Gmail’s spam filtering is very good, which is precisely why the attacks that reach the inbox are the ones designed to get past it. The techniques that have gained ground recently share a common trait: they do not look like phishing. They look like Google.
Here is what has changed and what actually helps.
Phishing that arrives from a genuine Google address
The most effective recent technique abuses Google’s own infrastructure. Attackers craft messages that are genuinely sent through Google services — via shared documents, calendar invitations, or notification systems — so the message passes SPF, DKIM, and DMARC checks and appears in Gmail with no warning banner at all.
A common variant is the shared Google Doc or spreadsheet notification. The email is real. The sharing is real. The document contains the phishing content, so no scanner flags the message itself.
Another abuses calendar invitations, which historically auto-populated a user’s calendar with events containing malicious links.
What helps: in Calendar settings, turn off automatic addition of invitations, so only invitations you accept appear. And treat an unexpected share notification the way you would treat an unexpected attachment — verify with the sender through another channel before opening.
AI-written phishing that reads correctly
The old advice — look for spelling errors and awkward grammar — is obsolete. Generative AI has removed the language tells entirely, and it has made personalization cheap. An attacker can now reference your actual industry, your actual vendors, and your actual job title at scale.
Since the writing no longer gives it away, the signals that remain are structural: Is this request unexpected? Does it create urgency? Does it ask me to move money, change payment details, or authenticate? Those three questions catch more than proofreading ever did.
Fake support and account recovery calls
A pattern that has become common: a user receives a genuine Google account recovery notification, then a phone call from someone claiming to be Google support, warning that the account is under attack and offering to help secure it. The caller is the one who triggered the notification. The “help” consists of getting the user to approve a recovery prompt or read out a code.
The rule is simple and worth stating to your whole team: Google does not call you about your account. Nobody legitimate will ever need a code from your phone.
Session hijacking that goes around MFA
Adversary-in-the-middle phishing kits proxy the real Google login page, capture credentials and the MFA response in real time, and steal the resulting session cookie. The victim logs in successfully and notices nothing. Meanwhile the attacker has an authenticated session that no longer requires the second factor.
Standard MFA does not stop this. Passkeys do, because they are cryptographically bound to the real domain and will not authenticate against a lookalike. If you make one change after reading this, make it that one.
Settings worth changing today
Add a passkey to your Google account and use it as the primary sign-in method. Under Security settings, review third-party apps with account access and revoke anything you do not actively use — OAuth grants persist through password changes and are a favorite persistence mechanism.
Check your filters and forwarding rules. A quiet forwarding rule sending copies of your mail elsewhere is one of the first things an attacker sets up, and one of the last things anyone notices. Look at recent security activity while you are there.
If your business handles particularly sensitive material, Google’s Advanced Protection Program locks the account to hardware keys and heavily restricts app access. It is inconvenient by design, and for an owner or finance lead that trade is often worth making.
For businesses running Google Workspace
Enforce two-step verification across the domain and set the enforcement date rather than leaving it optional. Restrict third-party app access to allowlisted applications. Enable enhanced pre-delivery scanning. Configure DMARC on your own domain at enforcement so nobody can convincingly impersonate you outbound.
And keep the reporting channel open: staff who know exactly who to tell, and who will not be criticized for a false alarm, are your fastest detection system.
If you would like your Workspace or Microsoft 365 tenant reviewed against current attack techniques, we are happy to take a look.