In June 2026, Google published one of its most urgent fraud and scams advisories ever — pegging global fraud losses at a staggering $580 billion for 2025, with roughly one in five adults hit. Buried inside that report was a warning aimed squarely at the inbox: three new Gmail scams are bypassing the defenses that protected users for years, including two-factor authentication itself. These aren't the clumsy "Nigerian prince" emails of the past. They are AI-assisted, professionally built, and engineered to look like the legitimate Google services you trust every day.
This guide breaks down each of the three threats Google named, shows you the exact warning signs to memorize, and gives you a concrete checklist to lock down your account. Whether you run a single personal inbox or manage dozens of aged Gmail accounts for outreach, understanding the 2026 Gmail scams landscape is now a basic survival skill.
Inside Google's June 2026 Scam Advisory
Google releases periodic fraud advisories to warn its roughly two billion Gmail users about emerging attack patterns. The June 2026 edition stood out because of its scale and its focus. Instead of generic "watch out for phishing" language, Google named specific, named techniques that its own threat teams were watching spread in the wild — and admitted that several of them defeat the multi-factor authentication most people assume keeps them safe.
The headline numbers were sobering. Global fraud losses reached an estimated $580 billion in 2025. Security researchers tracked a 1,210% jump in AI-assisted fraud tooling year over year, and in controlled studies roughly 60% of participants fell for AI-generated phishing messages — about the same success rate as messages hand-crafted by skilled human attackers. The takeaway is simple: the volume, polish, and personalization of modern Gmail scams have all climbed at once.
Three techniques were called out as directly targeting Gmail and Google account users: Adversary-in-the-Middle (AiTM) phishing, calendar invite phishing, and ClickFix fake update lures. Each one attacks a different layer of your trust — your login, your schedule, and your habit of clicking "update now." We'll examine all three in detail.
Why Gmail Scams Got More Dangerous in 2026
For most of email's history, the weakest link in a phishing attack was the attacker's writing. Spelling mistakes, broken grammar, and awkward phrasing gave scams away. Generative AI erased that tell. A scammer can now produce a flawless, perfectly localized email — or an entire cloned login page — in seconds, then personalize it with details scraped from a data breach.
Three forces converged to make 2026 a breakout year for Gmail scams:
- AI-generated content — Phishing emails, fake support pages, and even voice calls (vishing) are now produced at scale with no language errors to expose them.
- Phishing-as-a-Service (PhaaS) kits — Ready-made toolkits like the Tycoon family let low-skill criminals launch sophisticated AiTM campaigns for a monthly subscription fee.
- Massive credential leaks — In one 2026 incident, roughly 48 million Gmail logins surfaced inside a 96 GB exposed database bundling credentials from many services. Leaked passwords feed targeted, personalized attacks.
The result is that the old advice — "look for typos, don't click strange links" — is no longer enough. The new Gmail scams are clean, contextual, and designed to walk you through steps that feel completely normal. That's exactly why Google had to name them.
Threat 1: Adversary-in-the-Middle (AiTM) Phishing
Adversary-in-the-Middle is the most technically dangerous of the three Gmail scams because it defeats two-factor authentication — the protection most people rely on as their last line of defense.
Here's how an AiTM attack works. You receive an email that looks like it's from Google, your bank, or a shared-document notification. You click the link and land on a login page that looks identical to the real one. But this page is a malicious proxy sitting between you and the genuine service. When you type your password, the proxy relays it to the real site in real time. When the real site asks for your 2FA code, the proxy passes that prompt to you, you enter the code, and the proxy forwards it too. You log in successfully — everything "works."
The catch: while you complete the genuine two-step prompt yourself, the attacker silently captures the session cookie that the real service hands back after login. That cookie is what keeps you logged in. With it, the attacker walks through the door behind you and stays authenticated on their own machine — no password or 2FA code needed again. This is why AiTM is sometimes described as "MFA bypass": it doesn't break your second factor, it steals the result of it.
Why it's so effective: there is nothing visually wrong. The login flow behaves normally, the 2FA prompt is real, and the only sign of trouble is the URL — which AiTM kits disguise with look-alike domains and redirect chains. Once an attacker has your session, they can read your mail, reset other account passwords, and pivot to your contacts. If your account is hijacked this way, our guide to recovering a Gmail account walks through the emergency steps.
Threat 2: Calendar Invite Phishing
The second of the named Gmail scams is clever because it skips your inbox entirely. Calendar invite phishing abuses the way Google Calendar can automatically add events from incoming invitations.
An attacker sends a calendar invite — often delivered as an .ics file — carrying a fake "subscription renewal," "payment failed," or "security review required" notice. Because many calendars are set to add invitations automatically, the event simply appears on your schedule, complete with a reminder notification. The psychological trick is powerful: a calendar entry feels like something you created or agreed to, not something a stranger pushed at you. When the reminder fires, it carries a link to a phishing form, and you're far more likely to trust it.
This vector works for a structural reason: the .ics format has not traditionally been treated as a threat by email security platforms, so these invites often sail past filters that would catch a normal phishing email. Attackers also pair calendar invites with QR codes ("scan to confirm your meeting"), pushing you onto your phone — a device with less security tooling — to complete the AiTM flow described above.
The good news: this one has a simple structural fix. Google recommends turning off automatic event creation from invitations so that only events you explicitly accept ever appear on your calendar. We cover the exact setting in the protection section below.
Threat 3: ClickFix Fake Update Lures
ClickFix is the newest and fastest-growing of the three Gmail scams, and it weaponizes your instinct to fix a small problem. It's a malware lure disguised as a routine maintenance step.
The attack usually starts with an email link that leads to a convincing page — frequently hosted on a legitimate-looking Google Sites or cloud-document address to dodge reputation filters. The page tells you that a browser update, a CAPTCHA verification, or a "human check" is required, then instructs you to copy and paste a command into a system dialog, or to run a small download. The "fix" is the infection. The pasted command quietly installs an infostealer that harvests passwords, cookies, and crypto wallets straight off your machine.
Throughout 2026, ClickFix campaigns expanded rapidly with new malware loaders and fresh disguises — fake Windows updates, fake macOS utilities, and fake document-verification prompts. Because the victim performs the installation themselves, antivirus software and email filters frequently miss it.
The defense is a single, memorable rule: no legitimate website ever asks you to paste a command into your terminal, the Windows Run box, or any system setting to "verify" yourself. If a verification step tells you to leave your browser and run something, it is not a CAPTCHA — it's a ClickFix attack. Close the tab.
The Three Threats at a Glance
Here's how the three Gmail scams from Google's June 2026 advisory compare across what they target and how to stop them:
| Threat | What It Targets | Key Tell | Primary Defense |
|---|---|---|---|
| AiTM Phishing | Your login session (steals cookies, bypasses 2FA) | Login URL is a look-alike domain | Passkeys + Advanced Protection |
| Calendar Invite Phishing | Your schedule and your trust | Event you never accepted appears | Disable auto-add of invites |
| ClickFix Fake Updates | Your device (installs infostealer malware) | Asked to paste a command or "verify" outside the browser | Never run pasted commands |
Notice the pattern: each of these Gmail scams asks you to do something that feels small and routine — log in, glance at an event, complete a verification. The danger is hidden inside an ordinary-looking action, which is exactly what makes them so much harder to spot than classic spam.
Warning Signs Every Gmail User Should Memorize
Because the new Gmail scams are visually polished, you can't rely on spotting bad grammar anymore. Instead, train yourself to react to behavioral red flags — the things a legitimate service would never ask you to do:
- Urgency and consequences — "Your account will be suspended in 24 hours," "payment failed, act now." Real providers rarely impose panic deadlines.
- A login page reached by clicking an email link — Always navigate to
mail.google.comyourself instead of clicking through. AiTM lives in that click. - Any instruction to paste a command or open a system dialog — The signature move of ClickFix. There is no legitimate version of this.
- Calendar events you don't remember accepting — Especially ones about money, security, or deliveries.
- QR codes in emails — "Scan to verify" pushes you to a less-protected phone. Treat QR codes in unsolicited messages as hostile.
- Look-alike domains —
google-secure.com,gmail-support.net, and similar are never Google. The real domain isgoogle.com. - Requests for your 2FA code by phone or chat — Google will never call and ask you to read out a code.
If even one of these flags appears, stop and verify through a channel you trust. Many of these same instincts overlap with the broader habits in our Gmail account security tips guide — worth reviewing alongside this advisory.
How to Protect Your Gmail Account in 2026
Knowing the threats is half the battle; the other half is hardening your account so that even a successful phishing attempt fails. Here is a prioritized checklist that directly counters all three Gmail scams Google named.
1. Switch to passkeys (the single biggest upgrade). Passkeys are phishing-resistant by design. Because they're cryptographically bound to the real Google domain, a passkey simply won't authenticate on an AiTM proxy page — the look-alike domain doesn't match, so login fails. This neutralizes the most dangerous of the three threats at the source.
2. Enroll high-value accounts in Google Advanced Protection. Advanced Protection enforces hardware-backed sign-in and blocks the cookie theft that powers AiTM attacks. Google is also rolling out Device Bound Session Credentials, which tie a session cookie to the device that created it — so a stolen token is worthless on the attacker's machine.
3. Turn off automatic calendar invites. In Google Calendar settings, open Event settings and set "Add invitations to my calendar" to "Only if the sender is known" (or "When I respond to the invitation in email"). This single toggle defeats calendar invite phishing by ensuring nothing lands on your schedule without your say-so.
4. Adopt one unbreakable rule against ClickFix. Never paste a command, open the Run box, or run a downloaded "verification" tool because a web page told you to. Bookmark this rule mentally: CAPTCHAs happen inside the browser, never outside it.
5. Use a password manager with domain matching. A good password manager autofills credentials only on the exact domain it saved them for. If it refuses to autofill on a "Google" login page, that's a loud signal the page is fake.
6. Run a Security Checkup quarterly. Visit your Google Account's Security Checkup to review connected devices, third-party app access, and recovery options. Revoke anything you don't recognize. If you ever find yourself locked out or flagged, our guides on fixing a suspended Gmail account and recovering access are a useful next step.
7. Keep recovery information current. An up-to-date recovery phone and email dramatically speed up regaining control if an account is compromised — and they make automated trust signals stronger, which also helps your long-term deliverability and account standing.
What These Gmail Scams Mean for Businesses
For solo users, the new Gmail scams are a personal risk. For businesses, marketers, and anyone running outreach across multiple inboxes, they're an operational one. A single hijacked sending account can poison an entire campaign, burn your sender reputation, and expose your contact list.
Consider the compounding damage of an AiTM compromise on a business inbox:
- Outbound spam from a trusted address — Attackers use the hijacked account to send phishing to your real contacts, who trust you. Your domain reputation tanks.
- Account suspension — Google may disable an account showing compromised behavior, instantly halting any campaign running through it.
- Data exposure — CRM exports, client lists, and saved drafts all sit inside that inbox.
The defensive playbook for teams adds a few layers on top of the personal checklist: enforce passkeys or hardware keys organization-wide, segment accounts so one breach can't cascade, train staff to recognize calendar and ClickFix lures specifically, and monitor for unusual sign-in locations. If you operate at volume, treat each account's security posture the way you'd treat its warm-up schedule — as a deliberate, maintained process, not a one-time setup.
It's also worth noting that strong account hygiene and good deliverability reinforce each other. Accounts with clean security histories, consistent sign-ins, and no compromise events are exactly the accounts Gmail's systems trust most — the same trust signals that keep your legitimate mail out of the spam folder.
Account Age, Trust, and Scam Resistance
One question we hear often: do older, established Gmail accounts hold up better against the 2026 Gmail scams? The honest answer is nuanced. Account age does not make you immune to phishing — an AiTM proxy will steal a 10-year-old account's session cookie just as easily as a brand-new one's. Security behavior, not age, stops the initial compromise.
Where account age does matter is in resilience and recovery:
- Stronger recovery options — Aged accounts typically have well-established recovery emails, phone numbers, and a long sign-in history that Google uses to verify the real owner during a recovery dispute.
- Better anomaly detection — A long, consistent history of normal behavior makes sudden malicious activity stand out more clearly to Google's systems, which can trigger protective challenges sooner.
- Reputation cushion — An aged account with years of clean sending is less likely to be permanently blacklisted after a single incident than a fresh account with no track record.
This is part of why aged accounts outperform new ones for serious email work — not because they can't be phished, but because they're built on a deeper foundation of trust that's harder to erase. If you're sourcing established Gmail accounts for business, pair that age advantage with the security hardening above, and you get the best of both: a trusted account that's also genuinely difficult to hijack. The 2026 threat landscape rewards exactly that combination of structural trust and disciplined security hygiene.
Want help choosing secure, well-aged Gmail accounts for your outreach? Browse our accounts or reach us on Telegram for guidance tailored to your use case.
Frequently Asked Questions
What are the three Gmail scams in Google's June 2026 advisory?
Google named Adversary-in-the-Middle (AiTM) phishing, calendar invite phishing, and ClickFix fake update lures. AiTM steals your login session and bypasses two-factor authentication; calendar phishing slips fake events onto your schedule; and ClickFix tricks you into pasting a command that installs malware. All three are designed to look like routine, trustworthy actions rather than obvious spam.
Can these Gmail scams really bypass two-factor authentication?
Yes. AiTM phishing doesn't break your 2FA — it sits between you and the real login page, lets you complete the genuine two-step prompt yourself, and silently steals the session cookie that keeps you logged in afterward. With that cookie, the attacker stays authenticated without ever needing your password or code again. The strongest defense is switching to passkeys, which are cryptographically bound to the real Google domain and won't work on a fake page.
How do I stop fake calendar invites from appearing in Gmail?
Open Google Calendar settings, go to Event settings, and change "Add invitations to my calendar" to "Only if the sender is known" or "When I respond to the invitation in email." This prevents strangers' invites from auto-adding to your schedule. You can also report a malicious invite directly from the event, which helps Google block the sender for everyone.
What is a ClickFix attack and how do I avoid it?
ClickFix is a scam that disguises malware as a routine fix — a page claims you need a browser update or CAPTCHA verification and tells you to copy and paste a command or run a download. The command installs an infostealer. The rule that defeats it is simple: no legitimate site ever asks you to paste a command into your terminal or system settings to "verify" yourself. If a verification step tells you to leave your browser, close the tab immediately.
Are older Gmail accounts safer from these 2026 scams?
Account age doesn't prevent the initial phishing — an AiTM attack works the same on old and new accounts. However, aged accounts recover better because they have established recovery options, a long sign-in history Google can verify against, and a reputation cushion that makes a one-time incident less catastrophic. Security behavior stops the attack; account age helps you survive and recover from one.
What should I do if I think my Gmail account was compromised?
Act fast. Change your password from a device you trust, sign out of all sessions, run Google's Security Checkup to revoke unknown devices and app access, and re-enable or upgrade your 2FA to passkeys. Then review forwarding rules and filters, since attackers often add hidden ones. Our Gmail recovery guide walks through every step, and the suspended-account guide covers what to do if Google locks the account during the incident.
Will Google ever ask for my password or 2FA code by phone or email?
No. Google will never call, email, or message you asking for your password, your two-factor code, or to paste a command somewhere. Any message that does is a scam, full stop. When in doubt, ignore the message and navigate directly to your Google Account security page yourself rather than clicking any link you were sent.
The 2026 Gmail scams are sophisticated, but they all rely on one thing: catching you in a moment of routine, trusting action. Slow down at login pages, lock down your calendar, never run pasted commands, and upgrade to passkeys — and you defeat all three. For more on keeping your accounts secure and trusted at scale, message us on Telegram @mixgmail or explore our aged Gmail accounts built for reliable, long-term use.