know. However, it’s possible that those who fell for the scam, as well as anyone in their email contacts, could be targeted in future phishing schemes.
The Google Docs worm, as security experts are describing it, presented Gmail recipients with a legitimate-looking email that said one of their contacts had invited them to view a shared file in Google Docs. Upon clicking the email, however, users were directed to a link that appeared to come from Google Docs, but actually gave an unverified third-party app access to their email accounts and contacts.
Yesterday, Google said that it had “disabled offending accounts,” removed fake pages and taken steps to “prevent this kind of spoofing from happening again.” The company also began rolling out a new security feature for Gmail on Android that will show a phishing warning if users click on suspicious links in messages.
Millions Could Have Been Affected
While Google did not release any details about how many users might have been affected by the Google Docs worm, computer security analyst Graham Cluley noted in a blog post today that millions could have received such phishing emails.
“The likelihood is that someone was attempting to harvest a large number of contact details, perhaps with the intention of selling them for profit to spammers and scammers,” Cluley said. “The attack appears to have been too aggressive and worm-like to have been intended as a targeted attack against a particular group, but it’s interesting to note that just over a week ago researchers at Trend Micro blogged how the state-sponsored Pawn Storm hacking group was abusing OAuth in a similar fashion in an attempt…