Google's official URL shortcut (update: or Google Workspace's domain verification, see bottom), is compromised. People are actively having their Google accounts stolen.
Google's official URL shortcut (update: or Google Workspace's domain verification, see bottom), is compromised. People are actively having their Google accounts stolen.

gist.github.com
almost_pwned.md

cross-posted from: https://lemmy.dbzer0.com/post/36237226
The call would have ended the second they they told me they're from Google.
Google does not call you.
I guess that depends. On GitHub it sounds like the victim is a paying customer of Google Workplace, not just some free account. I had similar genuine calls from hotels, credit card companies, an ISP, my electricity provider etc.
So yes, there are some signs that might make you suspicious, but I guess we agree that this was not just a regular everyday scam but a pretty professional, well-prepared and possibly targeted attack.
Anytime this happens, hang up and call a known company support number