One morning in August, a member of our team answered a call from a California number.
The caller, polished and speaking with a flawless American accent, claimed to be from Google. An attempt had been made, the caller said, to change the account recovery address on the employee’s Gmail account, and an email about it was sitting in his inbox at that very moment.
Upon further investigation, however, our team member soon learned things were not as they seemed.
This was a phishing scam, and a more sophisticated form of social engineering. It used a carefully scripted conversation designed to build just enough trust that you believe the caller really is Google, ultimately persuading you to hand over some form of access.
Our colleague ended the call before reaching that moment, so the exact ask went unheard. But the structure of the scam tells you exactly where it was headed.
- How this Google account recovery scam works
- The tells, annotated
- Why this Gmail scam is so convincing
- How to protect yourself from account takeover attempts
- A safer inbox starts with better email security
How this Google account recovery scam works
The setup
Before the phone rings, the scammer creates a fresh, anonymous Gmail address, which consists of random letters and digits. Using Google’s legitimate “add a recovery email” flow, they try to add the victim’s address as the recovery email for the scammer’s own throwaway account.
The first real email
Google’s system needs the victim’s confirmation, so an authentic message arrives asking them to verify the recovery email. The sender, branding, and code are real. (Figure 1 below)
The call
The scammer makes a call, poses as a member of Google’s security team, and describes a suspicious account access attempt that was supposedly blocked, even claiming to have intercepted the victim’s authenticator code. The word “blocked” casts the caller as the hero. In reality, the attack is the phone call.
The second real email
Still on the line, the victim receives a genuine “Security alert” announcing that a recovery email was changed on a linked Google Account. Skimmed, it looks like a compromise. Read carefully, the fine print reveals it’s a copy of an alert sent to the scammer’s address. (Figure 2 below)
The vanishing act
The first email offers a legitimate escape: removing your address from the stranger’s account. But the moment our colleague hung up, the scammer withdrew the recovery request, erasing the trail, and likely moved on to the next target.
The tells, annotated
Figure 1 shows the first Google email, which contains a security code needed to confirm your address as the recovery email for the scammer’s account.

- The genuine Google sender — real, which is precisely what makes it dangerous.
- “Wants to use your email address as their recovery email” — the reversed logic, as this is about someone else’s account.
- The anonymous throwaway address — no way to verify who’s behind it.
- The expiring code — manufactured urgency, keeping you stressed and compliant.
- “Remove email” — the one action that stops it, and exactly what the scammer cancels when you hang up.
Figure 2 shows how a genuine Google security alert can appear alarming at first.

- The subject addresses the scammer’s inbox, not yours — the first sign this alert isn’t about you.
- “A copy of a security alert sent to” the throwaway address — the biggest tell, and the easiest to miss on a skim.
- The alarming headline — designed to scare before you read the fine print.
- “If you didn’t change it, check what happened” — planted doubt that primes you to trust the caller.
- The “Check activity” button — a prompt to act fast instead of read carefully.
Why this Gmail scam is so convincing
Both phishing emails come from Google’s real servers, so every conventional anti-phishing check passes.
Each element corroborates the others: real notifications, plus a caller who knows exactly what just landed in your inbox. At the same time, the conversation can discourage any attempt you may have to click “Remove email”, keeping you focused on the caller’s instructions.
A Google data breach can make scams like this more convincing if exposed information gives attackers details they can use to personalize vishing or phishing attacks. Even when passwords aren’t leaked, names, contact details, or account-related information can help scammers sound more credible and build trust.
How to protect yourself from account takeover attempts
You can protect yourself by slowing the interaction down and verifying what’s happening through Google directly:
Hang up and verify independently. If someone calls claiming to be from Google, end the call and check your account directly rather than following their instructions.
Read Google security emails carefully. Pay attention to which account the alert actually refers to, especially any line saying the message is a copy of an alert sent to another address.
Do not share verification codes. Google will not need you to read out an authenticator code, recovery code, or other sign-in credential over the phone.
Use “Remove email” if you do not recognize the account. If Google says someone wants to use your address as their recovery email, remove it from that account.
Do not let the caller rush you. Scammers rely on urgency to keep you reacting instead of checking what the notification actually says.
Review your Google Account security directly. Open your account settings yourself and check recent activity, signed-in devices, recovery details, and security alerts.
Report suspicious calls and messages. Reporting the attempt can help Google and your phone provider identify repeated abuse.
Review your Google privacy settings. While privacy settings won’t stop this particular scam, regularly checking what data you share and which apps and services have access to your Google Account can reduce your exposure.
A safer inbox starts with better email security
Scams like this are a reminder that even legitimate security emails can be turned into tools for social engineering. Staying skeptical of unexpected calls, checking account activity independently, and reading alerts carefully can help you avoid falling for them.
Looking for a better alternative to Gmail? Proton Mail gives you a secure email service built around protecting your data and communications with end-to-end and zero-access encryption.
If someone tries a similar scam while pretending to be Proton, there’s a simple rule to remember: Proton will never call you about an account security issue. You can protect your account from takeover by enabling two-factor authentication. On paid plans, Proton Sentinel combines automated detection with human security analysis.
Proton Mail also includes protections against more conventional phishing attempts, such as cloud storage email scams. PhishGuard blocks and flags suspected phishing emails, while link confirmation prompts you to verify before opening external links from an email.
No email service can provide perfect protection against account takeover. However, if someone does manage to break into your Proton account using email or SMS recovery, they won’t automatically gain access to your emails and contacts, thanks to separate data recovery protections.






