The Swiss NCSC has identified a scam in which attackers used genuine Google system messages to prime victims for a phone-support call and then installed app passwords that allowed persistent access even after the account password was changed.
How attackers used genuine Google alerts
The attackers created a new Google account and entered the victim’s email address as the account’s recovery address. They then generated a device/app password in that account and inserted the text ‘Kevin W. Case ID: 834333 To view your case⦒ into the text field. Google’s automated system sent an official security warning to the recovery address; because the subject line was automatically copied into the email, the message appeared as an urgent support case with a named case handler and a case number. A related security alert was also delivered by SMS in the same message thread as previous Google texts.
Phishing call, spoofed Swiss number and Google Sites
Shortly after the email arrived, victims received a phone call from somebody claiming to be from Google’s support team. The phone display showed what looked like a trustworthy Swiss landline number, but that caller ID had been spoofed. The caller pressured victims to act immediately and, in at least one case, continued despite the victim saying the account used a physical hardware key. The fraudsters redirected victims to a phishing page hosted on sites.google.com. Because the page used a legitimate Google domain in the browser address bar, the embedded malicious login form could appear credible while sending credentials directly to the attackers.
App passwords: a persistent back door
After capturing credentials, the attackers created an app password in the victim’s Google Account within minutes. App passwords are special access codes for older applications that can be used without additional two-factor authentication. An app password allowed the perpetrators to retain access to the account even after the user changed their main password. In the reported case, emails and contacts continued to synchronise to a device abroad for some time after the attack.
Telephone spoofing despite Swiss telecom rules
Since mid-2026, stricter telecom regulations in Switzerland have reduced the number of fake calls that display Swiss landline or mobile numbers. However, the NCSC’s case shows that a Swiss caller ID or local area code on the screen is not a guarantee of authenticity, as fraudsters continue to find new ways to spoof numbers.
Recommendations
Genuine platform operators never call users out of the blue about security incidents; if you receive such a call, hang up immediately. Never disclose passwords, SMS codes or verification codes over the phone, and do not enter them on any website while you are being pressured on a call. Official Google login pages are only at accounts.google.com and are never hosted at sites.google.com. If you suspect compromise, change your account password immediately, log out of all active sessions and disconnect any unauthorised devices in your account settings. In Google Account security, check the App passwords section and delete every entry there. Also verify any recovery email addresses and any automatic forwarding rules in your email account.

