A Google fraudulent account surfaced inside the company’s Law Enforcement Request System (LERS). The portal processes sensitive law enforcement data requests. Google confirmed the account but stated no user data was stolen.

How the Incident Unfolded

A malicious actor created a fake account inside the LERS system. Google detected the account and shut it down quickly. Hackers using the name “Scattered Lapsus$ Hunters” later claimed responsibility. They also bragged about breaching the FBI’s eCheck system, but those claims remain unverified.

Who Claimed the Attack

The “Scattered Lapsus$ Hunters” group links itself to Shiny Hunters, Scattered Spider, and Lapsus$. These groups have histories of high-profile attacks. On Telegram, the group shared screenshots to support its claims.

Why the Breach Matters

Attackers can abuse weak verification systems to impersonate law enforcement agencies. If successful, they could submit fake subpoenas and gain user data. Even though no requests were made, the case highlights serious weaknesses.

Google’s Response

Google confirmed the fraudulent account, disabled it, and reviewed its security processes. The company emphasized that the fake account never accessed data. By acting fast, Google prevented further misuse.

Lessons for Security

  • Organizations must verify users strictly before granting access to sensitive portals.
  • Regular monitoring can detect suspicious accounts earlier.
  • Collaboration between tech firms and law enforcement strengthens overall defenses.

Conclusion

The Google fraudulent account case underscores how attackers exploit verification gaps. Google stopped the attempt, but the warning is clear. Sensitive systems need stronger identity checks and constant monitoring to block future threats.


0 responses to “Google Fraudulent Account Found in Law Enforcement Portal”