I received an unexpected email from a friend today with a Google doc attachment. It was a friendly note, so friendly that I did consider clicking on it โ even with about 20 years experience watching all manner of hacker tricks. Fortunately, I stopped and asked a simple question, which is almost always enough to separate real email from phishing attacks.
โDid you mean to send me a document?โ
Iโve done this 100 times, and Iโve nearly always received a, โOh no, I must have been hackedโ response. Today, however, was different. Thatโs why Iโm nervous for you.
โYes, I sent it myselfโฆ,โ was the response I got from my friendโs email account. โLog in to view the document.โ
Whoa. Knowing my friend as I do, I could tell this was not written in her chatty style. But outside of that language analysis and my already raised eyebrows, I might have clicked. So I persisted.
โHow is the new home?โ I asked, fishing for any sense that my friend was behind the email. Again, I expected that a hacker wouldnโt bother responding. After all, in a traditional phishing attack like this, itโs likely the bad guy sent out a million of these emails, just hoping to get 100 or so people to click and cough up their login credentials.
Seconds later, I got a response.
โNice and lovely.โ
Two email responses? This was getting interestingโฆand concerning. I now had a pretty strong feeling that a computer criminal was behind the keyboard, but there was still a small chance it was my friend. So I did two things. You can try these two if you think you might be talking to a criminal.
1) I contacted her on Facebook, borrowing from a technique called โout of bandโ authentication. I used a different tool to communicate with her to ask if the email was real. Mind you, itโs possible that both my friendโs Gmail and Facebook accounts were hacked, and the criminal could have โpassedโ this test. But it it at least a good start. If Iโd had more time, I would have sent her a text message from my cellphone, and waited for a reply, which would genuinely qualify as โout of bandโ authentication.
2) I devised a question that a hacker probably couldnโt answer.
โIโm coming to visit (your new city) soon. Remind me what neighborhood are you in?โ
Then, the email fell silent. Again, this isnโt a perfect strategy: a very clever criminal could have hacked into her Facebook account and replied back with her new neighborhood (which, of course, I know). But again, Iโve climbed up the ladder of authentication pretty easily, and also not said anything too offensive.
What does that mean? Many people fall for booby traps because they are simply too polite to say, โThat doesnโt sound like you!โ Criminals rely on social conventions like these to trick us. Such a statement might actually generate a reply like, โI canโt believe you said that. Iโm really offended,โ or similar. Many people fall for that. So having polite but informed banter is a good tool for situations like this.
Those details aside, Iโm writing this up to share with you something that really concerns me. It is incredibly labor intensive for a hacker to reply to notes like mine. That says one thing to me: Someone is trying awfully hard to trick you into surrendering your login information. So watch out.
So what was going on? Iโm pretty sure it was this. Users who click on the attachment are taken to a page that looks like Google docs, but itโs not, and are tricked into logging in to a page controlled by criminals, thereby giving up their Google credentials.
This is bad because a bad guy could send out emails in your name, but really, itโs much worse than that. Millions of people use Gmail as their password recovery tool, so when hacker gains access to it, s/he can often use it to hack other accounts. For example, they go to an online banking site, click on โI forgot my password,โ and have a password email reset link sent to your Gmail account. The problem can spiral pretty quickly.
My friend wrote an hour later or so to say she knew nothing about the emails, and a hacker must have broken in. Sheโs in full recovery mode now. If this has happened to you, Google has instructions on what to do.
Meanwhile, NEVER click on a link to an attachment you donโt expect, even if it comes from a friend. And even if that โfriendโ asks you to click on it several times. On the Internet, nobody knows youโre a dog. And you donโt know if youโre talking to a hacker, either.
[Editorโs note: If you suspect your personal data has been compromised by a hacker, itโs important to monitor your financial accounts daily. In addition, you can check your credit reports for fraudulent accounts or other errors that could be a result of identity theft. Monitoring your credit scores, which you can do for free through Credit.com, can also tip you off to identity fraud if you see a sudden, unexpected drop in your scores.]
This post originally appeared on BobSullivan.net.
More on Identity Theft:
- Identity Theft: What You Need to Know
- What Should I Do If Iโm a Victim of Identity Theft?
- How Credit Impacts Your Day-to-Day Life
Image: Tyler Olson
You Might Also Like
October 19, 2023
Identity Theft and Scams
May 17, 2022
Identity Theft and Scams
November 19, 2020
Identity Theft and Scams