Tech expert warns of ‘extremely sophisticated’ new Gmail scam claiming to be from 'law enforcement'
Share and Follow

It’s a digital wolf in sheep’s clothing.

Phishing messages are becoming harder to spot as they mimic legitimate communication more closely. Some experts are now warning about an extremely “sophisticated” scheme that impersonates Google in order to steal user accounts through fraudulent Gmail messages.

Nick Johnson, the lead developer of Ethereum Name Service (ENS), brought this digital Trojan Horse to light in a series of X posts.

One individual shared their experience of being targeted by this highly deceptive phishing attack. They emphasized the deceptiveness of the scheme, pointing out that it takes advantage of a vulnerability within Google’s system. Despite being aware of this issue, Google has yet to address it, making it a growing concern.

In this case, the phishing scam was disguised as an official request by law enforcement.

The fraudulent message claimed to be notifying the recipient of a subpoena sent to Google LLC by law enforcement. It requested the recipient to review the case details or raise objections through a provided link to Google Support Case. This type of manipulation aims to deceive users into unknowingly giving away their account information.

Upon clicking on “upload additional documents” or “view case,” the user is taken to a sign-in page to input their credentials, whereupon bad actors will presumably use them to commander their account.

“I haven’t gone further to check,” Johnson noted.

The correspondence was particularly insidious as it linked to a very convincing ‘support portal’ page.

The cyberspoofers also used Google Sites — a free web-based platform for creating websites without needing coding skills — “because they know people will see the domain is and assume it’s legit,” said Johnson.

To make things more confusing, the email originated from an official no-reply on Google’s domain and was filed “in the same conversation as other, legitimate security alerts,” the tech whiz warned.

How did the hackers manage to fly under the radar? Johnson pointed to “two vulnerabilities in Google’s [infrastructure] that they have declined to fix.”

He wrote that the legacy sites.google.com product dates back to “before Google got serious about security,” and allows anyone to host content on a google.com subdomain, including nefarious embeds and scripts such as the above.

“Obviously, this makes building a credential harvesting site trivial; they simply have to be prepared to upload new versions as old ones get taken down by Google’s abuse team,” Johnson said.

Fortunately, there are a few ways to suss out this masquerade.

For one, while the header is signed by accounts.google.com, it is sent via privateemail.com and sent to the address “me@blah,” the cybersecurity maven wrote.

Also suspect, per Johnson is that there is “a lot of whitespace” below the phishing message “followed by ‘Google Legal Support was granted access to your Google Account’ and the odd me@… email address again.”

In light of the incident, Johnson is calling on Google to disable scripts and arbitrary embeds in Sites to make Gmail less susceptible to phishing.

The Post has contacted Google for comment.

Share and Follow
You May Also Like
Who is Nick Reiner? Rob Reiner's son arrested after his death

Rob Reiner’s Son Nick Reiner in the Spotlight Following Recent Arrest

A 32-year-old man has been apprehended following the tragic discovery of his…
Gun jams as shoplifting suspect tries to shoot Ohio police officer at point-blank range in wild bodycam video

Gun Malfunction Saves Ohio Police Officer During Close-Range Encounter with Shoplifting Suspect, Captured on Bodycam Video

An intense video captures the harrowing moment when a suspected shoplifter attempted…
Australian immigrant who tackled gunman 'riddled with bullets,' but 'said he’d do it again,' lawyer says

Heroic Act at Bondi Beach: Fundraiser for Brave Australian Who Foiled Terrorist Attack Soars Past $2.6M

Over $2.6 million has been collected to support a man hailed as…
Australian PM defies calls for broad independent investigation of Bondi Beach massacre

Australian PM Stands Firm Against Demands for Independent Probe into Bondi Beach Tragedy

Australian Prime Minister Anthony Albanese has decided against initiating a Royal Commission…
This image made from video provided by the United States Geological Survey (USGS) shows a muddy eruption at Black Diamond Pool in Yellowstone National Park on Saturday, Dec. 20, 2025. (U.S. Geological Survey via AP)

Video Captures Dramatic Mud Eruption at Yellowstone’s Black Diamond Pool

“Kablooey!” This is how experts from the U.S. Geological Survey depicted a…
Forget Florida! Retirees ditching golf and sun for this unlikely city

Why Retirees Are Swapping Florida Sunshine for Culture-Rich Living in Unexpected City

Mention ‘retirement’ in the United States, and a common vision emerges for…
FAA warning after THREE passenger jets in panic to avoid Musk rocket

FAA Issues Urgent Alert: Three Passenger Jets in Close Call with SpaceX Rocket

A SpaceX test flight in January met a fiery end in under…
Bowen Yang breaks down crying as he leaves SNL after seven years

Emotional Farewell: Bowen Yang’s Tearful Goodbye After 7 Memorable Years on SNL

Bowen Yang was overcome with emotion during his final sketch on “Saturday…