This Google Recovery Contact Email Is a Phishing Scam

Phishing email disguised as a Google recovery contact request notification

Please be on the lookout for this one, and do not fall for it. If you do, your Google account will be taken over and the attacker gains access to everything: photos, emails, documents, everything you have ever put in there.

This is one of the best-crafted phishing emails I have come across. It was sent to one of my client's personal Gmail accounts at 10:18pm.

Phishing email disguised as a Google recovery contact request, claiming a recovery contact has been added and the password can be reset in 24 hours
The email as it arrived. Sender and recipient addresses have been redacted.

Why this one works so well

Most phishing is easy to spot. This is not. Four things make it dangerous:

  • It creates fear. Your account is going to be taken over, and someone else now controls how you get back in.
  • It creates urgency. The 24 hour window is the whole trick. It tells you that you have to act, and act now.
  • It was sent at a vulnerable time. 10:18pm, right before bed, when people are tired and just want the problem to go away.
  • It looks completely legitimate. It comes from a Google email address and it points at a Google link.

That last point is worth sitting with. The message arrives from Google's real notification address, not a lookalike domain with a swapped letter. Attackers have methods to pull this off, which means the usual advice about checking the sender address does not save you here.

The link is the second trap

The next step is just as hard to catch. The link looks like a real Google sign-in URL, because the first part of it genuinely is. But if you follow where it actually ends up, it forwards to sites.google.com.

Google Sites is a legitimate product. Anyone can build a page on it, and that page sits on a real Google domain with a valid certificate. So an attacker builds a convincing fake sign-in page there, and every surface-level check a careful person would make still comes back clean.

If you click through and authenticate or approve the request, the attacker has your Google account. The takeover starts immediately.

What happens next

Once they are in, they work fast. They remove your recovery methods, reset your password, and lock you out of your own account. From there your email becomes the key to everything else you own online, because almost every other service you use will happily send a password reset to it. Banking, shopping, social, work. Then come the extortion attempts and the scams run in your name against the people in your contacts.

Losing a Gmail account is not losing an email account. It is losing the recovery route to your entire digital life.

What to do if this lands in your inbox

  • Do not click anything in the email. Not the link, not an unsubscribe, nothing.
  • Go to your account directly. Type myaccount.google.com into your browser yourself. Never navigate to a security setting from a link in a message.
  • Check your recovery settings while you are there. Look at your recovery email, recovery phone and any recovery contacts. If something is listed that you did not add, remove it.
  • Check recent security activity. Google will show you recent sign-ins and devices. Anything you do not recognize is worth acting on.
  • Delete and report the message. Use Gmail's own report phishing option rather than just deleting it.

If you already clicked

Move quickly, and do it from a device you trust.

  • Change your Google password immediately, from a different device if you can.
  • Sign out of all other sessions so anyone already logged in gets kicked out.
  • Remove any recovery email, phone number or recovery contact you do not recognize.
  • Check Gmail for forwarding rules and filters you did not create. Attackers add these to keep reading your mail quietly after you have locked them out.
  • Review third-party apps and any app passwords with access to your account, and revoke what should not be there.
  • Turn on 2-Step Verification if it is not already on. Passkeys or an authenticator app are stronger than SMS codes.

Then check the accounts that use that address for password resets, starting with anything financial.

The wider point

The old advice was to look for bad spelling, odd sender addresses and suspicious links. This email has none of those. It is well written, it comes from Google, and it links to Google.

So the rule has to change. Treat any unexpected message about your account security as untrustworthy regardless of how legitimate it looks, and go check the account yourself by typing the address in. That habit costs you thirty seconds and it is the one thing that would have defeated this email completely.

If you are not sure about something that has arrived in your inbox, forward it to us before you click. We would much rather look at ten harmless emails than clean up after one that was not.

Let Us Handle the Tech.

Schedule a free IT, Cybersecurity & AI strategy call.

Schedule a Free Call