Did You Get A Weird Invitation To Edit A Google Doc? It's Best Not To Click | WBEZ
Skip to main content


Did You Get A Weird Invitation To Edit A Google Doc? It's Best Not To Click

There's a decent chance you — or someone you know — just got an odd email inviting you to edit a document in Google Docs. The email could be from a stranger, a colleague or a friend, but it's addressed to a contact that boasts a whole string of H's in its name. In other words, it looks a little something like this:

This is what the subject line may look like in the email, for people using Microsoft Outlook. The telltale sign something's amiss: that email address with that long line of H's.

Screenshot by NPR

Or, if you're looking at the invite in Gmail, it likely looks more like this:

@zeynep Just got this as well. Super sophisticated. pic.twitter.com/l6c1ljSFIX

— Zach Latta (@zachlatta) May 3, 2017

Either of these look familiar to you? Here's a handy tip: Don't open the link.

Those invitations aren't what they seem. They are in fact malicious files intended to hijack recipients' accounts — and Google advises its users not to open them.

"We have taken action to protect users against an email impersonating Google Docs, and have disabled offending accounts," a Google spokesperson says in a statement emailed to NPR.

"We've removed the fake pages, pushed updates through Safe Browsing," the statement continues, "and our abuse team is working to prevent this kind of spoofing from happening again. We encourage users to report phishing emails in Gmail."

We are investigating a phishing email that appears as Google Docs. We encourage you to not click through, & report as phishing within Gmail.



If this public service announcement has reached you too late and you're now staring in despair at an already opened link, Vice's Motherboard explains what to do next:

"If you have clicked on the link, go to your Google account's page (https://myaccount.google.com/permissions) where you can manage the permissions you've granted to apps (or go through the whole Google Security Checkup). Then locate the 'Google Doc' app. This looks totally legitimate, but it's actually not. If that's the malicious app that's gotten access to your account after you clicked on the link it should have a recent 'Authorization Time.' Now, click on that Google Docs app and click 'Remove.' "

And, in case it helps, know at least that you're not alone.

Many people — especially journalists — reported receiving these invites Wednesday afternoon. Enough people, in fact, that the hashtag #PhishingScam began trending on Twitter and email inboxes clogged with nearly as many warnings about the scam as instances of the scam itself.

So, once you successfully delete that phishy email — or take steps to remove its gnarled claws from your hapless inbox — you can take comfort in the fact that, no matter what ails you, Twitter has some snark to cure it.

That friend trying to get you to click on a Google Doc today is a phishing scam. DON'T CLICK, PEOPLES. 

Copyright 2017 NPR. To see more, visit http://www.npr.org/.

Get the WBEZ App

Download the best live and on-demand public radio experience. Find out more.