Search

Gmail Dot Feature Exploited to Commit Credit Fraud and More: Report

Advertisement
Highlights
  • The Gmail dot feature was misused for availing financial benefits
  • Cybercriminals even filed for fake tax returns
  • It was also exploited for availing certain online services
Gmail Dot Feature Exploited to Commit Credit Fraud and More: Report

The fraudsters have reportedly been exploiting the feature since early 2018

Gmail offers a nifty “dot” feature which redirects all emails to the same account in case users have mistakenly added a dot or a period in the recipient's email address. But cybercriminals are exploiting the same feature to commit crimes such as filing fake tax returns, availing financial benefits from government agencies, extending the trial period of online services, and credit fraud among others. As per a report, the bad actors have been exploiting the feature to commit a diverse array of scams since early 2018.

The Gmail dot feature fraud, that was discovered by security firm Agari and was first reported by Axios, was primarily employed to commit BEC (Business Email Compromise) scams. So, how did this happen? The Gmail dot feature ensures that emails intended for a particular recipient reaches them if the sender accidentally adds (or forgets) a dot or period in the username. For example, if someone intends to send an email to abc@gmail.comand mistakenly sends it to a.bc@gmail.com, the email will be delivered to the intended recipient who owns the correct username, or vice versa - if someone intends to send an email to a.bc@gmail.com, and mistakenly sends it to abc@gmail.com.

Since Gmail is the only major service provider to follow this practice of making these email addresses indistinguishable, service providers continue to treat each dot variant of the email address as a separate one, and indirectly, a different individual. While many of us have used this Gmail 'feature' to register 'different' emails to the same service provider, such as Netflix, it appears 

Gmail dot scam screenshot Gmail Dot Scam

The dot variants of a username used to file fake tax returns
Photo Credit: Agari

This vulnerability makes the process of scaling up a fraud much easier. As per the findings of security experts, a group of cybercriminals exploited the Gmail dot feature to avail around $65,000 (roughly Rs. 46,52,400) in credits from four banking institutions in the US. Moreover, they reportedly registered 14 different trial accounts with commercial services, filed 13 fraudulent tax returns before an online tax filing service and submitted 12 address change requests with the US postal service. Moreover, the feature was also misused to avail financial allowances such as social security benefits as well as disaster assistance and unemployment benefits under different identities.

Cybersecurity experts identified a total of 56 variants of an email address belonging to a single individual but differentiated by the placement of a dot in the username to bamboozle the service providers. And since all the emails intended for a supposedly different user were delivered to the same account, thanks to the Gmail dot feature, it became very easy for the bad actors to manage their fraudulent activities. 

Separately, Crane Hassold, Senior Director of Threat Research at Agari told ZDNet that the Gmail dot feature is only one of several Gmail features that can be used by scammers, such as the plus sign (where username+randomword@gmail.com redirects emails to username@gmail.com), and the legacy googlemail.com domain. While exploits on these features haven't yet been spotted in the wild, Hassold says they are just as efficient as the Gmail dot feature. 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Gmail, Gmail Dot Feature, Cybercrime
 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. HeartBeat Season 2 OTT Release Date: When and Where to Watch it Online?
  2. OnePlus Nord 5 Price in India, Launch Timeline, Key Features Leaked
  3. GTA 6 Has Been Delayed to 2026; Rockstar Confirms Launch Date
  4. Oppo Reno 14 With MediaTek Dimensity 8400 SoC Spotted on Geekbench
  5. Realme Narzo 80 Pro 5G Is Now Available in This Colour Variant in India
  6. Sony Xperia 1 VII May Debut with Snapdragon 8 Elite SoC and 12GB of RAM
  7. OnePlus Nord CE 5 Spotted on BIS Website, Could Launch in India Soon
  8. ISRO Sets June 2025 Launch for Joint NASA-ISRO NISAR Satellite After Delays
  9. Honor Teases Upcoming Launch of These New Smartwatches
  10. Poco F7 Listed on IMDA Certification Website, Could Launch Soon
  1. Juno Mission Sheds Light on Jupiter’s Storms and Volcanic Activity on Io
  2. New Study Uncovers Shadowy Origins of Universe’s Most Luminous Phenomena
  3. NASA’s Psyche Mission Encounters Pressure Drop, Backup Systems on Standby
  4. ISRO Sets June 2025 Launch for Joint NASA-ISRO NISAR Satellite After Delays
  5. See a Wafer-Thin Crescent Moon Leapfrog Jupiter in the Post-Sunset Sky This Week
  6. Realme Narzo 80 Pro 5G Nitro Orange Colour Variant Launched in India: Price, Specifications
  7. Oppo Reno 14 With MediaTek Dimensity 8400 SoC Seen on Geekbench Ahead of Debut
  8. Honor 400 Pro Arrives on Geekbench With Snapdragon 8 Gen 3, 12GB of RAM
  9. Microsoft Raises Xbox and Game Prices, Citing Rising Costs
  10. Grand Theft Auto 6 Delayed to Next Year, Will Launch on May 26, 2026
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »