A new phishing email is circulating that masquerades as a missed voicemail alert. Clicking the message can hand your Google password directly to attackers. What makes this scam especially dangerous is that it avoids the obvious red flags—there’s no suspicious attachment or blatantly malicious link—so it’s much easier to miss.
Anyone who uses Gmail or another Google account should be alert for this kind of message. At a glance it looks legitimate—the kind of notification most people would click without thinking. That apparent normalcy is intentional: scammers want recipients to trust the email and follow the prompt without taking a closer look.
Security researcher Anurag discovered this scam and shared details with Cyber Security News. The email arrives with the subject line “New Audio MSG,” imitating a missed voicemail notification and including a prominent “Play Audio” button. Instead of playing audio, the button directs victims through a chain of links that appear legitimate. That redirect sequence ultimately lands on a convincing fake Google sign-in page designed to capture your password.
Why this one is harder to spot
Most phishing attempts are detected because they include an obvious attachment or an obvious malicious link—elements people have been trained to distrust. This scam is different: it routes through trusted cloud services and legitimate-looking URLs, which allows it to bypass many email filters. The deceptive login page can even show the victim’s email address pre-filled, a subtle detail that makes the fake page feel authentic and increases the chances someone will enter their password.
If an attacker obtains your Google password, the consequences go far beyond a single email account. Your Google credentials often provide access to Gmail, Google Drive, Google Calendar, contacts, photos, and any other services tied to your Google identity. Additionally, any third-party accounts you sign in to with Google could be compromised. That broad access makes a stolen Google password particularly valuable to scammers.
This technique is not entirely new. Last year, scammers used a different phishing approach that also slipped past Gmail’s filters by exploiting the way Google formats certain security messages. A compromised work account can be especially dangerous because attackers can then send believable phishing emails to colleagues, increasing the likelihood of additional compromises within an organization.
If you receive an email claiming you have a new voicemail or audio message, avoid clicking any buttons or links inside the message. Instead, open Gmail, Google Voice, or your phone carrier’s voicemail system directly in a browser or app to check for real messages. If you have already clicked a suspicious login page and entered your password, change your password immediately—but do so by typing the service’s address into your browser yourself, not by following a link from the suspicious email.
To protect yourself further: enable two-factor authentication (2FA) on your Google account, use a strong, unique password that you don’t reuse across sites, and consider a password manager to generate and store secure credentials. Regularly review account activity and connected apps in your Google account settings, and remove any unfamiliar devices or app permissions. These practices reduce the chances that a single mistake will lead to a wider compromise.
In short, treat unexpected voicemail emails with skepticism. When a message looks routine but asks you to sign in or play an audio file, pause and verify the notification through official channels. Small extra steps can prevent a significant security breach and keep your Google account and associated services safe.