A scammer called a Gmail user pretending to be Google’s security team and used real Google account-recovery emails to make the story believable. The attacker first triggered legitimate Google verification and security-alert messages, then tried to pressure the victim during the phone call into handing over access (likely a code or other sign-in information).
How the attack worked
This attack combined a real system feature with a convincing phone call. The attacker first attempted to add the victim's email address as the recovery address for a throwaway Gmail account they controlled. This action triggered a genuine Google verification email to the victim, since Google's system requires confirmation before linking a recovery address. With that legitimate email now sitting in the victim's inbox, the attacker placed a phone call impersonating Google's security team and referenced the email directly, using it as proof of authenticity.
A second legitimate-looking "Security alert" email was actually a copy sent to the scammer's own throwaway address, but formatted to appear as if the victim's account had been compromised. The combination of a real inbound email and a confident caller created a strong illusion of legitimacy.
Why it succeeded
The scam worked because it exploited reversed logic that most people would not immediately catch. The core message, that someone else wants to use your email as their recovery address, is easy to misread as your own account being at risk. Because the triggering email was genuinely sent by Google's systems, technical indicators like sender authenticity looked clean. The caller's polished delivery and urgency added social pressure, discouraging the victim from pausing to verify independently.
What to watch for
- Unsolicited phone calls claiming to be from Google or another provider's security team
- Callers who reference a real email you just received to build trust
- Emails describing an unfamiliar account wanting to use your address as a recovery email
- Requests to read back a verification code, authenticator code, or other sign-in credential over the phone
- Expiring codes or time pressure designed to prevent careful review
How to build resistance
Organizations can reduce risk from this kind of attack by reinforcing a few habits across staff, executives, IT/helpdesk, and customer support teams:
- Treat unsolicited security calls as unverified until confirmed independently through official account settings, not through the caller
- Never share verification or authenticator codes over the phone or in chat, regardless of how legitimate the surrounding email looks
- Read security emails slowly, paying attention to whether the alert actually concerns your own account or references another address
- Use built-in account options, such as removing an email from an unfamiliar account request, rather than acting on caller instructions
Because this technique relies on abusing a real notification system rather than a fake login page, standard phishing-link training is not enough. Awareness needs to specifically address vishing calls that arrive alongside legitimate-looking emails.
Key findings
- Attacker triggered legitimate Google emails by attempting to add the victim’s address as a recovery email on a throwaway Gmail account.
- Scammer called the victim, impersonated Google security, and referenced the real email that had just arrived to build trust.
- Second legitimate Google “Security alert” email was actually a copy sent to the scammer’s throwaway address, designed to look like the victim’s account was compromised.
- The scam relies on urgency and confusion around reversed logic (“someone wants to use your email as their recovery email”).
- When the victim hung up, the attacker withdrew the recovery request to erase the trail.
Who’s being targeted
- Commonly targeted roles: All staff, Executives, Finance, IT/helpdesk, Customer support.
- Affected industries: Information technology, Professional services, Any organization using Google Workspace/Gmail.
- Attack channels: email, vishing.
- Impersonated: Google Security team, Google automated security notification (legitimate sender abused).
Red flags to watch for
- Unsolicited phone call claiming to be Google and creating urgency
- Caller tries to keep you focused on their instructions rather than reading the email carefully
- Request to share a verification/authenticator code over the phone
- Message is about someone else’s account (reversed logic)
- Throwaway Gmail address with random letters and digits
- Expiring code creates pressure to act fast
Frequently asked questions
How did the scammer get a real Google email to send?
The attacker attempted to add the victim's address as a recovery email on a throwaway Gmail account, which triggered Google's legitimate verification email to the victim.
What did the caller ask the victim to do?
The caller impersonated Google security, referenced the real email that had just arrived, and pushed the victim to read back a verification code or follow instructions instead of checking the account independently.
How can someone tell this kind of email is fake trouble?
The alert describes someone else's account wanting to use your email as their recovery address, a reversed logic that signals the message is not about a compromise of your own account.
What should you do if you get a call claiming to be from Google?
Hang up and verify account status directly in your own account settings rather than following instructions from the caller, and never share verification or authenticator codes over the phone.
Read the video transcript
Your phone rings: “This is Google Security. Someone just tried to change your Gmail recovery email.” And yep, there’s a real Google alert in your inbox. Here’s the trick: the scammer triggered that legit email by adding your address as the recovery email on their throwaway Gmail. Then they call, sound polished, and say, “Read me the Google verification code on that message.” Red flags: the call is unsolicited, the email is really about someone else’s random Gmail using your address, and they’re pushing you to act fast instead of reading: it literally says they want to use your email as their recovery email. If this happens, hang up. Then, on your own, open your Google account settings, read the alert slowly, and if you don’t recognize the account, hit “Remove email.” Never say a verification code out loud.