New Phishing Campaign Imitates Google Account Page (from @SmarterMSP)
You can find the details on the SmarterMSP blog. Their recommendations are:
What are the recommendations?
Barracuda strongly recommends taking the following actions:
SmarterMSP
- Don’t trust pop‑ups or emails prompting you to “verify” or “secure” your account.
- Manually type myaccount.google.com or use the Google app—never click security links in messages or ads.
- Don’t accept “Install app” or “Add to Home screen” prompts unless you initiated the process on a trusted site.
- Check browser settings (Chrome/Edge > Apps/Installed apps) and remove any unknown PWAs.
- Install Google or security‑related apps only from the Google Play Store and official developer listings.
- Use an authenticator app (e.g., Google Authenticator, Authy) instead of SMS to reduce risk from WebOTP abuse.
These fit nicely with my standard caution: Don’t follow links in an email you receive. If it purports to come from your bank, go to your bank via the URL you use, or call the toll free number that is likely on your debit card.