You get an email from Google to your Gmail account, saying that you have successfully approved a request to add a recovery contact for your Google account. Typically, the subject line might be something like “You have a recovery contact request” or “Your Google Account was recovered successfully”. The email listed is one you don’t recognize. The instructions include a link to check your recovery info and secure your account, so in a panic, you do. It came from Google, after all, and the URL is Google’s, so everything should be safe, right?

The page requests your username and password, which you expect. And since you have 2-factor authentication (which everybody should), it will ask you to type in that code (or it will ask you to enter a code into a form). It’ll then boot you into the Google Account page. You see that you’re safe, breathe a sigh of relief, and go on with your life.

It’s not until later that you find you’re getting warnings - a new passkey was added to your account, or your recovery codes were downloaded, or a new device you don’t recognize was added to your account. In addition, you may find that someone has accessed your financial accounts, changing your password and locking you out, or even sending scams using your account.

You can still kick the hacker out - they’re usually pretty careful to keep you in ignorance and thus don’t change your password or anything obvious - but the damage is done.

How to protect yourself
Google never asks you to click a link to check the security of your account! Never, ever, EVER follow a link from an email when it comes to account security - for Google, this is myaccount[.]google[.]com.

If the URL includes a link to sites[.]google[.]com somewhere in there, it is definitely malicious. Google does not use Google Sites for security issues!

If you’re still unsure, see if there’s a lot of whitespace between the urgent request and the bottom of the form, and if there’s text at the bottom. If there is text after the whitespace, this is certainly a scam intending to get into your Google/Gmail account.

What the scammer has done is inject their own text into an otherwise benign Google request, which hides that benign request (though don’t click that link, either), hoping that the fact the email did come from Google to fool you into clicking. This is called an “injection attack” and it’s used beyond this specific instance - so always be cautious about clicking links, and especially about entering passwords (and codes)!

(If you have fallen prey to this attack, Google itself has excellent guides on how to fix the problem; I won’t replicate them here.