New Phishing Scheme

mpartenope4676
Contributor

I have yet to see this in our environment but wanted to share.

Phishers Exploit Google Sites and DKIM Replay to Send Signed Emails, Steal Credentials

https://thehackernews.com/2025/04/phishers-exploit-google-sites-and-dkim.html

1 REPLY 1

Kim_Nilsson
Admin Moderator

Just train your users.

The "fake" website address sites.google.com is clearly visible, and nobody should ever type in their credentials there.

The real address is accounts.google.com.

--
https://wheretofind.me/@NoSubstitute