Stay Alert! Latest phishing campaign targeting Google Looker Studio users

A series of phishing attacks, discovered by Check Point, are using Google Looker Studio to trick people into giving away their login information and money.

New Phishing Campaign targeting Google Looker Studio
New Phishing Campaign targeting Google Looker Studio

Highlights

  • Check Point, a cybersecurity firm, cautions about a novel phishing tactic that exploits Google Looker Studio to bypass security measures
  • Attackers are using Google Looker Studio, a legitimate platform, to create fake crypto pages
  • The phishing campaign, which manipulates Google's authority, demonstrates standard email security checks

Check Point, a cybersecurity firm, has uncovered a concerning trend in phishing attacks that exploit Google Looker Studio, a legitimate online tool. These attacks target users with deceptive emails, claiming to offer lucrative cryptocurrency investment advice.

Tricking through trustworthy tools

Attackers are taking advantage of Google Looker Studio's credibility to create fake crypto pages. They craft emails using the tool itself and send them to unsuspecting victims.

Making a tempting bait

Recipients receive an email containing a link to a counterfeit report promising investment strategies for substantial returns.

When victims click the link, they're directed to a genuine Google Looker page, where a Google slideshow appears to provide cryptocurrency instructions.

To proceed, victims are taken to a login page, warning of potential account loss. Unfortunately, this page is designed to steal login credentials.

Malicious email (Source: Check Point)

Sneaky tactics to fool checks

Check Point's analysis reveals that this attack can pass various email security checks, exploiting Google's trusted domain to appear legitimate.

Although security measures may fail, recipients' attention to detail can stop such assaults. When receiving unusual links or requests, always proceed with caution.

Ongoing threat

This campaign has persisted for several weeks. Google was alerted to these attacks on 22 August, underlining the need for continued awareness and caution in online interactions.

About Google Looker Studio

Google Looker Studio is a legitimate online platform that enables users to create custom reports, charts, and graphs for data analysis. It simplifies data visualisation and report sharing, making it a valuable tool for businesses and individuals to extract insights from complex data sets.

The emergence of a phishing campaign exploiting Google Looker Studio underscores the need for users to remain vigilant and informed about evolving cybersecurity threats. By exercising caution and adopting secure online practices, individuals can contribute to their protection against such deceptive attacks. Stay safe online!