Google warns 1.8 billion Gmail users about fake security alerts designed to hijack accounts

,
 April 22, 2026

Google has told its 1.8 billion Gmail users that a warning message appearing on their phones, one that looks like an official notice about suspicious account activity, may be a forgery built to hand control of their devices to criminals. The company confirmed in August 2025 that hackers have sharply escalated these attacks, copying legitimate "suspicious sign-in prevented" messages to scare people into surrendering their passwords and phone numbers.

The scheme works because it mimics what Gmail users already expect to see. A notification arrives, styled to look like it came from Google, claiming the account has been compromised. It urges immediate action. And for anyone who follows the link, the trap is already set.

The Daily Mail reported that Google acknowledged cybercriminals have been replicating its own security notifications, and that the volume of these fake "suspicious sign-in prevented" emails has risen sharply since last year. Google's motive assessment is blunt: the attackers want to gain more passwords and potentially access millions of accounts worldwide.

How the phishing scam caught one user off guard

In February, an unnamed Reddit user posted a firsthand account of falling for the scheme. The user said they received a message appearing to come from "Gmail from Google" claiming their email account was compromised and needed immediate recovery. Before that message arrived, the user had already received several emails reporting suspicious login attempts from IP addresses in Venezuela and Bangladesh, messages that primed them to believe the account was under genuine threat.

The Reddit user described the moment they clicked:

"I panicked. Normally, I would recognize this as phishing, but it had never happened on the phone before, and I clicked on the link, 'signing on,' which gave the scammer my Gmail password."

That single click opened a phony Google webpage that harvested the user's password and cell phone number. There is also a potential for the link to also download malware disguised as a "Google security check", software that could fully hijack the device.

The user only realized the scam after checking Google's official account activity records. There was never any suspicious sign-in detected. The earlier emails about login attempts from Venezuela and Bangladesh were part of the setup, a trail of fake breadcrumbs designed to make the final phishing message feel urgent and real.

A pattern of increasingly convincing attacks

This is not an isolated trick. The same basic technique has been adapted to other formats. The Washington Times reported on a separate phishing campaign in which scammers sent Gmail users a message disguised as an official Google "subpoena alert," urging them to click a link hosted on sites.google.com. That email appeared to come from a Google no-reply account and even passed a digital signature check, but it was actually sent from a privateemail.com address to a garbled recipient address.

What makes these attacks so effective is that criminals are exploiting Google's own infrastructure to lend credibility to their fakes. The New York Post reported that one phishing email passed DKIM authentication checks and linked to a fake portal hosted on sites.google.com rather than the legitimate accounts.google.com domain. Developer Nick Johnson, who flagged the attack, noted that the only visible hint it was a phish was the hosting domain.

That distinction, sites.google.com versus accounts.google.com, is the kind of detail most people will never notice, especially when they're already alarmed by a message telling them their account has been breached. The criminals are counting on panic overriding caution.

The broader trend of AI-powered scam emails growing more convincing makes this problem worse. Phishing messages that once arrived riddled with misspellings and odd formatting now read like polished corporate communications.

Google's response and recommended steps

Google has issued guidance through its Account Help center, recommending six immediate steps for anyone who receives a "suspicious sign-in prevented" alert on their phone. The core advice: do not click links in the message. Instead, go directly to your Google Account page, click Security, and review "Recent security events." Any genuine suspicious logins over the last month will appear in that panel.

If users see unfamiliar activity, Google says they can click the option to "secure your account" at the top of the page. The company will then guide them through changing their password.

A Google spokesperson stated the company's position plainly:

"Always be wary of messages that ask for personal information like usernames, passwords, or other identification information, or send you to unfamiliar websites asking for this information."

In a separate statement addressing the subpoena-style phishing campaign, a Google spokesperson said the company has "rolled out protections to shut down this avenue for abuse" and urged users to adopt two-factor authentication and passkeys.

Google was even more direct in the New York Post's reporting: "Google will not ask for any of your account credentials, including your password, one-time passwords, confirm push notifications, etc., and Google will not call you."

That last line deserves to be printed on a card and taped to every monitor in America. If Google contacts you asking for your password, it isn't Google.

What users should do right now

Cybersecurity experts urge users to enable two-factor authentication immediately. Passkeys, a newer login method that eliminates traditional passwords, offer even stronger protection against phishing because there is no password to steal. Experts who spoke with the Daily Mail also stressed that email users need strong, complex passwords and should never reuse the same password across multiple sites.

One commenter quoted in the coverage put it simply: "Why, in 2026, would you use the same password on multiple sites?" It is a fair question. But millions of people still do it, and the criminals know that.

The surge in Social Security imposter email scams targeting retirees follows the same playbook: official-looking messages, urgent language, a link that leads somewhere it shouldn't. The victims are almost always people who trust institutions and follow instructions, exactly the behavior these scams exploit.

And it is not just email. The IRS's updated "Dirty Dozen" list of tax scams shows the same fraud ecosystem at work across government agencies, financial services, and tech platforms. The common thread is always the same: a message that looks official, a demand for immediate action, and a link that leads to theft.

The real cost of digital complacency

Google deserves credit for issuing the warning and rolling out protections. But the fact remains that the world's largest email provider, a company with virtually unlimited engineering resources, built an ecosystem where criminals can host fake login pages on Google's own domain, send phishing emails that pass Google's own authentication checks, and fool experienced users into handing over their credentials.

The Reddit user who fell for the scam said something telling: "Normally, I would recognize this as phishing." This was not a careless person. This was someone who knew what phishing looked like, and got caught anyway, because the attack was good enough to bypass their instincts.

When the scams are this polished, telling people to "be wary" is necessary but not sufficient. Google controls the infrastructure these criminals are abusing. The company's responsibility does not end with a help-center page.

The lesson for every Gmail user is simple and old-fashioned: never click a link in a message that tells you your account is in danger. Go to the source yourself. Type the address. Check your own security panel. If nothing shows up, the message was the threat, not whatever it was warning you about.

In a world where the con artists have learned to dress in the uniforms of the institutions we trust, the only safe reflex is suspicion.

About Alex Tanzer

Become Wealthier... 
In Just 5 Minutes Per Day

Subscribe to Capital Digest and get fast, actionable insights on markets, money, and opportunity — straight to your inbox.