Suspicious

Phishings targeting Gemini

Suspicious and active websites


Phishings targeting Gemini

Suspicious and active websites


About
AIGoogle's AI assistant accessed via the standard Google account. Phishing pages typically funnel into broader Google account takeover (Gmail, Drive, Workspace) since auth is shared with the main Google login.

Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) URL Screenshot Flags Details

Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.

URL Screenshot Details

AIHow to verify a real Gemini URL

  • Legitimate Gemini URLs always end in gemini.google.com (e.g. www.gemini.google.com, account.gemini.google.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not Gemini.
  • The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
  • If you got the link from email, SMS, or social media, do not click it. Open gemini.google.com from your browser bookmark or type the domain manually.
  • Real Gemini pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.