logo

Google Docs Scam Highlights Phishing’s Low, Low Bar

ID: eecb18e9-9605-5355-be5e-a38318421d35

STIX ID: report--eecb18e9-9605-5355-be5e-a38318421d35

Feed Name: Security Ledger

Threat Score
55/100

Date Published: 2017-05-05

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

The article recounts a widespread Google Docs phishing campaign in which attackers sent spoofed document invitations that led to malicious web applications (on domains such as g-cloud.win and docscloud.info) that invoked Google OAuth to request broad permissions (read/send/manage email and contacts). Thousands of users clicked the links and granted permissions before Google intervened; the incident highlights weaknesses in OAuth app spoofing, the effectiveness of social-engineering phishing, and the need for better inbox filtering, permission controls, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.