• News/
  • https://www.bleepingcomputer.com/news/security/phishers-abuse-google-oauth-to-spoof-google-in-dkim-replay-attack/

Phishers abuse Google OAuth to spoof Google in DKIM replay attack

BleepingComputer
·
Ionut Ilascu
·
Published Apr 20, 2025
·
Updated

In a rather clever attack, hackers leveraged a weakness that allowed them to send a fake email that seemed delivered from Google’s systems, passing all verifications but pointing to a fraudulent page that collected logins. The attacker leveraged Google’s infrastructure to trick recipients into accessing a legitimate-looking “support portal” that asks for Google account credentials. The fraudulent message appeared to come from “no-reply@google.com” and passed the DomainKeys Identified Mail (DKIM) authentication method but the real sender was different. Nick Johnson, the lead developer of the Ethereum Name Service (ENS), received a security alert that seemed to be from Google, informing him of a subpoena from a law enforcement authority asking for his Google Account content. Almost everything looked legitimate and Google even placed it with other legitimate security alerts, which would likely trick less technical users that don’t know where to look for the signs of fraud. However, Johnson’s keen eye spotted that the fake support portal in the email was hosted on sites.google.com - Google’s free web-building platform, which raised suspicion. Being on a Google domain, the chances of the recipient to realize they are being targeted are lower. Johnson says the fake support portal was “an exact duplicate of the real thing” and “the only hint it's a phish is that it's hosted on sites.google.com instead of accounts.google.com.” The developer believes that the purpose of the fraudulen...

Read full article

Affected Software

4 affected components
Google Google
Google Google OAuth
Paypal PayPal
Google Gmail

Frequently Asked Questions

1

What is the main method used in the phishing attack described in the article?

Hackers exploited Google OAuth to spoof legitimate emails from Google's systems.

2

What kind of attack is being discussed in the article?

The article discusses a DKIM replay attack utilized by phishers to trick users into revealing their login credentials.

3

What is the outcome of the phishing attack?

Victims are redirected to a fraudulent page that collects their login information.

4

Which major software platforms are affected by this security issue?

The attack affects Google services, including Google OAuth, Gmail, and PayPal.

5

What verification process was bypassed in the phishing scheme?

The phishing emails were able to pass all verifications, making them appear legitimate.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203