On MovieTome: CAPTAIN AMERICA gets a storyline!
BNET Business Network:
BNET
TechRepublic
ZDNet

By Jo Best
Posted on ZDNet News: Sep 15, 2004 4:41:00 PM

Scammers have caught on to the allure of Gmail and are using the Google e-mail service for a "phishing" scam to harvest e-mail addresses and passwords.

For the fashion-conscious techie, a Gmail account seems to be a must-have status symbol. The free service, which is not yet widely available, has even provoked people to try to sell their Gmail addresses on eBay.

Phishing schemes commonly involve e-mail requests for information that seem to be from trusted sources such as eBay or Citibank. In this case, the scammers send the phishing e-mail to existing holders of Gmail accounts, offering them the opportunity to invite three or six of their friends to join Gmail. The body of the e-mail reads "I found this e-mail very weird."

It continues to read: "The Gmail Team is proud to announce that we are offering Gmail free invitation packages to the existing Gmail account holders. By now you probably know the key ways in which Gmail differs from traditional webmail services. Searching instead of filing. A free gigabyte of storage. Messages displayed in context as conversations. Just fill in the form below to claim your free invitation package."

The "Gmail Team" asks users to give away their Gmail addresses and passwords to get the invites.

The e-mails are currently able to make their way through Gmail's spam filters, but the Gmail fraternity is fighting back by publicizing the con on messageboards and in forums.

For those account holders genuinely given Gmail invites to hand out by Google, a click is all it takes to get a friend onboard. A message saying "You have 6 Gmail invitations. Invite a friend to join Gmail!" appears in the user's status bar, for example.

Why the scammers are after the usernames and passwords is, as yet, unclear. One possibility is to use the accounts to send spam. Another is the potential to search though the e-mail messages for any financial details left lying around in e-mails. With up to a gigabyte of storage per account, that's a lot of e-mail to trawl though.

  • Talkback
  • Most Recent of 9 Talkback(s)
Possible uses
Knowing that people often use the same username across the web and that some of those individuals stick to the same one or two passwords, gaining a user's gmail name and password could mean the ticket... (Read the rest)
Posted by: Gardenwife Posted on: 08/26/08 You are currently: Logged In | Log out
This is all m$'$ fault NonZealot   | 09/15/04
I'll get you started: NonZealot   | 09/15/04
just so you feel better... ryusen   | 09/15/04
This is all m$'$ fault Loverock Davidson   | 09/15/04
No it's all Al Gore's fault Roger Ramjet   | 09/16/04
eh zomgguy   | 08/26/08
What the heck could be the possible use? Roger Ramjet   | 09/16/04
RE: Scammers use Gmail invite as phishing hook WATKINS12@...   | 08/25/08
Possible uses Gardenwife   | 08/26/08

What do you think?

advertisement
advertisement
advertisement
Click Here