← Back to Wiki
Security / Social Engineering

Anatomy of a Google Account Vishing Call

A phone call claiming to be Google support tried, in real time, to talk its way into a real Google account with a real Play Store developer app attached to it. It didn't work — but the technique behind it is worth understanding in detail, because it doesn't rely on guessing a password. It relies on you approving something Google itself sends you.

Share on X

What the call actually said

The caller identified as Google support, claiming the account's Play Console developer profile had been breached and that its API keys were being reset as a result. Moments later, a real Google "Is this you trying to recover your account?" push notification landed on the account owner's phone. The caller asked for it to be approved to "confirm the reset."

That prompt wasn't fake — that's what makes this dangerous. The caller had, from their own end, actually kicked off Google's real password/account-recovery flow for the target account. Doing that generates a genuine approval prompt on the real owner's device. The "breach" story was just the pretext to get someone to tap Approve on something Google itself sent — which would have handed full account control to the caller, no password or 2FA code needed.

Why this works better than a fake login page

A phishing link pointing at a fake Google login page can be caught by a careful look at the URL bar, a password manager that refuses to autofill on the wrong domain, or a browser's own phishing-site warning. This technique skips all of that. There's no fake page — the prompt genuinely comes from google.com, on the real Google app, referencing the real account. The only thing standing between the caller and full account access is whether the person holding the phone taps the right button.

The tell, in hindsight

What actually stopped it

Two things, in order:

  1. Declining the prompt. Not approving something just because someone on the phone says to, regardless of how official they sound or how real the prompt looks.
  2. Independent verification, on a separately-typed URL. Going directly to myaccount.google.com/notifications — typed by hand, not through any link the caller provided — showed no actual Google-initiated security event on file. That confirmed the entire "breach and API key reset" story was fabricated, not just suspicious.
The rule that generalizes: if anyone calls you about resetting, recovering, or verifying an account and then asks you to approve a prompt, read back a code, or "confirm" anything — hang up, and check the account status yourself by typing the real URL in fresh. Legitimate account security processes never depend on you taking an action during an unsolicited call to "complete" something.

Follow-up hardening worth doing regardless

Even with no real compromise, a call like this is a good prompt to actually check these, since most people set them up once and never look again:

Report it. A caller ID name and number were left behind in this case, almost certainly spoofed — worth reporting to reportfraud.ftc.gov and through your carrier's spam-reporting flow regardless, since it helps the pattern get flagged even when the specific number turns out to be a burner.