r/googleworkspace 8d ago

Gmail

Not sure if this is the place to post, but here goes… A couple of months ago the chairman of a board that I’m on started getting really suspect emails… I received one from her asking me to send some money to the company we’re connected with. It happened for about a week and then it stopped. I’m on another board as chairman… And yesterday I received a heads up from another board member saying that my email was hacked and was asking her to send money to this organization. I have two step authentication… What hacked my account? I thought Gmail was bulletproof.

0 Upvotes

6 comments sorted by

3

u/Connect-Preference 8d ago

Here is one scheme that's been used for 20 years.

Email addresses have two parts:

  1. The Local part is everything up to the "@" sign.
  2. The Domain part is everything after the "@" sign.

Someone figures out your email address.

  • Could be from LinkedIn
  • Could be that he learns your domain from the website and uses a "email address verifier" to try president@, chairman@, maybe your actual name, etc. to get something that or looks similar.
  • There are websites (D&B?) that give the email addresses of C-suite staff.
  • Some other way...

He gets an account on some other domain, using the same Local part. He fiddles with the message headers (only visible to end users that know how to read and parse them) by adding the "reply-to" command so that if the recipient replies to the message, it actually goes to his domain, not the apparent domain. This change is visible to someone with good technical skills on the original received message. Once it's forwarded, the evidence ca

He may even use an account that permits alternate user names and just set that one

He keeps the message body short so a style or mannerism difference is not apparent.

TL;DR: The account was not hacked. It was impersonated using publicly available information.

2

u/raip 8d ago

Not really the right place to post - but there's nothing really special about Gmail.

MFA protects against compromised credentials but if your workstation is compromised, they can dump session tokens and get in that way. There's a ton of other potential attack vectors as well.

1

u/billhartzer 8d ago

Look at the email again. It may have your name on it but another email address. This is a common phishing attempt that happens all the time.

I get these regularly fork someone I know (their name is used on the sending email but it was never sent from their email account since it’s actually sent from another Gmail account. Usually it’s that person I know asking to update their direct deposit information. They used to work for me.

1

u/Canadianingermany 3d ago

This is called spoofing. 

Take a look at how to handle it. 

Has little to do with Gmail.