2 thoughts on “Crooks Bypassed Google’s Email Verification to Create Workspace Accounts, Access 3rd-Party Services

  1. zuo

    what Google says is simply not true. Attacks started around early June. I write here as one of the victims from that time. Even more – have a buganizer ticket numer from June the 7th with initial findings. It was fixed about month later.

    Reply
  2. Paul B

    I’ve had several bogus workplace trials started for my personal domains and had to dig to discover how to shut them down. The flaw is that no verification is required to sign up and start the trial. The trial will expire without control of the domain DNS entries but they should never allow it to even start if you can’t confirm via an in-domain email. This is kindergarten-level security but Google is more interested in making it easy to get hooked in. I have no idea what those first days of free trial allows them to do but it shouldn’t even be a question. I get a ‘thanks for signing up’ email that has no link to abort the fraudulent signup or to require a verification of any sort. Maybe that was pen testing that led to this breach or maybe it was amateurs hoping to cash in somehow. Google=evil.

    Krebs, please give them hell for this!

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *