NG Solution Team
Cybersecurity

Google app passwords abused to bypass 2FA in phone-support scam

The Swiss NCSC has identified a scam in which attackers used genuine Google system messages to prime victims for a phone-support call and then installed app passwords that allowed persistent access even after the account password was changed.

How attackers used genuine Google alerts

The attackers created a new Google account and entered the victim’s email address as the account’s recovery address. They then generated a device/app password in that account and inserted the text ‘Kevin W. Case ID: 834333 To view your case…’ into the text field. Google’s automated system sent an official security warning to the recovery address; because the subject line was automatically copied into the email, the message appeared as an urgent support case with a named case handler and a case number. A related security alert was also delivered by SMS in the same message thread as previous Google texts.

Phishing call, spoofed Swiss number and Google Sites

Shortly after the email arrived, victims received a phone call from somebody claiming to be from Google’s support team. The phone display showed what looked like a trustworthy Swiss landline number, but that caller ID had been spoofed. The caller pressured victims to act immediately and, in at least one case, continued despite the victim saying the account used a physical hardware key. The fraudsters redirected victims to a phishing page hosted on sites.google.com. Because the page used a legitimate Google domain in the browser address bar, the embedded malicious login form could appear credible while sending credentials directly to the attackers.

App passwords: a persistent back door

After capturing credentials, the attackers created an app password in the victim’s Google Account within minutes. App passwords are special access codes for older applications that can be used without additional two-factor authentication. An app password allowed the perpetrators to retain access to the account even after the user changed their main password. In the reported case, emails and contacts continued to synchronise to a device abroad for some time after the attack.

Telephone spoofing despite Swiss telecom rules

Since mid-2026, stricter telecom regulations in Switzerland have reduced the number of fake calls that display Swiss landline or mobile numbers. However, the NCSC’s case shows that a Swiss caller ID or local area code on the screen is not a guarantee of authenticity, as fraudsters continue to find new ways to spoof numbers.

Recommendations

Genuine platform operators never call users out of the blue about security incidents; if you receive such a call, hang up immediately. Never disclose passwords, SMS codes or verification codes over the phone, and do not enter them on any website while you are being pressured on a call. Official Google login pages are only at accounts.google.com and are never hosted at sites.google.com. If you suspect compromise, change your account password immediately, log out of all active sessions and disconnect any unauthorised devices in your account settings. In Google Account security, check the App passwords section and delete every entry there. Also verify any recovery email addresses and any automatic forwarding rules in your email account.

Related posts

Amgen data breach: were patient records stolen?

Jessica Williams

AI agents: 700-strong swarm breached Hugging Face, reports find

James Smith

Trezor email provider breached as fake wallet alert spreads

James Smith

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy