Scammers are now sending phishing emails on Gmail with verified checkmark

Main Image
  • Like
  • Comment
  • Share

Google introduced a blue verified checkmark for Gmail to combat phishing emails and attackers impersonating businesses. However, it seems like scamsters have got their way around the safety mechanism thereby impersonating verified blue checkmark on phishing emails.

Earlier last month, Google introduced a blue verified checkmark on Gmail for organizations and companies that have been verified. The feature uses signals such as Brand Indicators for Message Identification (BIMI), Verified Mark Certified (VMC), and Domain-based Message Authentication, Reporting, and Conformance (DMARC) to put a blue-colored verified checkmark against emails of businesses to signal that it is legit.

With the latest information coming from cybersecurity engineer Chris Plummer, scammers have been able to bypass Google’s verified checkmark feature thereby impersonating businesses such as UPS in the tweet tagged below. For the unversed, the screenshot shows the UPS logo along with a notification stating that “kelerymjrlna.ups.com” is a verified email. There’s a blue-colored verified checkmark on the email as well.

Having a verified check mark against unauthorized emails will make it difficult for users to detect phishing attacks. It can open a whole new avenue for scammers to attack innocent users who might click on emails and links before ending up being phished.

However, when reported, Google tagged the bug as “won’t fix – intended behavior” and closed it lazily without any further resolution. It means if more attackers get to know the bug, they will use it to send phishing emails leading to a catastrophe. It is an irony given the fact that Google’s blue verified checkmark feature was introduced to end phishing emails.

Related Articles

ImageOnePlus Accidentally Leaks the Camera Specs of the OnePlus 15: 50MP JN5 85mm f2.8 Telephoto

OnePlus has quietly dropped fresh camera samples from its upcoming flagship, the OnePlus 15, showcasing its new imaging engine. The images reveal shots captured at 85 mm focal length with f2.8 aperture. When I downloaded the images, I was surprised to find the EXIF data attached. So, I checked the EXIF data and found the …

ImageTwitter Blue to redebut on December 2 with three color-graded checkmarks

Twitter CEO Elon Musk has recently announced that Twitter Blue will be relaunched on December 2. This time the verification system will also have three different colour-coded checkmarks to verify the user’s identity. Twitter will be adding gold checkmarks to the accounts owned by the companies, grey checkmarks to be provided to government bodies, and …

ImageTwitter will ask for phone number verification to curb impersonation

Twitter Blue is live and active now, and all the users around the globe are taking a keen interest. In a recent update, Twitter has announced that phone verification will be required on the platform to get to the blue tick or the verified mark. This step is being taken to avoid impersonation. A picture …

ImageHow to unsend an email in Gmail: Know more about ‘Undo Send’ feature of Gmail

Your work may require you to send several emails to various kinds of connections daily. In the process, you might have faced the issue of sending the wrong email or forgetting to attach the files immediately after hitting the send button. Well, if you are a Gmail user, Google lets you rectify your mistake by …

ImageGmail signature: How to create a signature for every email on your Gmail account

No matter whether you’re an individual, or a small or large company, Gmail is one of the most popular email providers all around the globe. Because its infrastructure wasn’t enough to provide customers with 1GB of storage back in 2004 during the launch, the technology community is now enthralled with its rich host of features. …

Discuss

Be the first to leave a comment.