a Google Doc link in your inbox today , scrutinize it carefully before you click—even if it looks likeAttack.Phishingit comes fromAttack.Phishingsomeone you trust . A nasty phishing scamAttack.Phishingthat impersonatesAttack.Phishinga Google Docs request has swept the internet today , including a decent chunk of media companies . You 've heard `` think before you click '' a million times , but it really could save you from a whole lot of hassle . Google has taken steps to neutralize this particular phishAttack.Phishing. The company said in a statement that it has `` disabled offending accounts . We ’ ve removed the fake pages , pushedVulnerability-related.PatchVulnerabilityupdates through Safe Browsing , and our abuse team is working to prevent this kind of spoofingAttack.Phishingfrom happening again . '' But when it comes to phishing defenseAttack.Phishingthere 's always an element of cat and mouse . Large-scale phishing attacksAttack.Phishingand those impersonatingAttack.Phishingpopular services like Google log-in pages regularly stalk the internet . `` The importance of this phishAttack.Phishingis not how it spread , but rather how it didn ’ t use malware or fake websites trickingAttack.Phishingusers to give up their passwords , '' says Aaron Higbee , chief technology officer at the phishing research and defense company PhishMe , which analyzed data from the fake Google Docs campaign. `` This phishAttack.Phishingworked because it trickedAttack.Phishingthe user into granting permissions to a third-party application . This is the future of phishingAttack.Phishing, and every security technology vendor is ill-equipped to deal with it . '' Similar Google Docs scamsAttack.Phishingin particular have been circulatingAttack.Phishingsince at least 2014 , but that does n't make them any easier to spot , in part because they seem so authentic . Phishers can use real Google accounts and develop third-party plugins that can interact with Google services , so they can lureAttack.Phishingvictims in through the most perfect-looking Google web pages of all : Genuine ones .