Gmail warns users to secure accounts after 'malicious' AI hack confirmed
Share and Follow

Sophisticated scams fueled by artificial intelligence are threatening the security of billions of Gmail users. security warning issued

The article from Forbes issues a warning about the increasing sophistication of AI technology in phone calls, which can now sound remarkably human. This advancement opens the door for potential cyber threats as malicious individuals may use AI to deceive the email service’s extensive user base of 2.5 billion into revealing their login credentials.

The outlet reported that the cybercriminals deploy phone calls posing as Google support — complete with a caller ID that looks convincingly legitimate. The technician might say the person’s account has been compromised in some way, or that they are attempting an account recovery.


Hand holding a mobile phone displaying the Google logo with the Gmail logo in the background, taken in Ankara, Turkiye
“She sounded like a real engineer, the connection was super clear, and she had an American accent,” Latta told Forbes. Anadolu via Getty Images

The so-called support agent will then send an email to the user’s Gmail account from what appears to be a legitimate Google email address to confirm the account was compromised and receive a code to recover the account.

For Zach Latta, the founder of the Hack Club, this is where he stopped the elaborate scam.

“She sounded like a real engineer, the connection was super clear, and she had an American accent,” Latta told Forbes.

Despite how real the voice on the other end of the line sounds, however, it is a scheme to trick customers into handing over precious login information to gain access to their accounts.

Garry Tan, the founder of venture capital firm Y Combinator, issued a “public service announcement” on X after receiving convincing phishing emails and phone calls.

“They claim to be checking that you are alive and that they should disregard a death certificate filed that claims a family member is recovering your account,” he wrote. “It’s a pretty elaborate ploy to get you to allow password recovery.”


Male hand holding a smartphone displaying Google GMail app interface in an office environment
“It’s a pretty elaborate ploy to get you to allow password recovery,” said Tan. Diego – stock.adobe.com

Simiarly, Sam Mitrovic, a Microsoft solutions consultant, experienced the same phenomenon months ago, according to a blog post written at the time.

He recalled receiving a Google account recovery attempt notification, followed less than an hour later by a phone call that looked like it was from the tech company, but he ignored it. A week later, it happened again. This time, he picked up.

“It’s an American voice, very polite and professional. The number is Australian,” he recounted, adding that he verified the phone number on an official Google support page.

“He introduces himself and says that there is suspicious activity on my account. He asks if I’m traveling, when I said no, he asks if I logged in from Germany to which I reply no.”

Then, the agent informs Mitrovic that “someone has had access to my account for a week” and was offering to help him secure it, but, luckily, he noticed that the follow-up email sent by the caller was a spoofed email address and stopped answering.

“The caller said ‘Hello,’ I ignored it then about 10 seconds later, then said ‘Hello’ again,” he described. “At this point I released it as an AI voice as the pronunciation and spacing were too perfect.”

Upon double-checking his log-in sessions in his Google account settings, he saw that the only log-ins were his own.

“Despite many red flags upon closer inspection, this call seemed legitimate enough to trick many people,” he warned.

“The scams are getting increasingly sophisticated, more convincing and are deployed at ever larger scale.”

To protect yourself and your accounts from malicious actors, Forbes advised turning on “Advanced Protection,” which, according to a Google spokesperson, “takes extra steps to verify your identity” with the use of passkeys and smart keys to keep your account secure, even if hackers have your credentials.

Share and Follow
You May Also Like
Chicago police warn of more armed robberies of businesses in Brighton Park, Jefferson Park, Bucktown, Montclare, West Beverly

St. Paul Incident: ICE Agent Opens Fire After SUV Collision with Cuban Man, Reports DHS

ST. PAUL, Minn. — A dramatic confrontation unfolded in Minnesota’s capital on…
'I go with a shepherd's heart': Bishop Ronald Hicks speaks on being named to lead New York Archdiocese

Bishop Ronald Hicks Embraces New Role as Leader of New York Archdiocese with a Shepherd’s Heart

Bishop Ronald Hicks, recently appointed leader of the New York Archdiocese, gave…
‘It: Chapter Two’ and 'The Wire' star James Ransone has died

Beloved Actor James Ransone, Known for ‘It: Chapter Two’ and ‘The Wire,’ Passes Away

James Ransone, known for his memorable roles in horror films and television…
60 Minutes abruptly drops Trump deportation segment at the last minute

60 Minutes Makes Unexpected Decision to Pull Trump Deportation Segment Just Before Airing

In an unexpected move, “60 Minutes” has postponed the airing of a…
Iran executes man convicted of spying for Israeli intelligence

Iran Executes Convicted Israeli Spy: Unveiling the High-Stakes Espionage Drama

Iranian authorities have executed a man accused of espionage for Israel’s intelligence…
DOJ forced into Epstein files U-turn after Trump photos vanished

DOJ Backtracks on Epstein Files: Missing Trump Photos Spark Controversy

The Department of Justice recently found itself in a tricky situation regarding…
Internet slow? Map reveals which provider is fastest at every Alabama address

Discover Alabama’s Fastest Internet Provider: Unveiling the Ultimate Speed Map for Your Address

(NEXSTAR) – If you’re constantly dealing with web pages failing to load…
CBS pulls '60 Minutes' episode about CECOT before premiere

CBS Withdraws ’60 Minutes’ Episode on CECOT Ahead of Scheduled Premiere

Just hours before its scheduled Sunday broadcast, there was an unexpected change…