• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Exclusive

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

TechPointCloud

Everyone Is Falling For This Frighteningly Effective Gmail Scam

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
January 18, 2017, 11:37 AM ET

Security researchers have identified a “highly effective” phishing scam that’s been fooling Google Gmail customers into divulging their login credentials. The scheme, which has been gaining popularity in the past few months and has reportedly been hitting other email services, involves a clever trick that can be difficult to detect.

Researchers at WordFence, a team that makes a popular security tool for the blog site WordPress, warned of the attack in a recent blog post, noting that it has been “having a wide impact, even on experienced technical users.” (See these people, whose accounts were targeted.)

Here’s how the swindle works. The attacker, usually disguised as a trusted contact, sends a boobytrapped email to a prospective victim. Affixed to that email, there appears to be a regular attachment, say a PDF document. Nothing seemingly out of the ordinary.

Get Data Sheet, Fortune’s technology newsletter.

But the attachment is actually an embedded image that has been crafted to look like a PDF. Rather than reveal a preview of the document when clicked, that embedded image links out to a fake Google (GOOGL) login page. And this is where the scam gets really devious.

https://twitter.com/tomscott/status/812265182646927361

Everything about this sign-in page looks authentic: the Google logo, the username and password entry fields, the tagline (“One account. All of Google.”). By all indications, the page is a facsimile of the real thing. Except for one clue: the browser’s address bar.

google login page
Screenshot of Google login page

Even there, it can be easy to miss the cue. The text still includes the “https://accounts.google.com,” a URL that seems legitimate. There’s a problem though; that URL is preceded by the prefix “data:text/html.”

WordFence gmail phishing scam
Via WordFence

In fact, the text in the address bar is what’s known as a “data URI,” not a URL. A data URI embeds a file, whereas a URL identifies a page’s location on the web. If you were were to zoom out on the address bar, you would find a long string of characters, a script that serves up a file designed to look like a Gmail login page. This is the trap.

As soon as a person enters her username and password into the fields, the attackers capture the information. To make matters worse, once they gain access to a person’s inbox, they immediately reconnoiter the compromised account and prepare to launch their next bombardment. They find past emails and attachments, create boobytrapped-image versions, drum up believable subject lines, and then target the person’s contacts.

And so the vicious cycle of hijackings continues.

For more on email, watch:

autoplay=””]

Google[/hotlink] Chrome users can protect themselves by checking the address bar and making sure a green lock symbol appears before entering their personal information into a site. Because scammers have been known to create HTTPS-protected phishing sites, which also display a green lock, it’s also important to make sure this appears alongside a proper, intended URL—without any funny business preceding it.

In addition, people should add two-step authentication, an added layer of security that can help prevent account takeovers. Experts recommend using a dedicated security token as well.

A Google spokesperson acknowledged the scam in an email and directed Fortune to a statement:

We’re aware of this issue and continue to strengthen our defenses against it. We help protect users from phishing attacks in a variety of ways, including: machine learning based detection of phishing messages, Safe Browsing warnings that notify users of dangerous links in emails and browsers, preventing suspicious account sign-ins, and more. Users can also activate two-step verification for additional account protection.

Be on the lookout.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Pope Leo launches an AI commission days before he releases a papal letter alongside Anthropic cofounder Christopher Olah
AIPope
Pope Leo launches an AI commission days before he releases a papal letter alongside Anthropic cofounder Christopher Olah
By Catherina GioinoMay 18, 2026
20 minutes ago
John Ketchum, CEO of NextEra Energy, speaks during BlackRock's 2026 Infrastructure Summit in Washington, DC, on March 11, 2026. Photographer: Daniel Heuer/Bloomberg via Getty Images
EnergyNextEra Energy
NextEra’s $67 billion Dominion takeover creates the world’s largest utility—just in time to win the AI data-center power surge
By Jordan BlumMay 18, 2026
49 minutes ago
Harvard University banners hang in front of a building
CryptoCryptocurrency
Harvard sold off its entire $87 million Ethereum stake just one quarter after buying it
By Jack KubinecMay 18, 2026
1 hour ago
Not the Allbirds effect: Japan’s top bidet maker Toto has been quietly making chip supplies for decades, and the stock market finally noticed
AIChips
Not the Allbirds effect: Japan’s top bidet maker Toto has been quietly making chip supplies for decades, and the stock market finally noticed
By Catherina GioinoMay 18, 2026
2 hours ago
monet
CybersecuritySocial Media
6.7 million people thought they were ripping apart an AI-generated Monet painting. But it was real
By Nick LichtenbergMay 18, 2026
2 hours ago
Photo of Elon Musk
AIOpenAI
Jury rules against Elon Musk in $150 billion lawsuit against OpenAI and Sam Altman
By Sharon GoldmanMay 18, 2026
3 hours ago

Most Popular

The top foreign holders of U.S. debt may soon dump Treasury bonds and bring their money back home, potentially spiking borrowing costs
Economy
The top foreign holders of U.S. debt may soon dump Treasury bonds and bring their money back home, potentially spiking borrowing costs
By Jason MaMay 17, 2026
1 day ago
Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI
AI
Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI
By Jake AngeloMay 16, 2026
2 days ago
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
Politics
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
By Jake AngeloMay 12, 2026
6 days ago
'No one was coming to save me': How Reese Witherspoon built a $900 million company from a problem Hollywood wouldn't fix
Success
'No one was coming to save me': How Reese Witherspoon built a $900 million company from a problem Hollywood wouldn't fix
By Sydney LakeMay 17, 2026
1 day ago
SpaceX heads into a record-shattering IPO with the 'deepest moat that exists today' as investors vow to 'never bet against Elon'
Innovation
SpaceX heads into a record-shattering IPO with the 'deepest moat that exists today' as investors vow to 'never bet against Elon'
By Jason MaMay 16, 2026
2 days ago
Mamdani's New York is coming to tax your private jet. Here's how to prepare
Personal Finance
Mamdani's New York is coming to tax your private jet. Here's how to prepare
By Greg RaiffMay 16, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.