FBI: Beware of a New Google Voice Authentication Scam – Even if You Don’t Use Google Voice!

Stu Sjouwerman | Jan 12, 2022

FBI Warns of Financial ExtortionA new advisory warns of a scam that can affect literally anyone designed as a precursor to additional vishing scams and/or to perform Gmail account takeovers.

If you’re unfamiliar with Google Voice, it is a service where Google provides you with a virtual phone number so you can make and receive calls and texts. Assuming you are unfamiliar with it, you may be wondering what’s all the excitement about?

According to a new FBI advisory entitled “Building a Digital Defense Against Google Voice Authentication Scams”, the FBI outlines a scam that involves a threat actor responding to a personal ad – they use the example of selling a couch on craigslist or some other site – and says they want to make sure you are legitimate so they don’t get scammed by sending you an authentication code from Google.

What’s really happening is they scammer is setting up Google voice using your phone number as the primary number and using you to assist them with Google’s authentication process during setup. Once completed, the threat actor has a new Google Voice account tied to your mobile phone, so they can carry on without worrying about having it tied to their phone. Additionally, the code being sent could be purposed to allow them access to reset the password to your Gmail account.

Organizations relying on Gmail for corporate email should be specifically concerned about the ramifications of such a scam; with access to one of your internal email accounts, threat actors can easily spray out phishing emails designed to provide endpoint access or install ransomware.

Users should be educated about this and other such scams using ongoing Security Awareness Training. Through repeated exposure to phishing and scam scenarios, users build up a sense of vigilance against these kind of attacks, spotting them instantly, and reducing the organization’s risk of successful attack.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.