Connect with us

Crypto World

Kaspersky Uncovers Google Tasks Phishing To Steal Credentials

Published

on

An email sent by the attackers via Google Tasks

Editor’s note: The following briefing outlines a new phishing campaign uncovered by Kaspersky that hijacks legitimate Google Tasks notifications to steal corporate credentials. The attackers impersonate trusted services, leveraging the @google.com domain and intra-company cues to evade standard filters and pressure users into acting quickly. Victims are invited to click a link and complete a fraudulent employee verification form, exposing sensitive credentials that could grant unauthorized access. This advisory highlights the evolving tactics criminals use to exploit familiar tools and the importance of vigilance in enterprise environments.

Key points

  • Attackers abuse legitimate Google Tasks notifications to steal corporate credentials.
  • The campaign uses the trusted @google.com domain to bypass filters and build trust.
  • Users are directed to a fraudulent employee verification form after clicking a link.
  • The social engineering hinges on urgency and internal process appearance to lower defenses.

Why this matters

By exploiting familiar services, the campaign exploits trust in everyday tools, increasing the likelihood that employees reveal credentials. This approach bypasses many security filters and highlights the need for awareness and layered defenses in organizations. The incident underscores why training, MFA, and robust verification processes are critical as attackers continue to adapt to legitimate platforms.

What to watch next

  • Look for more phishing attempts that imitate enterprise tools via trusted notification channels.
  • Watch for fraudulent forms asking for corporate credentials and verify URLs before interacting.
  • Ensure MFA and mail-server security measures are in place to protect accounts.
  • Report suspicious activity to IT and update security policies as needed.

Disclosure: The content below is a press release provided by the company/PR representative. It is published for informational purposes.

Kaspersky discovers new phishing campaign exploiting Google Tasks notifications to steal corporate credentials

February 26, 2026

Kaspersky has uncovered a new phishing scheme that abuses legitimate Google Tasks notifications to trick corporate users into revealing corporate login credentials. By leveraging Google’s trusted @google.com email domain and notification system, attackers bypass traditional email security filters and exploit users’ trust in familiar services.

In this campaign, victims receive an authentic-looking notification from Google Tasks with the subject line “You have a new task.” The message creates the illusion that the recipient’s company has adopted Google’s task management tool, pressuring them to act quickly. The notification often includes elements of urgency, such as a high-priority flag and a tight deadline, to prompt the victim’s immediate response.

Advertisement
An email sent by the attackers via Google Tasks
An email sent by the attackers via Google Tasks

Upon clicking the embedded link, users are directed to a fraudulent form disguised as an “employee verification” page, where they are asked to enter their corporate credentials under the pretense of confirming their status. These stolen credentials can then be used for unauthorized access to company systems, data theft, or further attacks.

“Google’s vast ecosystem of services gets exploited by scammers. The scheme with Google Tasks is part of a broader trend observed before and continuing into 2026, where cybercriminals misuse legitimate platforms to distribute scams and phishing. Notifications originating from legitimate domains naturally evade many spam and phishing filters, while the social engineering aspect – making it seem like an internal company process – lowers the victim’s guard,” comments Roman Dedenok, Anti-Spam Expert at Kaspersky.

Read the article about this tactic on Kaspersky’s blog.

To counter this and similar threats, Kaspersky recommends:

  • Treat unsolicited invitations from any platform with suspicion, even if they appear to come from trusted sources
  • Carefully inspect URLs before clicking
  • Do not call any phone numbers indicated in suspicious emails – if you need to call support of a certain service, it is best to find the phone number on the official webpage of this service
  • Report suspicious emails to the platform provider and use multi-factor authentication for all accounts
  • For corporate users, Kaspersky Security for Mail Server with its multi-layered defense mechanisms powered by machine learning algorithms provides robust protection against a wide range of evolving threats and offers peace of mind to businesses in the face of evolving cyber risks
  • For individual users Kaspersky Premium offers AI-powered anti phishing features designed to help avoid phishing attacks and improve overall cybersecurity

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect individuals, businesses, critical infrastructure and governments around the globe. The company’s comprehensive security portfolio includes leading digital life protection for personal devices, specialized security products and services for companies, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help millions of individuals and nearly 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Crypto World

Florida man arrested in alleged $328M crypto ponzi scheme

Published

on

Florida man arrested in alleged $328M crypto ponzi scheme

A Florida man accused of running what is arguably the largest crypto-linked Ponzi scheme involving $328 million has been arrested, federal prosecutors said Wednesday.

Christopher Alexander Delgado, 34, of Apopka, Florida, was taken into custody on a criminal complaint charging him with wire fraud and money laundering, according to the U.S. Attorney’s Office for the Middle District of Florida. If convicted on all counts, he faces up to 30 years in federal prison. A criminal complaint contains allegations, and Delgado is presumed innocent unless and until proven guilty.

According to a TRM Labs global report, pyramid and Ponzi schemes received approximately $6.1 billion in victim funds globally in 2025, a 49% increase from the previous year. The most recent case prior to Goliath Ventures involves Ramil Ventura Palafox, the CEO of Praetorian Group International (PGI), who was sentenced to 20 years for misleading more than 90,000 investors and draining over $62.7 million in funds.

Prosecutors allege Delgado served as president and CEO of Goliath Ventures, formerly known as Gen-Z Venture Firm, from January 2023 through January 2026. During that period, authorities claim he raised at least $328 million from investors by promising monthly returns generated through cryptocurrency “liquidity pools,” sometimes described as “guaranteed” or “low risk,” with contracts promising monthly returns of roughly 3% to 8%.

Advertisement

Instead of investing the funds as represented, Delgado allegedly operated Goliath as a Ponzi scheme, using money from new investors to pay purported returns to earlier backers and to meet withdrawal requests.

The complaint alleges that the firm’s claims about deploying capital into crypto liquidity pools were false. According to court filings, investigators said blockchain analysis showed only about $1.5 million was sent to Uniswap, while the “vast majority” of investor funds were not placed into liquidity pools.

To build credibility and attract victims, prosecutors say Delgado relied on personal referrals, polished marketing materials, luxury events, charitable sponsorships and periodic payments marketed as returns. The court documents also revealed investors were shown account updates via an online portal that displayed consistent gains, but the reported “returns” were allegedly fabricated and adjusted to match promised rates.

The case is being investigated by IRS Criminal Investigation and Homeland Security Investigations and is being prosecuted by the U.S. Attorney’s Office in Orlando. Law enforcement officials are asking potential victims to come forward as the investigation continues.

Advertisement

Source link

Continue Reading

Crypto World

Vitalik Buterin unveils roadmap to counter quantum computing threat

Published

on

Vitalik Buterin issues a blunt reality check to the biggest crypto networks

Ethereum co-founder Vitalik Buterin outlined a roadmap on Thursday to protect the blockchain from the long-term risks posed by quantum computers — a move that comes shortly after the Ethereum Foundation established a dedicated post-quantum research team to study the issue.

Although practical quantum computers capable of breaking modern cryptography do not yet exist, they could one day crack the digital signatures and cryptographic systems that secure Ethereum.

In a post on X, Buterin identified four key areas of vulnerability: validator signatures used in consensus, Ethereum’s data availability system, everyday wallet signatures, and certain zero-knowledge proofs used by applications and layer-2 networks.

A big part of the plan involves changing how Ethereum’s validators sign and confirm blocks. Right now, they use a type of digital signature called BLS. In a world with powerful quantum computers, those signatures could eventually be broken. Buterin suggests switching to “hash-based” signatures, which are considered much safer against quantum attacks.

Advertisement

Another area that would need updating is how Ethereum checks and stores large batches of transaction data. The system it uses today relies on a cryptographic tool called KZG commitments. Replacing that with a quantum-safe alternative is possible, Buterin said, but it would require significant behind-the-scenes engineering work and could make some parts of the system more complicated.

For everyday users, the proposed fix revolves around a planned upgrade called EIP-8141. In simple terms, this upgrade would make Ethereum wallets more flexible. Today, most wallets rely on one standard type of digital signature to approve transactions. EIP-8141 would allow accounts to switch to different types of signatures in the future — including ones designed to be safe against quantum computers.

There’s a similar issue with zero-knowledge proofs, a type of advanced cryptography used by privacy tools and many layer-2 scaling networks. Quantum-safe versions of these proofs are currently far more expensive to verify on Ethereum.

Buterin pointed to a longer-term solution built into EIP-8141 known as “validation frames.” These would allow the network to bundle together many signatures and proofs and replace them with a single combined proof. Instead of checking each one individually on the blockchain, Ethereum would only need to verify one compressed proof, helping keep costs down.

Advertisement

Read more: Quantum threat gets real: Ethereum Foundation prioritizes security with leanVM and PQ signatures

Source link

Continue Reading

Crypto World

Popular Trader Calls Cardano (ADA) One of His Worst Investments: The Community Reacts

Published

on

Popular Trader Calls Cardano (ADA) One of His Worst Investments: The Community Reacts


“The growth in Cardano’s technology has been amazing, and the best is yet to come,” one X user stroke back.

Cardano’s native token reached an all-time high of almost $3.10 in late 2021. Despite sporadic runs in the following years, it has not managed to break its record and is currently worth around $0.29, representing a staggering 90% decline from the historic peak.

The steep decline has left many investors frustrated, including popular content creator Jake Gagain, who described ADA as one of his worst investments since entering the crypto market.

Advertisement

Wasting “Such a Great Opportunity?’

Besides expressing regret over his investment, Gagain emphasized that Cardano still has a strong community and huge potential. He said he was disappointed to see the team waste “such a great opportunity” and asked his followers whether they still hold ADA.

His post on X sparked a heated debate, with many users sharing their experiences with the token. One person agreed with Gagain, arguing that Cardano’s community is among the most dedicated, “but the execution and speed have just been painful to watch for years now.”

The discontent was echoed by numerous others, some of whom pledged to step away from ADA and all altcoins for good and to shift their capital solely to Bitcoin (BTC) from now on.

Others differentiated from this thesis. X user Michael Lesser claimed that Gagain doesn’t understand the definition of a bear market, adding that his timing is bad.

Advertisement

“If you have an investment thesis and patience, ‘paper losses’ are just that. The growth in Cardano’s technology has been amazing, and the best is yet to come,” he said.

Many investors who remain optimistic said they would keep accumulating ADA, convinced that the token will set a new all-time high sooner or later. Some even flashed the “diamond hands” emoji to signal their determination not to sell under any circumstances.

You may also like:

Meanwhile, certain X users attacked Gagain for promoting meme coins, which performed much worse than ADA. In the summer of 2024, for instance, he claimed that NEIRO could be the next “billion-plus dollar project” on the Ethereum blockchain. It is important to note that the asset’s market cap briefly surged above $1 billion in late 2024, but since then, it has been in a sharp decline, and its current capitalization stands at less than $30 million.

What’s Next for ADA?

Cardano’s native token has been among the biggest beneficiaries of the recent market resurgence, with its price rallying by 9% on a weekly scale. The recent whale activity suggests a further jump might be on the way.

As CryptoPotato reported, large investors have scooped up almost 820 million coins over the past six months, thus increasing their total holdings to 25.36 billion tokens, or nearly 70% of ADA’s circulating supply.

Advertisement

Big purchases of this type leave fewer tokens on the open market, which could result in a surging price (should demand remain constant or rise). Whales’ buying also sends a strong signal that they believe in the asset’s long-term future, and that confidence could draw smaller players into the ecosystem.

Some analysts observed ADA’s recent comeback and envisioned further gains if key levels are reclaimed. X user Nehal argued that breaking and holding above $0.30 could lead to a pump to $0.32 and $0.34.

SPECIAL OFFER (Exclusive)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Advertisement

Source link

Continue Reading

Crypto World

REX Shares Launches New ETF with Exposure to Coinbase and Strategy

Published

on

REX Shares Launches New ETF with Exposure to Coinbase and Strategy

US-based asset manager REX Shares has launched an exchange-traded fund that bundles leveraged covered-call strategies tied to nine individual stocks, including crypto-linked names Coinbase and Strategy, into a single income-focused product trading under the ticker GIF.

According to Thursday’s announcement, the fund holds equal-weighted positions in REX’s existing single-stock Growth & Income ETFs, each of which targets about 1.25x exposure to its underlying equity while writing covered calls on a portion of the portfolio to generate option premium income.

GIF trades on Cboe Global Markets and each underlying ETF seeks to distribute income on a weekly basis, with payouts largely derived from covered call premiums.

Advertisement

Covered call premiums are the upfront payments a fund collects for selling options on stocks it already owns, generating income in exchange for capping some of the shares’ upside potential.

REX Shares said the ETF holds equal-weighted exposure to nine REX funds tied to Nvidia (NVII), Tesla (TSII), Strategy (MSII), Coinbase (COII), Robinhood (HOII), Palantir (PLTI), CoreWeave (CWII), Eli Lilly (LLII) and Walmart (WMTI), spanning crypto-linked equities, technology, AI, healthcare and retail sectors.

Related: Michael Saylor says quantum threat to Bitcoin is more than 10 years away

21Shares lists STRC ETP as companies add Strategy preferred shares to treasuries

The launch comes amid a week of new allocations tied to Strategy-linked securities.

Advertisement

On Wednesday, 21Shares introduced an exchange-traded product (ETP) giving European investors exposure to STRC, Strategy’s variable-rate perpetual preferred stock. The 21Shares Strategy Yield ETP began trading on Euronext Amsterdam under the ticker STRC NA on Thursday.

Also on Wednesday, Strategy said Prevalon Energy, an energy infrastructure company, and Anchorage Digital, a crypto-focused digital asset bank, had allocated portions of their corporate treasuries to STRC, though they did not disclose the size of their positions.

Strategy describes STRC as a digital credit instrument with an 11.25% annual dividend, part of its broader effort to issue fixed-income securities tied to its Bitcoin (BTC) holdings.

Strategy’s BTC holdings over time. Source: Bitbo.io

Since adopting its Bitcoin treasury strategy in August 2020, Strategy has become the largest corporate holder of Bitcoin, reporting 717,722 BTC, or about 3.4% of the fixed 21 million supply.

Despite demand for Strategy-linked securities, the company’s shares have fallen alongside Bitcoin’s price. The stock is down more than 60% over the past six months and about 50% over the past year, according to Yahoo Finance data.

Advertisement
Source: Yahoo Finance

​​Strategy has also emerged as the most heavily shorted large-cap US stock on Goldman Sachs’ latest ranking, based on short interest relative to market value.

Magazine: Bitcoin’s ‘biggest bull catalyst’ would be Saylor’s liquidation: Santiment founder