16 min read

Fake Google Security Checkup Scam 2026: The Page That Spies

A fake Google Security Checkup page is spreading in 2026 — it looks real, installs as an app with no address bar, and quietly steals your Gmail 2FA codes.

OldGmail Team
Fake Google Security Checkup Scam 2026: The Page That Spies

You get an urgent alert while browsing — a page styled in Google's exact colors warns that your account is at risk and offers to run a "Security Checkup" to fix it. It looks like the real tool you have used before, so you tap the button. That single tap is the whole attack. This is the fake Security Checkup scam, one of the most alarming Gmail threats of 2026: a counterfeit Google Security Checkup page that, instead of protecting your account, quietly turns your own browser into a surveillance tool that watches everything you do.

Security researchers who dissected the campaign in early 2026 called the payload one of the most fully featured browser-based surveillance toolkits they had ever seen — and the disguise is a page nearly every Gmail user has been trained to trust. This guide explains exactly how the fake Security Checkup scam works, why it slips past the defenses you rely on, how to tell the counterfeit page from Google's real one, and what to do the moment you suspect you tapped the wrong button. Whether you guard one personal inbox or a fleet of aged Gmail accounts, this is a lure you need to recognize on sight.

What Is the Fake Security Checkup Scam?

The fake Security Checkup scam is a social-engineering attack that impersonates Google's genuine Security Checkup — the legitimate dashboard that shows your recent sign-ins, connected devices, and third-party app access. In the scam, a malicious web page mimics that trusted interface pixel for pixel, warns you that your account is under threat, and offers to "run a checkup" or "secure your account now." The button does not fix anything. It walks you through a short flow that grants an attacker deep access to your device and, from there, to your Gmail.

What makes this Security Checkup scam so effective is the disguise. Google has spent years teaching users to run its real Security Checkup whenever something feels off — it appears in the account security tips of nearly every legitimate guide, including our own. Attackers weaponize that training. By dressing their trap as the exact tool people reach for when they are worried, the fake Security Checkup turns your good security habit into the delivery mechanism for the attack. You think you are hardening your account; you are actually installing the threat.

Unlike a traditional phishing page that simply harvests your password, the counterfeit Security Checkup goes much further. Malwarebytes researchers who reverse-engineered the 2026 campaign described a four-step flow that requests push-notification permission, access to your contact list, real-time GPS location, and clipboard contents — all without installing a single app from an app store. The page itself becomes the malware. That is what separates this from ordinary phishing and why the fake Security Checkup scam deserves its own place in your threat model.

Why the Security Checkup Scam Surged in 2026

Fake security pages are not new, but the Security Checkup scam reached a new level of polish and reach in 2026. Several forces converged to push it into the mainstream.

  • AI erased every tell. The old giveaways — misspellings, blurry logos, clumsy layouts — are gone. Generative tools now clone Google's fonts, spacing, and animation in minutes, so a fake Security Checkup page is visually indistinguishable from the real dashboard.
  • It exploits a habit Google built. Because "run a Security Checkup" is standard advice from Google and every reputable security site, the scam borrows the credibility of a genuinely good recommendation. Victims are primed to comply.
  • Progressive web apps hide the warning signs. The 2026 campaign pins the fake page to your home screen as a progressive web app (PWA), stripping away the browser address bar that would normally reveal the real, non-Google URL.
  • It is sold as a kit. Like the ClickFix scam, the fake Security Checkup is packaged as a ready-made toolkit, letting low-skill criminals launch professional-grade campaigns for a subscription fee.

The result is that the standard advice — "look for typos, check the logo" — no longer catches this threat. The fake Security Checkup page has no typos and a perfect logo. It relies entirely on getting you to trust a familiar-looking interface and tap through a flow that feels reassuring. For the full 2026 picture, our breakdown of Google's June 2026 scam advisory covers the other named techniques that share this DNA.

How the Attack Unfolds, Step by Step

Every fake Security Checkup scam follows a similar script, whether the lure arrives by email, ad, text, or a compromised website. Understanding the sequence is the surest way to interrupt it before the damage is done.

  1. The alarm. You encounter a warning — in an email, a pop-up, a malicious ad, or a redirect from a hacked site — telling you your Google account is compromised, has suspicious activity, or "requires immediate verification." Urgency is the point.
  2. The familiar page. Tapping the alert loads a page that looks exactly like Google's Security Checkup: the shield icon, the account summary, the reassuring blue-and-white palette. It "detects" a threat and offers to fix it.
  3. The install prompt. The page asks you to "install the security tool" or "add to home screen." On mobile this pins it as a progressive web app that opens full-screen, with no address bar to betray the fake URL.
  4. The four-step flow. The counterfeit Security Checkup then walks you through granting permissions — push notifications, contacts, location, clipboard — each framed as a step required to "complete the checkup."
  5. The silent harvest. Once granted, the page reads clipboard contents (where people paste passwords, one-time codes, and crypto wallet addresses), fingerprints your device, intercepts SMS-style prompts through notifications, and can track your location in real time.
  6. The account takeover. With intercepted codes and harvested credentials, the attacker moves on your Gmail directly — or sells the access. Because the tool captures one-time passwords as they arrive, even accounts with SMS two-factor can fall.

The elegance of the fake Security Checkup scam is that every step feels like security, not compromise. You are never asked to download a suspicious file or type a strange command. You simply tap "allow" on prompts that a real Google tool might plausibly show — and by the end, you have handed over the keys.

The PWA Trick: Why It Hides the Address Bar

The single most important technical detail of the 2026 Security Checkup scam is its use of a progressive web app. A PWA is a legitimate web technology that lets a website behave like an installed app — it gets an icon on your home screen and opens in its own full-screen window. Google, Twitter, and countless real services offer PWAs. Attackers abuse the same feature for a devastating reason: a PWA opens without the browser's address bar.

The address bar is your last line of defense against a fake Security Checkup. In a normal browser tab, you could glance up and see that the URL is not myaccount.google.com but some lookalike or random domain. Once the page is pinned as a PWA and launched from your home screen, that check disappears. The counterfeit Security Checkup now fills the entire screen, indistinguishable from a native Google app, with no visible URL to expose the lie.

This is why the "add to home screen" or "install" prompt is the critical moment. Google's real Security Checkup lives inside your existing Google account settings — it never asks to be installed as a separate app. Any Security Checkup that wants to add an icon to your home screen is fake, full stop. Recognizing that single request is enough to defeat the entire attack, because everything dangerous happens only after you install the PWA.

What the Fake Security Checkup Actually Steals

Once you complete the flow, the counterfeit Security Checkup becomes a browser-based remote access tool. Researchers cataloged an unusually broad set of capabilities in the 2026 samples. Here is what the permissions it requests actually enable:

  • Clipboard contents. Anything you copy — passwords from a manager, one-time codes, seed phrases, wallet addresses — can be read the instant it lands on your clipboard.
  • Push notifications. Granting notification access lets the attacker intercept prompts and codes and also push convincing fake "Google" alerts to keep you engaged.
  • Contact list. Your contacts are exfiltrated to fuel the next wave of the scam, since a lure that appears to come from someone you know is far more effective.
  • Real-time location. GPS access lets the attacker track your movements and tailor location-aware social engineering.
  • Device fingerprint. A detailed profile of your device helps attackers replicate your session and slip past Google's anomaly detection when they log in as you.

The theft of one-time codes is the most dangerous piece. It is what lets the fake Security Checkup scam defeat two-factor authentication that relies on SMS or app codes. The attacker triggers a login, the code arrives on your device, the malicious tool reads it through the permissions you granted, and your second factor is neutralized. This is the same weakness that makes SMS-based verification increasingly obsolete — a shift we cover in our guide to Gmail passkeys and going passwordless, which are immune to this class of interception because there is no code to steal.

The Gmail Connection: How the Lure Reaches You

The fake Security Checkup is a delivery technique, not a Gmail-specific bug — but Gmail is one of its primary channels for a simple reason: it is where billions of people expect legitimate Google security messages to arrive. A fake Security Checkup alert that lands in your inbox borrows the credibility of every real Google notice you have ever received.

The lures take familiar shapes. A message dressed as a "critical security alert" claims unusual sign-in activity and links to the counterfeit checkup. A fake "storage full" or "account suspended" notice routes you to the same page under the guise of resolving the problem. Malicious ads and compromised websites redirect browsers straight into the flow. In every case, the email or page itself is often just plausible text and a link — no attachment, nothing for Gmail's scanners to quarantine — because the dangerous action happens on the external page.

That structure connects the Security Checkup scam to the broader 2026 account-takeover economy. Stolen session tokens and intercepted codes power logins that skip your password entirely — the same mechanism behind Gmail session hijacking and cookie theft. The fake Security Checkup is simply one of the smoothest ways to plant the tool that harvests those secrets in the first place, and it does so while the victim believes they are improving their security.

Real Security Checkup vs the Fake: A Side-by-Side

The fastest way to stay safe is to know exactly how Google's genuine Security Checkup behaves, so any deviation stands out. The table below contrasts the two.

Behavior Real Google Security Checkup Fake Security Checkup Scam
Where it lives Inside your Google Account at myaccount.google.com/security-checkup A separate lookalike URL you were sent or redirected to
How you reach it You open it yourself from account settings An urgent alert pushes you toward it
Installation Never — it is a page inside your account Asks to "install" or "add to home screen" as an app
Permissions requested None — it only displays your existing account data Clipboard, contacts, location, notifications
Tone Calm, informational, no countdowns Alarming, urgent, "act now or lose access"
Address bar Shows google.com clearly Hidden once launched as a PWA

The single most reliable rule falls out of this table: the real Security Checkup never asks for device permissions and never asks to be installed. If a "Security Checkup" wants clipboard, contacts, location, or a home-screen icon, it is the scam.

Red Flags: How to Spot the Counterfeit Page

Beyond the install prompt, a fake Security Checkup betrays itself in several ways if you slow down for a moment. Watch for these signals:

  • It came to you. You did not open your account settings and navigate to the checkup — an alert, ad, or link pushed you there. Legitimate security tools wait for you.
  • Manufactured urgency. Countdown timers, "your account will be deleted," or "verify within 5 minutes" are pressure tactics. Google does not run doomsday clocks on your security.
  • Permission requests. Any prompt for location, contacts, clipboard, or notifications during a "checkup" is a hard stop. A checkup reads your account; it does not need your phone's sensors.
  • An install or "add to home screen" prompt. The genuine Security Checkup is a page, not an installable app. This request alone marks the page as fake.
  • A URL that is not google.com. Before any page hides its address bar, check it. If it is not a clear google.com address, close it.
  • Requests for codes or your password on the page itself. The real checkup never asks you to type your one-time code into a checkup screen.

If two or more of these appear together, treat the page as hostile and close it immediately — do not tap "cancel" inside a flow you do not trust, just close the tab or app entirely.

How to Protect Your Gmail Account

Defending against the fake Security Checkup scam is mostly about habits, backed by a few technical upgrades that make interception pointless.

  1. Only reach Security Checkup yourself. Type myaccount.google.com or open it from Gmail's settings. Never reach a "checkup" by tapping an alert, ad, or emailed link.
  2. Never install a security tool from a web prompt. Google will not ask you to add a Security Checkup to your home screen. Decline every such request.
  3. Move to passkeys or hardware keys. Because passkeys have no code to steal, they neutralize the tool's ability to intercept your second factor. See our passkeys guide for setup.
  4. Enroll high-value accounts in Advanced Protection. Google's Advanced Protection Program enforces hardware-key logins and blocks most of this attack class outright.
  5. Deny permission requests during verification. No legitimate security flow needs your clipboard, contacts, or location. Treat any such prompt as proof of a scam.
  6. Keep your browser and OS updated. Modern browsers increasingly flag deceptive PWA installs and malicious sites; updates close the gaps attackers exploit.
  7. Audit installed PWAs and permissions periodically. Review your home screen and browser site settings, and remove any app or permission you do not recognize.

These steps cost little and defeat the attack at multiple points. The single most powerful one is passkeys: even if a victim reaches the fake Security Checkup and grants every permission, an attacker with no stealable code cannot complete a login on a passkey-protected account.

What to Do If You Already Tapped It

If you completed the flow, granted permissions, or installed the app, act quickly and in order. Speed limits the damage.

  1. Remove the app or PWA immediately. Delete the icon from your home screen and revoke its permissions in your device settings — notifications, location, contacts, and clipboard access.
  2. From a different, trusted device, change your Google password. Do not use the possibly compromised device. A clean device begins invalidating stolen credentials.
  3. Sign out of all sessions. In your Google Account security settings, revoke access on all devices to kill any active sessions the attacker may hold.
  4. Run the real Security Checkup. Open it yourself at myaccount.google.com and review devices, recent security events, and third-party app access. Remove anything unfamiliar.
  5. Check for hidden forwarding rules and filters. Attackers add rules to quietly forward or delete mail. Inspect Gmail's Forwarding and Filters settings carefully.
  6. Rotate other exposed passwords. Anything you copied to your clipboard or typed during the incident should be considered compromised — prioritize email, banking, and crypto.
  7. Scan and, if needed, reset the device. Remove the malicious PWA, run a reputable mobile security scan, and reset the device if anything persists.

If you are locked out during the incident, our Gmail account recovery guide covers the emergency steps to reclaim access — and the process is markedly smoother on an established account with strong recovery options already in place.

Multi-Account and Business Risk

If you run outreach, agency work, or any operation spanning many inboxes, the fake Security Checkup scam carries an amplified risk. A single team member who taps through the flow on a shared device can expose the session tokens and codes for every account logged in through that device. One reassuring-looking "checkup" can hand an attacker a whole fleet.

That reality argues for a few operational disciplines. Isolate accounts so no single device or browser profile holds sessions for all of them — compartmentalization means one compromise cannot cascade. Standardize a clear rule across everyone who touches the accounts, including contractors and virtual assistants: never install a security tool from a prompt, and never grant permissions to a "checkup." Those team members are often the ones clicking through unfamiliar alerts under time pressure, so the rule has to be explicit.

This is one more reason established accounts outperform disposable ones for serious work. It is not that an aged account resists the initial lure any better — the tool treats every device the same. The advantage is resilience: aged accounts carry well-established recovery emails, phone numbers, and a long, consistent sign-in history that Google weighs when verifying the real owner during a dispute. If you are sourcing established Gmail accounts for business, pair that structural trust with passkeys and the habits above, and a fake Security Checkup incident becomes a contained scare rather than a catastrophe.

Frequently Asked Questions

What is the fake Security Checkup scam in simple terms?

It is a trick that impersonates Google's real Security Checkup tool. A web page copies Google's design, warns that your account is at risk, and offers to "run a checkup." Tapping the button walks you through granting permissions — clipboard, contacts, location, notifications — that turn the page into a surveillance tool. It then reads your one-time codes and copied passwords, letting an attacker into your Gmail while you believe you just secured it.

How is the fake Security Checkup different from normal phishing?

Ordinary phishing usually just tricks you into typing your password on a fake login page. The fake Security Checkup goes further: instead of only stealing a password, it installs itself as a progressive web app and requests device permissions, so it can intercept one-time codes, read your clipboard, and track your location in real time. That lets it defeat SMS and app-based two-factor authentication, which a simple phishing page cannot do.

Can the fake Security Checkup scam bypass two-factor authentication?

Yes, if your two-factor method is an SMS text or an app code. By capturing notifications and clipboard contents, the tool reads the one-time code as it arrives and passes it to the attacker, neutralizing that second factor. Passkeys and hardware security keys defeat this because they have no code to steal — the login is bound to your physical device, so there is nothing for the malicious page to intercept.

How do I tell the real Google Security Checkup from the fake one?

The real Security Checkup lives inside your account at myaccount.google.com, you open it yourself, it never asks to be installed, and it never requests permissions like clipboard or location — it only displays your existing account information. The fake version comes to you through an urgent alert, asks to be added to your home screen, and requests device permissions. If a "checkup" wants to install itself or access your phone's sensors, it is the scam.

I already tapped the fake Security Checkup and granted permissions. What now?

Act fast. Delete the app or PWA and revoke its permissions in your device settings, then use a different, trusted device to change your Google password and sign out of all sessions. Run the genuine Security Checkup yourself at myaccount.google.com, remove unknown devices and app access, and check Gmail for hidden forwarding rules or filters. Rotate any password you copied or typed during the incident, and scan or reset the affected device.

Does this scam only affect phones?

No. The progressive web app trick that hides the address bar is most effective on mobile, but the same counterfeit Security Checkup pages target desktop browsers too, where they lean on lookalike URLs and fake permission prompts. The core defense is identical on every device: only reach Security Checkup by opening it yourself from your Google account, and never grant permissions or install anything a "security" page offers you.

The fake Security Checkup scam is clever, but it has one fatal weakness: it needs you to trust a page that came to you and to tap through prompts a real Google tool would never show. Refuse to install security tools from web prompts, deny permission requests during any "checkup," reach Security Checkup only by opening it yourself, and move your accounts to passkeys — and the entire attack collapses no matter how convincing the page looks. For more on keeping your Gmail accounts secure and trusted at scale, message us on Telegram @mixgmail or explore our aged Gmail accounts built for reliable, long-term use.

Aged Gmail Account

Buy old Gmail accounts starting at just $1. Aged from 6 months to 15 years. Instant delivery via Telegram.


From $1 per account
In Stock ⚡ Instant Delivery
Order on Telegram Chat on WhatsApp