Sep 10 / Latest News

Attackers Use Stolen Contact Data to Run Multi‑Channel Scams That Mimic Google Support

Cybercriminals are increasingly abandoning brute-force hacking in favor of coordinated social engineering attacks powered by stolen contact information. When breaches expose names, phone numbers, and email addresses, attackers can build multi-channel impersonation campaigns that trick victims into handing over access to their own accounts.

Recent supply-chain breaches, including the incident involving Trezor's shipping partner ShipMonk, exposed personal details of more than 80,000 customers. Because attackers know these individuals own hardware crypto wallets, the leaked data becomes a highly targeted roadmap for exploitation.

Armed with accurate personal data, attackers launch coordinated strikes that blend legitimate system activity with impersonation tactics. First, they trigger a real security event, such as a password reset or an attempt to add a forwarding or recovery email. This causes Google to send a genuine verification code or automated alert to the victim.

Moments later, the attacker calls the victim, spoofing caller ID to appear as Google Support or a security team. They reference the victim's name and the exact email that just arrived, creating immediate credibility. In some cases, attackers claim that another email address has already accessed the victim's account and that they verified this using the victim's photo ID, a tactic designed to escalate fear and urgency.

Attackers also send spoofed emails pretending to be from the Google Security Team. These messages often include a case number and links to real Google support pages. However, email header analysis reveals SPF failures and non-Google sending servers, proving the messages are forged. The spoofed email is used to anchor the phone call and make the impersonation feel legitimate.

The caller then manufactures a crisis, claiming the account is actively being compromised. They ask the victim to read back the six-digit verification code they just received. If the victim provides the code, they bypass Google's security on the attacker's behalf, granting full account access. Attackers may also attempt to add their own email as a forwarding address, allowing them to intercept future messages.

In some cases, attackers escalate further by requesting photo ID, claiming it is needed to "confirm removal" of the unauthorized access. This is a direct attempt at identity theft. Google does not make unsolicited calls, does not ask for verification codes over the phone, and does not request photo ID through live calls.

These attacks succeed because they combine legitimate system alerts with high-pressure phone calls, creating cognitive overload that prevents victims from verifying the caller's identity. The strongest defense is a hard boundary: never read verification codes aloud, never provide photo ID, and never click links in unexpected security emails. Any suspicious alert should be verified only by logging directly into the account through a trusted browser or official app.