Efani<p>⚠️ Phishers have found a clever way to spoof Google — and their emails pass all security checks.</p><p>A new DKIM replay phishing attack abuses Google’s own OAuth infrastructure to send fake messages that look 100% legitimate, including passing DKIM authentication.</p><p>What happened:<br>- A phishing email was sent from “no-reply@google.com” <br>- It appeared in the user’s inbox alongside real Google security alerts <br>- The message linked to a fake support portal hosted on sites[dot]google[dot]com — a Google-owned domain <br>- The attacker used Google OAuth to trigger a real security alert to their inbox, then forwarded it to victims </p><p>Why this matters:<br>- DKIM only verifies the headers, not the envelope — allowing this spoof to work <br>- The phishing site was nearly indistinguishable from Google’s actual login portal <br>- Because the message was signed by Google and hosted on a Google domain, it bypassed most users’ suspicions <br>- Similar tricks have been used with PayPal and other platforms, raising broader concerns </p><p>Google has since acknowledged the issue and is working on a fix. But this attack is a reminder:</p><p>Even the most secure-looking emails can be fraudulent. <br>Even Google-signed emails can be weaponized.</p><p>🛡️ At <span class="h-card" translate="no"><a href="https://infosec.exchange/@Efani" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Efani</span></a></span>, we advocate for layered defense — because no one layer is ever enough.</p><p><a href="https://infosec.exchange/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://infosec.exchange/tags/Phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Phishing</span></a> <a href="https://infosec.exchange/tags/Google" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Google</span></a> <a href="https://infosec.exchange/tags/OAuth" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OAuth</span></a> <a href="https://infosec.exchange/tags/DKIM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DKIM</span></a> <a href="https://infosec.exchange/tags/EmailSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EmailSecurity</span></a> <a href="https://infosec.exchange/tags/EfaniSecure" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EfaniSecure</span></a> <a href="https://infosec.exchange/tags/ThreatIntel" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ThreatIntel</span></a></p>