Skip to main content

Phishing emails still surprisingly effective, reports Google

phishing emails still surprisingly effective reports google email hacks
Image used with permission by copyright holder
Phishing emails — spam messages that purport to come from a legitimate source but which actually lead to a fake website — are still a surprisingly effective method of hacking into online accounts, according to the latest security report from Google. Some phishing emails can achieve a hit rate of 45 percent, says Google, while even the worst and most obvious scams can attract clicks from 3 percent of users.

Once users have clicked through on the misleading link, on average 14 percent of them actually go on to enter sensitive details such as account login credentials or bank card information, according to the study. The hackers then work quickly to access the newly compromised accounts, with 1 in 5 exploited within the space of half an hour. If you unwittingly give up the keys to your digital home then you might find yourself locked out very quickly.

“For this study, we analyzed several sources of phishing messages and websites, observing both how hijackers operate and what sensitive information they seek out once they gain control of an account,” explains Google’s Elie Bursztein in a blog post. “Even though [these types of hacks are] rare — 9 incidents per million users per day — they’re often severe, and studying this type of hijacker has helped us improve our defenses against all types of hijacking.”

So what can you do to protect yourself, other than being wary of every email that turns up in your inbox? Google recommends reporting suspicious-looking messages and visiting websites directly to login, rather than clicking through a link in your email program. If you’re using Gmail, make sure you’ve set up backup information (like a phone number) that you can use to restore your account if it gets compromised, and switch on two-step verification to make it harder for unwelcome visitors to gain access to your account. Google says it has managed to block 99 percent of hijackings in the last few years.

[Image courtesy of mtkang / Shutterstock.com]

Editors' Recommendations

Topics
David Nield
Dave is a freelance journalist from Manchester in the north-west of England. He's been writing about technology since the…
Google just made this vital Gmail security tool completely free
The top corner of Gmail on a laptop screen.

Hackers are constantly trying to break into large websites to steal user databases, and it’s not entirely unlikely that your own login details have been leaked at some point in the past. In cases like that, upgrading your password is vital, but how can you do that if you don’t even know your data has been hacked?

Well, Google thinks it has the answer because it has just announced that it will roll out dark web monitoring reports to every Gmail user in the U.S. This handy feature was previously limited to paid Google One subscribers, but the company revealed at its Google I/O event that it will now be available to everyone, free of charge.

Read more
Google missed big chance with ChatGPT-like tech, report claims
Google Logo

Google missed a golden opportunity to lead the way with its own ChatGPT-like chatbot technology tool two years ago, but an overly cautious attitude from those at the top prevented the company from releasing it, according to a Wall Street Journal report on Tuesday.

The two Google researchers who created the powerful conversational AI technology reportedly told colleagues at the time that their creation could revolutionize how people searched on the internet and worked with computers.

Read more
Half of Google Chrome extensions may be collecting your personal data
Google Chrome icon in mac dock.

Data risk management company Incogni has found that half of every installed Google Chrome extension has a high to very high risk of collecting personal data, showing a strong correlation to the number of permissions given.

After analyzing 1,237 Chrome extensions found in the Chrome Web Store, a study by Incogni has uncovered some troubling findings. Nearly half (48.7%) of the extensions were found to potentially expose users' personally identifiable information (PII), distribute malware and adware, and record passwords and financial information.

Read more