Skip to main content

Posts

Showing posts with the label BEC scam

BEC Scammers are exploiting Gmail's ‘Dot accounts’ for various fraudulent activities

Scammers are exploiting Gmail feature ‘Dot accounts’ to perform various fraudulent activities such as filing for fraudulent unemployment benefits, filing fake tax returns, and more. Gmail's ‘Dot accounts’ is a feature of Gmail addresses that ignores dot characters inside Gmail usernames, regardless of their placement. Researchers recently observed that Business Email Compromise (BEC) scammers are exploiting a Gmail feature ‘Dot accounts’ to perform various fraudulent activities. Gmail's ‘Dot accounts’ is a feature of Gmail addresses that ignores dot characters inside Gmail usernames, regardless of their placement. Scammers are leveraging this feature to create multiple accounts on a single website which then direct all communication to a single Gmail account. For example, Google considers red.apple[at]gmail[.]com, redap.ple[at]gmail[.]com, red.app.le[at]gmail[.]com, and redapple[at]gmail[.]com as same and emails sent to any of these email addresses will arrive at