Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse

Report 4293

Associated Incidents

Incident 83920 Report
Purportedly AI-Driven Phishing Scam Uses Spoofed Google Call to Attempt Gmail Breach of Security Expert

Loading...
Gmail Users Alert! AI Scammers Target Gmail Users With Realistic Spoofing Techniques
timesnownews.com · 2024

Cybercriminals are increasingly utilizing AI technology to execute sophisticated scams, particularly targeting Gmail users. With over 2.5 billion accounts, Gmail presents an attractive opportunity for scammers employing a tactic known as a “super realistic AI scam call,” which can deceive even tech-savvy individuals.

Sam Mitrovic, founder of CloudJoy and a security expert, recently shared his experience of falling victim to such a scam. He received an email that appeared to be an approval notification for his Gmail account recovery, followed by a phone call displaying “Google Sydney” on the caller ID.

A week later, he received another recovery notification and a similar phone call from a legitimate phone number listed on Google’s support page. The caller claimed that his account had been accessed from overseas for over a week, and personal data linked to the account had been downloaded. An email confirming this issue, originating from a Google domain, further added to the scam’s credibility.

Mitrovic initially suspected foul play and sought validation online, eventually confirming that he was indeed targeted in a spoofing attempt aimed at taking over his Gmail account. The scam employed a legitimate-sounding AI voice bot, a Google domain email spoofed through Salesforce CRM, and a phone number identical to Google Workspace support, making it easy to trick unsuspecting users into divulging their credentials.

Historically, such scams required human resources to make calls, but the advancement of AI voice models has simplified the process, allowing scammers to initiate thousands of calls simultaneously.

To protect against these threats, users should be aware that Google rarely contacts individuals by phone regarding personal accounts, usually preferring email. If you receive suspicious calls, it’s advisable to verify the number through platforms like Truecaller. Regularly reviewing Gmail activity and enabling two-factor authentication (2FA) methods can also bolster security. Ultimately, vigilance is essential in safeguarding digital identities, as hackers continuously refine their tactics to exploit unsuspecting users.

Read the Source

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • e1b50cd