The FBI has issued an alert about a sophisticated new phishing campaign targeting Gmail users that uses artificial intelligence to create convincing impersonation attacks. The scheme is part of a broader surge in AI-powered phishing attacks that have affected 96 percent of organizations in 2024.
According to FBI reports, the attack begins with a phone call that appears to originate from Google through spoofed caller ID. The caller claims to represent Google and warns the target about potential unauthorized overseas access attempts on their account. The initial contact is followed by a fraudulent email, purportedly from Google, containing a code that victims are urged to use to secure their account. However, entering this code actually grants attackers access to the victim’s Gmail account.
The scam’s sophistication comes from its use of AI technology to impersonate legitimate Google representatives and generate convincing communications. For organizations, successful breaches via these phishing attacks can result in data loss, theft of intellectual property, and disruption of operations. The attack method is particularly concerning as it combines social engineering with advanced AI capabilities, making it more difficult for users to identify fraudulent communications.
The FBI advises Gmail users never to share login credentials or passwords over the phone. If users receive suspicious calls, they should disconnect and contact the company directly through official customer service channels. Google offers several advanced protection features that users can enable, including passkeys and smart keys, which provide additional security even if login credentials are compromised. Recently, Google made passkeys the default login option for personal accounts as part of its broader push toward passwordless authentication.
These security measures are part of Google’s broader effort to combat sophisticated phishing attempts. The Advanced Protection Program, designed for users at higher risk of targeted attacks, provides enhanced security features and has recently been streamlined to make enrollment easier through passkey support. The advanced protection features can help prevent unauthorized access even in cases where attackers have obtained login information and passwords.
The latest threat follows recent FBI and CISA warnings about vulnerabilities in traditional authentication methods, including SMS-based two-factor authentication, highlighting the importance of adopting more secure authentication technologies like biometrics and passkeys.
Sources: Hipther, The Star, Bank Info Security
Follow Us