Gmail Threats to Watch and How to Stay Safe
Gmail is one of the most targeted email services in the world, simply because so many people use it. For a small business, a hacked Gmail or Google Workspace account is rarely just an email problem. The same login usually opens Google Drive, shared calendars, saved passwords and every other service that sends password resets to that inbox.
Here are the Gmail threats worth knowing about right now, and the steps that keep your accounts and your business safe.
The threats to watch
1. Phishing that reads like the real thing
Spelling mistakes and clumsy wording used to give scam emails away. Attackers now use AI tools to write clean, convincing messages that match the tone of a bank, a supplier or Google itself. Some are tailored using information from your website or LinkedIn. You can no longer rely on “it looks dodgy” as your main defence.
2. Fake Google security alerts
Some of the most effective scams pretend to be from Google. In April 2025, security researchers documented a phishing email that appeared to come from a genuine Google address and passed Google’s own email authentication checks. It claimed a subpoena had been issued for the recipient’s account and linked to a fake support page hosted on Google Sites, which made the web address look trustworthy.
The lesson: a message that looks like it is from Google, with a link to a google.com address, can still be a scam. If you get a security alert, go to your Google Account directly rather than clicking the link.
3. Tricks aimed at AI email summaries
Gemini can summarise emails in Gmail. In 2025, researchers showed that hidden text inside an email could manipulate that summary, for example by adding a fake security warning with a phone number to call. Treat any urgent warning in an AI summary with the same suspicion as the email itself, and never call a number that only appears in a summary.
4. Malicious app connections
Some attacks do not steal your password at all. Instead, they trick you into clicking “Allow” on a third-party app that asks for access to your Gmail or Drive. Once approved, the app can read your email or files until you remove its access, even if you change your password.
5. Account takeover through stolen sessions
Infostealer malware can copy browser cookies that keep you signed in to Google. With those, an attacker may be able to use your account without needing your password. This is one reason to keep business computers clean, patched and protected.
6. Scams that start in Gmail and move to the phone
Many scams use email only to start the conversation, then push you to call a “support line” or reply by text. Once you are on the phone, the scammer talks you into handing over codes, installing remote access software or making a payment.
How to protect your Gmail account
Use passkeys or 2-Step Verification
Google supports passkeys, which let you sign in with your fingerprint, face or device PIN instead of a password. Passkeys are much harder to phish, because there is no password to type into a fake page. If you are not ready for passkeys, at least turn on 2-Step Verification with an authenticator app or a security key rather than SMS codes. Our guide to multi-factor authentication for small businesses explains the options.
Run Google’s Security Checkup
Google’s Security Checkup in your Google Account shows recent sign-ins, connected devices, third-party apps with access and recovery details. Run it now, and again every few months.
Remove apps you do not recognise
In your Google Account, review third-party connections and remove anything you no longer use or do not recognise. Be very cautious about any app that asks to read, send or delete your email.
Consider the Advanced Protection Program
Google’s Advanced Protection Program is designed for people at higher risk of targeted attacks, such as business owners, finance staff and anyone who approves payments. It requires passkeys or security keys to sign in and adds stricter checks on downloads and app access.
Use a strong, unique password
If you still use a password, make it a long passphrase that you do not use anywhere else, stored in a password manager. See our complete guide to strong passwords and authentication.
Extra steps for Google Workspace businesses
If your business email runs on Google Workspace, the admin console gives you more control:
- Enforce 2-Step Verification for every user, not just encourage it.
- Restrict which third-party apps can access company data.
- Set up SPF, DKIM and DMARC for your domain to make your own email harder to spoof.
- Review admin alerts for suspicious sign-ins and forwarding rules.
- Back up Gmail and Drive separately from Google’s own recycle bins.
What to do if you clicked something
- Change your Google password from a device you trust and sign out of all other sessions.
- Check for new email forwarding rules, filters and recovery details, and remove anything you did not set up.
- Remove unfamiliar third-party apps.
- If money or banking details were involved, call your bank immediately.
- Report scams to Scamwatch, and report cyber incidents to the ACSC through ReportCyber at cyber.gov.au.
- Tell your IT provider so they can check whether other accounts were affected.
Key takeaways
- Scam emails now look professional, and some even pass Google’s own checks.
- Go to your Google Account directly instead of clicking links in security alerts.
- Passkeys or app-based 2-Step Verification stop most account takeovers.
- Review connected apps regularly, because app access can survive a password change.
Whether your business runs on Google Workspace or Microsoft 365, our managed IT security service helps lock down email accounts and keep an eye on suspicious activity.
Is your business email as secure as you think?
Our free IT Health Check reviews your email accounts, sign-in security and connected apps, and shows you exactly what to tighten up.
Or call 1300 133 770.




