Technology

Scammers have discovered a way to violate Gmail’s blue verified checkmark protection

The point of trusting online sources and apps is complicated as much as we try to keep ourselves aware and safe, but these scammers still find the latest tools and techniques to barge into our sensitive information. Because of this, businesses have long worked to create tests that are simple to understand and can be used quickly to confirm an individual’s online identity, like the tiny blue checkmarks you can find next to confirmed senders in your Gmail inbox. Unfortunately, it appears that at least a few dishonest people have managed to take advantage of Google’s technology.

With technologies like BIMI (Brand Indicators for Message Identification), VMC (Verified Mark Certificate), and DMARC (Domain-Based Message Authentication, Reporting, and Conformance), Gmail gives businesses and organizations the ability to confirm their identity. Gmail will start displaying a company’s logo and that blue checkmark next to its name once it has gone through the necessary hoops to demonstrate that it is who it claims to be.

As observed by cybersecurity engineer Chris Plummer, some bad actors have found a way to violate the boundary of Google’s protection and make the message look like it came from an original source.

Plummer was troubled by what he learned, so he contacted Google to alert the corporation to this obviously problematic scenario. However, when he did, his bug report was promptly dismissed with the explanation that this was somehow “intended behavior.” Because that response didn’t pass the smell test, Plummer vented his concerns on Twitter. The reaction on social media to what he had to say was negative, and it was significant enough to reportedly cause Google to reconsider its initial rejection.

Now that Google is in charge, we’re cautiously optimistic that the issue that led to this attack will be rapidly found and fixed. Although it doesn’t look good that Plummer had to virtually drag Google into taking this seriously, we’re just satisfied by the way the company is involved in resolving the issue.

Recent Posts

Multikernel Linux: Multiple Linux systems without a VM on one device

Multikernel Technologies has a public version of its multikernel Linux for the first time with…

22 hours ago

Memory crisis makes you creative: New MSI laptop with DDR4 or DDR5

The world's PC manufacturers are in a bind when it comes to memory. DDR4 RAM…

22 hours ago

Gamescom 2026: Series of thefts hit small indie developers hard

How safe are the protected halls of Gamescom 2026 really? After the night-time theft of…

23 hours ago

GrapheneOS: No secure Android for the Pixel 11 because Google is sloppy?

Google has apparently made changes to the security features of the Pixel 11 series, which…

23 hours ago

The Smart Girl’s Guide to Staying Safe Online While Shopping

Bagging a bargain online has never been easier - or riskier. Between dodgy "influencer" deals…

23 hours ago

Google against website operators: AI overview in search even larger

Google is expanding its AI overviews and is now displaying even more information and details…

24 hours ago