Fake “Google Security” Calls Abuse Real Gmail Alerts

Proton Blog · Medium sophistication
Last updated September 8, 2026

A scammer called a Gmail user pretending to be Google’s security team and used real Google account-recovery emails to make the story believable. The attacker first triggered legitimate Google verification and security-alert messages, then tried to pressure the victim during the phone call into handing over access (likely a code or other sign-in information).

How the attack worked

This attack combined a real system feature with a convincing phone call. The attacker first attempted to add the victim's email address as the recovery address for a throwaway Gmail account they controlled. This action triggered a genuine Google verification email to the victim, since Google's system requires confirmation before linking a recovery address. With that legitimate email now sitting in the victim's inbox, the attacker placed a phone call impersonating Google's security team and referenced the email directly, using it as proof of authenticity.

A second legitimate-looking "Security alert" email was actually a copy sent to the scammer's own throwaway address, but formatted to appear as if the victim's account had been compromised. The combination of a real inbound email and a confident caller created a strong illusion of legitimacy.

Why it succeeded

The scam worked because it exploited reversed logic that most people would not immediately catch. The core message, that someone else wants to use your email as their recovery address, is easy to misread as your own account being at risk. Because the triggering email was genuinely sent by Google's systems, technical indicators like sender authenticity looked clean. The caller's polished delivery and urgency added social pressure, discouraging the victim from pausing to verify independently.

What to watch for

  • Unsolicited phone calls claiming to be from Google or another provider's security team
  • Callers who reference a real email you just received to build trust
  • Emails describing an unfamiliar account wanting to use your address as a recovery email
  • Requests to read back a verification code, authenticator code, or other sign-in credential over the phone
  • Expiring codes or time pressure designed to prevent careful review

How to build resistance

Organizations can reduce risk from this kind of attack by reinforcing a few habits across staff, executives, IT/helpdesk, and customer support teams:

  • Treat unsolicited security calls as unverified until confirmed independently through official account settings, not through the caller
  • Never share verification or authenticator codes over the phone or in chat, regardless of how legitimate the surrounding email looks
  • Read security emails slowly, paying attention to whether the alert actually concerns your own account or references another address
  • Use built-in account options, such as removing an email from an unfamiliar account request, rather than acting on caller instructions

Because this technique relies on abusing a real notification system rather than a fake login page, standard phishing-link training is not enough. Awareness needs to specifically address vishing calls that arrive alongside legitimate-looking emails.

Key findings

  • Attacker triggered legitimate Google emails by attempting to add the victim’s address as a recovery email on a throwaway Gmail account.
  • Scammer called the victim, impersonated Google security, and referenced the real email that had just arrived to build trust.
  • Second legitimate Google “Security alert” email was actually a copy sent to the scammer’s throwaway address, designed to look like the victim’s account was compromised.
  • The scam relies on urgency and confusion around reversed logic (“someone wants to use your email as their recovery email”).
  • When the victim hung up, the attacker withdrew the recovery request to erase the trail.

Who’s being targeted

  • Commonly targeted roles: All staff, Executives, Finance, IT/helpdesk, Customer support.
  • Affected industries: Information technology, Professional services, Any organization using Google Workspace/Gmail.
  • Attack channels: email, vishing.
  • Impersonated: Google Security team, Google automated security notification (legitimate sender abused).

Red flags to watch for

  • Unsolicited phone call claiming to be Google and creating urgency
  • Caller tries to keep you focused on their instructions rather than reading the email carefully
  • Request to share a verification/authenticator code over the phone
  • Message is about someone else’s account (reversed logic)
  • Throwaway Gmail address with random letters and digits
  • Expiring code creates pressure to act fast
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the scammer get a real Google email to send?

The attacker attempted to add the victim's address as a recovery email on a throwaway Gmail account, which triggered Google's legitimate verification email to the victim.

What did the caller ask the victim to do?

The caller impersonated Google security, referenced the real email that had just arrived, and pushed the victim to read back a verification code or follow instructions instead of checking the account independently.

How can someone tell this kind of email is fake trouble?

The alert describes someone else's account wanting to use your email as their recovery address, a reversed logic that signals the message is not about a compromise of your own account.

What should you do if you get a call claiming to be from Google?

Hang up and verify account status directly in your own account settings rather than following instructions from the caller, and never share verification or authenticator codes over the phone.

Read the video transcript

Your phone rings: “This is Google Security. Someone just tried to change your Gmail recovery email.” And yep, there’s a real Google alert in your inbox. Here’s the trick: the scammer triggered that legit email by adding your address as the recovery email on their throwaway Gmail. Then they call, sound polished, and say, “Read me the Google verification code on that message.” Red flags: the call is unsolicited, the email is really about someone else’s random Gmail using your address, and they’re pushing you to act fast instead of reading: it literally says they want to use your email as their recovery email. If this happens, hang up. Then, on your own, open your Google account settings, read the alert slowly, and if you don’t recognize the account, hit “Remove email.” Never say a verification code out loud.

Similar attacks

Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Fake IT Help Desk Calls Steal M365 Data, Extort

Fake IT Help Desk Calls Steal M365 Data, Extort

Threat actors are calling employees while pretending to be internal IT/help desk staff and directing them to fake Microsoft 365 login pages. The goal is to capture credentials and MFA approvals, steal session tokens, then access and exfiltrate data from SaaS services like SharePoint, OneDrive, and…

September 7, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
CEO Fraud and Fake Invoices Fuel BEC Losses

CEO Fraud and Fake Invoices Fuel BEC Losses

This article explains how business email compromise (BEC) scams work when attackers impersonate executives or suppliers to request urgent wire transfers, bank-detail changes, or credentials, often without malware or links. It cites real, high-loss cases (including Google/Facebook and aerospace…

August 21, 2026