Why a Phishing Email From “Google” Can Be 100% Real and Still Be a Scam
Every day I help more than five people who’ve been scammed, some of them out of hundreds of thousands of dollars. Every one of them had a virus scanner running. Every one of them knew scammers existed and thought they’d never fall for one. They still did. I hate scammers. They wreck lives and wipe out savings people spent decades building, and the people I see caught up in it most are usually older, trusting, and pushed to act before they’ve had time to think it through. That’s the whole trick: create urgency, and people do things they’d never do with a clear head.
Last week it happened to me. A call from an American number with an American on the other end of the phone that was more precise than anything I’d seen come through to me before, that made me even question whether or not this was legit.
Most of the scam calls my customers describe come from call centres in India. Scammers have noticed that’s become a red flag for a lot of people, so plenty have shifted to operators from European and American call centers instead, betting that people trust a US accent more than another foreign accent. There’s no truth to that bet. Good and bad people exist everywhere.
The caller told me my Google account had been breached and someone had started claiming ownership of my account by changing recovery information. He had my full name, my address, my date of birth. Every question I threw at him, he had an answer ready, calm and fluent, like he’d done this hundreds of times. He pushed urgency hard: I needed to act immediately or risk losing access to everything in the account. I stayed on the line and logged in while we talked, because I knew where to check for unauthorised devices or altered security settings. My Google account holds my photos, my saved card details, my messages. If someone got into it, the damage would be serious. Someone less familiar with their own account settings might have just given in and trusted this call who spoke with just authority coming from a California number.
He was good. Convincing enough that I started recording the phone call and told him outright that I help scam victims for a living. He didn’t flinch. He said he’d send me an email from Google to prove who he was. I knew it was coming and I knew it would be a phishing attempt, but I wanted to see how far he’d take it, so I stayed on. The email landed looking exactly like something Google would send, from an actual google.com address. That’s usually the first thing I tell customers to check, and on its own it would have passed.


What gave it away was the link. It pointed to sites.google.com, Google’s free website builder. They had created a page name based on a non-existent case number to make it look more legit. Anyone can put up a page there without owning a domain, and Google has no reason to use it for official support communication. The page itself was hosted on a real Google domain with a valid SSL certificate, which is what made it dangerous. Nothing about the address looked fake. There was no “G00gle.com” misspelling for anyone to catch. Most people would go to the FROM address straight away and verify that if it had came from a google account it would be legit. This is scams 101 which everybody knows by now, but now they are finding waits how to alter messages sent from these official addresses.

The sender address being real wasn’t an accident. Scammers fill out a contact form on an actual Google support page using the victim’s email address and whatever text they want, and Google’s own system automatically sends a confirmation back. That confirmation carries valid DKIM and SPF signatures because Google’s infrastructure generated it, so it skips spam filters and lands straight in the main inbox. The phishing isn’t in the email itself. It’s entirely in where the embedded link leads.
I knew what I was looking at and still wanted to see how far the scam went from start to finish. Most of my customers don’t have that advantage. They get a call from someone who already knows their date of birth, see an email that looks completely legitimate, and have thirty seconds to decide whether to trust it. That’s the gap scammers are exploiting, and it’s why I keep writing about this. If you think you or someone you know has been targeted, get in touch. The earlier you catch it, the more there is to save. Scammers are really starting to target Google accounts, Google, Microsoft, and Facebook accounts get targeted hardest for one reason: they’re the master key. Most websites now let you sign in with one of those three instead of creating a new password, so scammers don’t need to break into every account you own. They just need that one. Get into your Google account and they’re potentially in your email, your photos, your saved cards, and every other site where you clicked “Sign in with Google” instead of setting up a separate login. One password, dozens of doors.
The most dangerous element of this email is the link you are visiting a public web page that the scammer built using Google’s free website creator. Because they can customise that page to look like whatever they want, they build an exact replica of the standard Google Sign-In box.
If you’ve Clicked and logged into one of these pages it’s really important that you get a Computer security professional to check everything out for you ASAP as time is of the essence. We are seeing an uptrend of people getting family and friends to fix the problem where in some cases it’s OK – but when it comes to security you want to make sure it’s a trusted professional and not just someone who treats it as a hobby.
Remember the biggest Flag is when someone creates a sense of urgency. People think different if they think they need to act now. I’ve started emailing my customer base myself because this goes against the typical scam’s that most people are aware of and it just goes to show how clever and innovative that scammers are becoming in order to try to gain even more trust so you hand over your valuable details.
