← Back to Wiki
Security / Social Engineering
Google Account Recovery Scam Call: How the Vishing Attempt Works
A phone call claiming to be Google support tried, in real time, to talk its way into a real
Google account with a real Play Store developer app attached. It did not work. The technique behind it is
worth understanding in detail. It does not rely on guessing a password. It relies on you approving
something Google itself sends you.
What the call actually said
The caller identified as Google support, claiming the account's Play Console developer profile had been
breached and that its API keys were being reset as a result. Moments later, a real Google "Is this you
trying to recover your account?" push notification landed on the account owner's phone. The caller asked
for it to be approved to "confirm the reset."
BE WARNED: that prompt was not fake. That is what makes this dangerous. From their own end
the caller had kicked off Google's real password and account-recovery flow for the target account. Doing that
generates a genuine approval prompt on the real owner's device. The "breach" story was the pretext to get
someone to tap Approve on something Google itself sent. Approving it hands full account control to the
caller. No password, no 2FA code needed.
Why this works better than a fake login page
A phishing link pointing at a fake Google login page gets caught by a careful look at the URL bar, or a
password manager refusing to autofill on the wrong domain, or the browser's own phishing warning. This
technique skips all of that. There is no fake page. The prompt comes from google.com, on the
real Google app, referencing the real account. The only thing between the caller and full account access is
whether the person holding the phone taps the right button.
The tell, in hindsight
- Google does not call you. Google's real security and account-recovery processes are
self-service. Email, in-app notifications, or prompts inside Google Cloud Console and Play Console. An
unsolicited inbound call "from Google" about your account is close to a guaranteed red flag on its
own.
- The pretext was specific, not generic. The call referenced a Play Console developer
account, not a vague "your account has a problem". That is a sign of real reconnaissance. The caller
likely knew from public information that this Google account had a developer profile attached. Not a
random mass-dialed scam.
- Urgency plus a real-looking prompt is the whole attack. There was no time to look
anything up. No separate verification step suggested by the caller. Just "approve this to confirm the
reset". A genuine-looking prompt and an authority figure on the phone telling you what it means. That
combination is the entire mechanism. Remove either half and the attack does not work.
What actually stopped it
Two things, in order:
- Declining the prompt. Not approving something just because someone on the phone says
to, regardless of how official they sound or how real the prompt looks.
- Independent verification, on a separately typed URL. Going directly to
myaccount.google.com/notifications, typed by hand rather than through any link the caller
provided, showed no Google-initiated security event on file. That confirmed the whole "breach and API key
reset" story was fabricated, not just suspicious.
The rule that generalizes. If anyone calls you about resetting, recovering or verifying an
account and then asks you to approve a prompt, read back a code or "confirm" anything, hang up. Check the
account status yourself by typing the real URL in fresh. Legitimate account security processes never depend
on you taking an action during an unsolicited call to complete something.
Follow-up hardening worth doing regardless
Even with no real compromise, a call like this is a good prompt to check these. Most people set them up once
and never look again:
- Review recent sign-in activity and connected devices under the account's security settings.
- Confirm every 2-Step Verification method listed is yours. Remove anything unfamiliar.
- Prefer an authenticator app, a hardware key or a passkey over SMS. SMS is the fallback these calls pivot
toward next, through a follow-up SIM-swap attempt, because it needs no device prompt approved.
- Review third-party apps and services with account access for anything you do not recognize.
- Change the account password as a precaution, even if you are confident nothing was approved.
Report it. A caller ID name and number were left behind here, almost certainly spoofed.
Report it to
reportfraud.ftc.gov
and through your carrier's spam-reporting flow anyway. It helps the pattern get flagged even when the
specific number turns out to be a burner.