
The legitimate Netflix notification ‘update your card details’ would arrive in the real user's inbox, who would later update the scammer's account unknowingly. Recently, a scammer group used Gmail ‘Dot accounts’ to trick Netflix account owners into adding card details to scammers' accounts. Scammers are taking advantage of this feature and creating multilple email accounts to perform various fraudulent activities such as filing for fraudulent unemployment benefits, filing fake tax returns, bypassing trial periods for online services, and more.Įmail security firm Agari in its blog described one of the scams where a scammer was able to submit 22 separate applications using different email accounts and successfully opened over $65,000 in fraudulent credit cards at a single financial institution. Scammers are leveraging this feature to create multiple accounts on a single website which then direct all communication to a single Gmail account.įor example, Google considers red.applegmailcom, egmailcom,, and redapplegmailcom as same and emails sent to any of these email addresses will arrive at the same email account. Gmail's ‘Dot accounts’ is a feature of Gmail addresses that ignores dot characters inside Gmail usernames, regardless of their placement.

Researchers recently observed that Business Email Compromise (BEC) scammers are exploiting a Gmail feature ‘Dot accounts’ to perform various fraudulent activities. Gmail's ‘Dot accounts’ is a feature of Gmail addresses that ignores dot characters inside Gmail usernames, regardless of their placement.

Scammers are exploiting Gmail feature ‘Dot accounts’ to perform various fraudulent activities such as filing for fraudulent unemployment benefits, filing fake tax returns, and more.
