Google Email Phishing Attack Leveraging DKIM Signatures

April 22, 2025, 4:20 am

A sophisticated phishing campaign has tricked email systems by reusing valid DKIM signatures on fake subpoena emails that managed to sneak past DMARC checks. Cybersecurity experts are left wondering if this clever hack is a wake‐up call or just another case of email security taking an unintended coffee break.


winbuzzer.com / Google Email Systems Spoofed by Phishing Campaign Reusing Valid DKIM Signatures

Attackers have successfully impersonated Google by exploiting DKIM replay, using valid signatures on fake subpoena emails delivered past DMARC checks. The post Google Email Systems Spoofed by Phishing Campaign Reusing Valid DKIM Signatures appeared first on WinBuzzer.

theregister.com / Google's email spoofed by cunning phisherfolk who re-used DKIM creds

PLUS: Malware developers adopt Node.js; US disinformation warriors disbanded; Gig worker accounts for sale; and more Infosec In Brief  Email security outfit EasyDMARC recently spotted a phishing campaign that successfully spoofed Google with a sophisticated attack.…


permalink / 2 stories from 2 sources in 4 hours ago #cybersecurity #infosec #google #email-security



Disclaimer: The information provided on this website is intended for general informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the content. Users are encouraged to verify all details independently. We accept no liability for errors, omissions, or any decisions made based on this information.