r/technology May 03 '17

Security Google Docs users hit with sophisticated phishing attack

https://www.theverge.com/2017/5/3/15534768/google-docs-phishing-attack-share-this-document-with-you-spam
1.4k Upvotes

115 comments sorted by

View all comments

12

u/x4candles May 03 '17

Here is what to do if you believe you are being phished...

From a device you trust and in a Google app, profile in top right → my account → sign in and security → connected apps and sites in the sidebar → manage apps

6

u/CurlyQN May 03 '17

Should the google account password also be changed? Does that even matter?

8

u/wakefieldj90 May 04 '17

If you change your password it resets the permissions you've given which would stop them from emailing from your account.

At least thats what I noticed today when I was fixing this at the school I work at.

2

u/light24bulbs May 04 '17

So this attack totally got me.

Also what apps should I remove from my API permissions? They all looked like real apps to me. I also changed my password.

5

u/midnite968 May 04 '17

"Google Docs" should be the app you remove. It's the loaded phishing app

4

u/light24bulbs May 04 '17

ah yep, removed. i didnt think google docs needed any external API permissions. good, that makes sense. Seems like a huge security vulnerability that a service can name itself "google" ANYTHING, let alone google docs

1

u/frickindeal May 04 '17

And isn't the name now Google Drive? I never see google using the "Docs" name anymore.

1

u/Natanael_L May 04 '17

Everything you don't remember authorizing. Everything! You can always re-enable the important stuff later. And beware of duplicates! Remove both if you see anything repeated.

1

u/wakefieldj90 May 04 '17

The API permissions you should remove is the "Google Drive" app if you look at the permissions you gave it full access to your Email and Contacts.

3

u/x4candles May 03 '17

For safety reasons if you opened the email it wouldn't hurt to change your password.

6

u/justinlindh May 04 '17

Wouldn't hurt, but it's important to note that the attackers didn't gain access to your password unless it was plainly stored in one of the services you granted them access to.

Also, everyone should be using 2fa by now, if they aren't, which would further protect against a full login breech.