← Back to Wiki
Security / Social Engineering

Google Account Recovery Scam Call: How the Vishing Attempt Works

A phone call claiming to be Google support tried, in real time, to talk its way into a real Google account with a real Play Store developer app attached. It did not work. The technique behind it is worth understanding in detail. It does not rely on guessing a password. It relies on you approving something Google itself sends you.

Share on X

What the call actually said

The caller identified as Google support, claiming the account's Play Console developer profile had been breached and that its API keys were being reset as a result. Moments later, a real Google "Is this you trying to recover your account?" push notification landed on the account owner's phone. The caller asked for it to be approved to "confirm the reset."

BE WARNED: that prompt was not fake. That is what makes this dangerous. From their own end the caller had kicked off Google's real password and account-recovery flow for the target account. Doing that generates a genuine approval prompt on the real owner's device. The "breach" story was the pretext to get someone to tap Approve on something Google itself sent. Approving it hands full account control to the caller. No password, no 2FA code needed.

Why this works better than a fake login page

A phishing link pointing at a fake Google login page gets caught by a careful look at the URL bar, or a password manager refusing to autofill on the wrong domain, or the browser's own phishing warning. This technique skips all of that. There is no fake page. The prompt comes from google.com, on the real Google app, referencing the real account. The only thing between the caller and full account access is whether the person holding the phone taps the right button.

The tell, in hindsight

What actually stopped it

Two things, in order:

  1. Declining the prompt. Not approving something just because someone on the phone says to, regardless of how official they sound or how real the prompt looks.
  2. Independent verification, on a separately typed URL. Going directly to myaccount.google.com/notifications, typed by hand rather than through any link the caller provided, showed no Google-initiated security event on file. That confirmed the whole "breach and API key reset" story was fabricated, not just suspicious.
The rule that generalizes. If anyone calls you about resetting, recovering or verifying an account and then asks you to approve a prompt, read back a code or "confirm" anything, hang up. Check the account status yourself by typing the real URL in fresh. Legitimate account security processes never depend on you taking an action during an unsolicited call to complete something.

Follow-up hardening worth doing regardless

Even with no real compromise, a call like this is a good prompt to check these. Most people set them up once and never look again:

Report it. A caller ID name and number were left behind here, almost certainly spoofed. Report it to reportfraud.ftc.gov and through your carrier's spam-reporting flow anyway. It helps the pattern get flagged even when the specific number turns out to be a burner.