Google probes after scammers exploit new Gmail 'blue-tick' feature

File picture

Gmail faces a significant setback as hackers have found a way to exploit one of its recently introduced security features.

The Gmail blue checkmark system, designed to assist users in identifying verified companies and organisations, is now being manipulated by scammers to deceive unsuspecting users.

Launched in May, the checkmark system displays a blue tick next to emails from verified sources, aiming to enhance user confidence and prevent falling victim to impersonation scams. However, cybersecurity engineer Chris Plummer has uncovered a vulnerability that allows scammers to deceive Gmail into recognising their fake brands as legitimate ones.

Plummer, who initially discovered the issue, brought it to the attention of Google, only to face dismissal of his findings. It was only after Plummer's tweets about the matter gained viral attention that Google acknowledged the problem and issued a statement.

In their response to Plummer, Google stated, "After taking a closer look, we realised that this indeed doesn't seem like a generic SPF vulnerability. Thus, we are reopening this, and the appropriate team is taking a closer look at what is going on. We apologise again for the confusion, and we understand our initial response might have been frustrating.

"Thank you so much for pressing on for us to take a closer look at this! We'll keep you posted with our assessment and the direction that this issue takes."

Recognising the gravity of the situation, Google has now classified the flaw as a 'P1' (top priority) fix, which is currently in progress. The tech giant is actively working to address the vulnerability and provide users with a secure email experience once again.

Until Google implements a fix, the Gmail checkmark system remains compromised, leaving users vulnerable to scams and fraudulent activities. 

In the meantime, users are advised to exercise scepticism and adopt additional measures to safeguard their personal information and online security.

More from Business

  • DEWA announces record AED 30.98 bln revenue

    Dubai Electricity and Water Authority (DEWA) recorded consolidated full year revenue, for 2024, of AED 30.98 billion, EBITDA of AED 15.70 billion and net profit after tax of AED 7.24 billion.

  • Aviation sector contributes $4.1 trillion to global economy

    The UAE's Minister of Economy and Chairman of the General Civil Aviation Authority (GCAA), on Monday emphasised the aviation sector's critical role in the global economy, noting that it accounts for 12 to 13 per cent of GDP in some countries and supports millions of jobs worldwide.

  • Paris AI summit draws world leaders

    World leaders and technology executives are convening in Paris on Monday to discuss how to safely embrace artificial intelligence at a time of mounting resistance to red tape that businesses say stifles innovation.

  • 16% growth in new economic licences in Abu Dhabi during 2024

    The Abu Dhabi Registration and Licensing Authority (ADRA), which develops and regulates the business sector, on Monday revealed significant growth in business licences and compliance indicators in the Emirate's mainland and non-financial economic free zones during 2024.

  • DEWA updates billing on water consumption

    Dubai Electricity and Water Authority (DEWA) has announced that it will adopt the cubic metre as the standard unit for measuring water consumption starting from the March 2025 billing cycle.