Posts: 15,877
Threads: 10,155
Thanks Received: 9,306 in 7,452 posts
Thanks Given: 10,225
Joined: 12 September 18
1 hour ago
Quote:Attackers are delivering phishing links via Google Tasks notifications.
We’ve written time and again about phishing schemes where attackers exploit various legitimate servers to deliver emails. If they manage to hijack someone’s SharePoint server, they’ll use that; if not, they’ll settle for sending notifications through a free service like GetShared. However, Google’s vast ecosystem of services holds a special place in the hearts of scammers, and this time Google Tasks is the star of the show. As per usual, the main goal of this trick is to bypass email filters by piggybacking the rock-solid reputation of the middleman being exploited.
What phishing via Google Tasks looks likeThe recipient gets a legitimate notification from an @google.com address with the message: “You have a new task”. Essentially, the attackers are trying to give the victim the impression that the company has started using Google’s task tracker, and as a result they need to immediately follow a link to fill out an employee verification form.
![[Image: google-tasks-phishing-notification.png]](https://media.kasperskydaily.com/wp-content/uploads/sites/92/2026/02/19033200/google-tasks-phishing-notification.png)
To deprive the recipient of any time to actually think about whether this is necessary, the task usually includes a tight deadline and is marked with high priority. Upon clicking the link within the task, the victim is presented with an URL leading to a form where they must enter their corporate credentials to “confirm their employee status”. These credentials, of course, are the ultimate goal of the phishing attack.
Continue Reading...