Gmail’s encrypted email push: security boost or phishing nightmare?

Google says it’s making it easier than ever for businesses to send fully encrypted emails. But there are fears that Gmail’s encrypted email system could be exploited by phishing attacks.

The new system will allow enterprise users of Gmail to send end-to-end encrypted (E2EE) messages to any recipient, whether they’re inside your own organisation or external.

Google Workspace currently uses the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol to encrypt messages. That requires IT teams at both ends of the chain to manage certificates and deploy them to users, but most organisations simply don’t implement it. Which means the vast bulk of messages are sent unencrypted.

The company has developed a neat workaround that makes the process much easier to deploy, using client-side encryption. Under the new system, if the recipient is a Gmail user (either enterprise or personal), the email is automatically decrypted, and they can reply with encryption switched on.

However, if the recipient isn’t a Gmail user, they will receive an invitation to view the email in a “restricted version of Gmail”. According to Google, the “recipient can then use a guest Google Workspace account to securely view and reply to the email”, as shown below.

Gmail encrypted email
Here’s what non-Gmail users will see when sent an encrypted email (image: Google)

Encrypted Gmail: business advantage

Google claims this approach has several benefits for businesses.

For example, IT teams will “have the option to require all external recipients (even if they are Gmail users) to use the restricted version of Gmail,” the company stated in a blog post announcing the new feature. “This helps ensure that their organisation’s data does not end up stored on third-party servers and devices.”

Google added: “It also makes it easier for organisations to protect their data by having the ability to apply security policies and revoke access to emails, no matter how long ago they were sent.

“Essentially, the E2EE email becomes like a document in Google Drive, allowing the IT team to control its access.” 

Phishing fears

The concern with Google’s new system is that it will become a target for phishing attacks, with fraudsters generating similar-looking emails that encourage victims to click through and enter their credentials.

Google is alive to this threat, with a warning message appearing when users click on the View Message link reading: “Be careful when signing in to view this encrypted message” and warning recipients to “make sure you trust the sender and their identity provider before entering your username and password”.

Google says it has also developed a new threat protection model using (yep, you guessed it) AI, which “evaluates thousands of combined signals from billions of endpoints based on the actor, behaviour, and content to catch more spam and phishing before they reach users”.

Although that won’t offer any protection to users who aren’t using Gmail.

The new system is now available in beta, but currently only supports sending encrypted email within your own organisation. The ability to send encrypted emails to any Gmail inbox will arrive in the “coming weeks”, with the option to send to any email inbox arriving “later this year”.

Avatar photo
Barry Collins

Barry has 25 years of experience working on national newspapers, websites and magazines. He was editor of PC Pro and is co-editor and co-owner of BigTechQuestion.com. He has published a number of articles on TechFinitive covering data, innovation and cybersecurity.