Newsletter Subscribe
Enter your email address below and subscribe to our newsletter


This sophisticated new Gmail phishing scam shows that the more savvy criminals are reacting to defence techniques and evolving their strategies to outpace them. The scam specifically counters several previously reliable measures for spotting malicious emails in order to fool its targets.
How it works:
The use of a familiar attachment rather than a strange looking link will catch most users off guard, especially if the context of the rest of the email otherwise looks fine. Likewise, the link generated by clicking the PDF is disguised with a blank space, and even users who are aware enough to check the link will be unlikely to scroll all the way along to discover it is unusually long.
We believe browser service providers should take the initiative and begin displaying warning messages when it comes to unusual URLs like the one used here which deviate from the normal HTTP or HTTPS, as this will help to raise a red

How to spot it:
In terms of spotting the attack, the general steps can apply in terms of expecting emails and what is an email asking you to do. However, given that this is a technically very clever attack, educating non-technical users will be extremely difficult, especially as it is targeting the world’s most-used free email service.
We are certain to see more attacks using these kinds of sophisticated attacks, widening the net to target other services alongside Gmail. Businesses – especially those in high risk sectors such as finance and legal – should take this as a cue to review their current cyber awareness policies. Used in conjunction with a well-researched Business Email Compromise (BEC) attack, advanced attacks like this could cause limitless damage to any organisation if attackers covertly take over a business account.
Simon Cork