Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What did the account did the email actually come from? Was it legit from legal and he just submitted the request or was it a real spoofing


It was not legit from legal, I had the same attack on me two weeks ago. They were pretending to be from Google General Counsel responding to an estate request to my Google account being handed to another party who was supposedly the inheritor.

What clued me in was that he said he couldnt share the estate documents with me until I gave him my popup 2FA code.


Were there any further login attempts that they tried to do to access your Google Account? It almost seems like the attack being described in the article is very sophisticated that the attackers aren't just contacting random people but might have certain people in their radar.


It was legit from Google email and servers.

You cannot spoof an email from @google that will inbox


They clearly did.


You can trigger emails from Google on behalf of other users or use a platform like Google Cloud or Google Sites to trigger emails that come from real Google servers.

This was not spoofed.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: