← Back to Wiki
Security / Social Engineering
Anatomy of a Google Account Vishing Call
A phone call claiming to be Google support tried, in real time, to talk its way into a real
Google account with a real Play Store developer app attached to it. It didn't work — but the technique
behind it is worth understanding in detail, because it doesn't rely on guessing a password. It relies on
you approving something Google itself sends you.
What the call actually said
The caller identified as Google support, claiming the account's Play Console developer profile had been
breached and that its API keys were being reset as a result. Moments later, a real Google "Is this you
trying to recover your account?" push notification landed on the account owner's phone. The caller asked
for it to be approved to "confirm the reset."
That prompt wasn't fake — that's what makes this dangerous. The caller had, from their own
end, actually kicked off Google's real password/account-recovery flow for the target account. Doing that
generates a genuine approval prompt on the real owner's device. The "breach" story was just the pretext to
get someone to tap Approve on something Google itself sent — which would have handed full account control
to the caller, no password or 2FA code needed.
Why this works better than a fake login page
A phishing link pointing at a fake Google login page can be caught by a careful look at the URL bar, a
password manager that refuses to autofill on the wrong domain, or a browser's own phishing-site warning.
This technique skips all of that. There's no fake page — the prompt genuinely comes from
google.com, on the real Google app, referencing the real account. The only thing standing
between the caller and full account access is whether the person holding the phone taps the right button.
The tell, in hindsight
- Google does not call you. Google's real security and account-recovery processes are
entirely self-service — email, in-app notifications, or prompts inside Google Cloud Console / Play
Console. An unsolicited inbound call "from Google" about your account is, on its own, close to a
guaranteed red flag.
- The pretext was specific, not generic. The call referenced a Play Console developer
account specifically, rather than a vague "your account has a problem." That's a sign of real
reconnaissance — the caller likely knew, from public information, that this Google account had a
developer profile attached to it — not a random mass-dialed scam.
- Urgency plus a real-looking prompt is the whole attack. There was no time pressure to
look anything up, no separate verification step suggested by the caller — just "approve this to confirm
the reset." That combination (a genuine-looking prompt + an authority figure on the phone telling you
what it means) is the entire mechanism. Remove either half and the attack doesn't work.
What actually stopped it
Two things, in order:
- Declining the prompt. Not approving something just because someone on the phone says
to, regardless of how official they sound or how real the prompt looks.
- Independent verification, on a separately-typed URL. Going directly to
myaccount.google.com/notifications — typed by hand, not through any link the caller
provided — showed no actual Google-initiated security event on file. That confirmed the entire "breach
and API key reset" story was fabricated, not just suspicious.
The rule that generalizes: if anyone calls you about resetting, recovering, or verifying an
account and then asks you to approve a prompt, read back a code, or "confirm" anything — hang up, and check
the account status yourself by typing the real URL in fresh. Legitimate account security processes never
depend on you taking an action during an unsolicited call to "complete" something.
Follow-up hardening worth doing regardless
Even with no real compromise, a call like this is a good prompt to actually check these, since most people
set them up once and never look again:
- Review recent sign-in activity and connected devices under the account's security settings.
- Confirm every 2-Step Verification method listed is actually yours; remove anything unfamiliar.
- Prefer an authenticator app or a hardware/passkey second factor over SMS — SMS is the fallback these
calls often try to pivot toward next (via a follow-up SIM-swap attempt), since it doesn't require
approving a device prompt.
- Review third-party apps and services with account access for anything you don't recognize.
- Change the account password as a precaution, even if you're confident nothing was approved.
Report it. A caller ID name and number were left behind in this case, almost certainly
spoofed — worth reporting to
reportfraud.ftc.gov and through your carrier's spam-reporting flow regardless, since it
helps the pattern get flagged even when the specific number turns out to be a burner.