← the record
AIAAIC-1771

Al account recovery scam calls target Gmail users

Cybercriminals are using AI-generated voice calls, spoofed phone numbers, and fake Google emails to trick Gmail users into surrendering control of their accounts, posing a large-scale fraud threat to billions of people worldwide and exposing deep vulnerabilities in how identity and trust are established in digital communications. What happened According to security researcher Sam Mitrovic, who experienced it first hand, the scam begins with an unexpected notification asking users to approve a recovery request they had not initiated. Following this, victims typically receive a phone call from someone posing as a Google support representative, using a convincing American accent and professional demeanour. The American voice explained there had been some suspicious activity on Mitrovic's Google account and someone had accessed it a week ago. The apparent Google employee offered to send an email detailing what happened, and that message promptly arrived from an official Google address. However, Mitrovic realised the voice was actually AI-manipulated or generated and hung up. Why it happened With nearly 2.5 billion users globally, Gmail is an appealing target for cybercriminals. Scammers use sophisticated techniques, including AI-generated voices and spoofed email addresses, to create a sense of legitimacy. The use of AI enhances the realism of the calls, making it harder for victims to detect the fraud. In addition, the scammers take advantage of common fears about account security, manipulating users into acting quickly without verifying the authenticity of the requests. What it means The rise of these types of scams indicates a trend in cybercrime where traditional phishing tactics are being augmented with advanced technology such as AI. This not only makes scams more convincing but also increases the risk for unsuspecting users who may not be equipped to identify these threats. As these tactics evolve, it becomes crucial for users to remain vigilant and adopt protective measures, such as verifying unexpected recovery requests and regularly checking their account security settings. System 🤖 Unknown Developer: Country: Australia; Global Sector: Technology Purpose: Defraud Technology: Deepfake Issue: Privacy/surveillance; Security

Date it happened
2024-10-01
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.