Report: Looker Studio abused for phishing emails

Hello there! I wasn't really sure where to post this, but maybe this community could be able to provide me some assistance.

Beginning November 1, 2024 my personal Gmail account began receiving emails from "looker-studio-noreply@google.com" with subject lines: "🎉 Congratulations! You're Invited to Join Our Exclusive Adult Community! 🎉 - Nov 3, 2024" (or the date I received it). They passed by spam filters and made it to my inbox. The senders as parsed by my mail client show "FirstName LastName (via Looker Studio)", but the reply to email is always "differentfirst.differentlast@domain.domain.domain". I am not using the actual names and domains to prevent any privacy issues.

The content of the email is an Looker Studio scheduled report sent by Google on behalf of some name, always for an "Untitled Report" with some description of a scummy adult website or community, even sometimes with an "invite link". This Untitled_Report.pdf is attached, though I have never dared to open any of them. The bottom of the email contains the usual Looker Studio footer, including the link to unsubscribe from the scheduled email that uses the official optout token. I attempted to just unsubscribe and block the sender using this method, but there are so many now (28 in less than 72 hours) and I gave up. My next step will probably just be a filter that catches any Looker Studio emails and treats them as malicious.

I have not fallen victim to phishing or the links - I did not click any of them except the official Looker Studio optout. I would first of all like to make the community aware that this is being abused by malicious actors. Secondly, as someone who has never used Looker Studio for personal or business reasons, is there any way that I can add my email to a blacklist so that others cannot subscribe me to their reports? They seem to only need my email (which is likely available in any number of breaches). I feel like a complete optout or the requirement that an email have used Looker Studio should be a feature to prevent this misuse of the system against vulnerable individuals who do not catch that the official Google email is from a 3rd party. Seems like this was used in the past for other phishing attempts (2023: (URL Removed by Staff), 2023: (URL Removed by Staff) 2023: (URL Removed by Staff)

Any help would be great, and I can provide more details if that is not in violation of the community guidelines and would prove helpful to improving the product. Thank you!

Solved Solved
8 61 9,857
1 ACCEPTED SOLUTION

Hi @ian-rybak, thanks for letting us know - I will report this to my colleagues. In the meantime, it seems the best course of action is to filter the emails, as you mentioned, and report them as spam.

View solution in original post

61 REPLIES 61

There have been a few requests for Google to help deal with this, ranging back to late 2023. There has been no response from Google so far. Thankfully my work and personal GMail accounts now filter all LookerStudio mail to the spam folder by default. It only took a handful of spam reports on each.

Hi @ian-rybak, thanks for letting us know - I will report this to my colleagues. In the meantime, it seems the best course of action is to filter the emails, as you mentioned, and report them as spam.

Hi @Michelle, how do I find my "pending" posts? I was directed to "My Unmoderated Items" once, but now I cannot get back to that page. Any direction? Thx!

While filtering does move the spam to trash. The real issue is the misuse of a great product. I'm having the same problem and the spam has escalated, seeing 40 + from Looker-Studio per day, all spam, all trash. 

Hey @Lobo-Google and @JenS  , are you aware how can I fix Couldn’t send scheduled email. I saw so many people are having this issue but no one found the right answer or fix. I am getting always error message from "data-studio-noreply@google.com" Data Studio encountered an error running this report and was unable to send scheduled email to recipients. View the report in your browser to troubleshoot the error. Event there is no way for troubleshooting. or is this schedule email only available for looker studio pro? 

I need to send the reports to the stackholder but with this way I can't. All the emails form google are in white list, still collecting error message. 

I am glad to hear this. This makes it sound like Google temporarily broke the feature which people are abusing while they work on improving it to protect it from abuse. We are sorry that you are affected by this @tota  as it sounds like you are a legitimate user (or maybe you are one of the people abusing the service?). But any service which allows you to send emails to people who have not opted in will eventually be abused in this way. Hopefully Google will redesign the feature so that your use case can be supported again soon, but, IMO, stopping the spam is more important.

This should not be marked as "Solved." It's an open issue while Google's own service is a source of spam.

Filters on Google don't work. Looker refuse to stop emailing me,  5000 and counting. That's a fine of $51,500 per email by the FT  TO GOOGLE! NO IMMUNITY HERE. LOOKER IS A DATA SITE NOT ■■■ OR ADULT ■■■■. FRICKEN STOP IDIOTS. MAYBE FBI WILL STOP U

It's been 9 months now and people are still receiving these phishing emails. How long is it going to take to shut this down, or does some foreign government need to impose a fine big enough to make it hurt?

Went away after I had reported on here a second time now it has come back. Will this ever be fully removed. I just do not understand the need to push this crap in people’s in boxes. Just rediculous that still dealing with something like this after months of it repeatedly asking for an actual resolution.

look like it didn't worked, as spam still coming

I have the same issue ,I have never used studio locker , it seems like Google like this kind of misuse of services   there is no way to atom them attacking 

How do I get the hell OUT of Looker completely? Not only do I not remember joining but I can't find any way to remove myself from this horrible spam machine.

Google, you are full of it. The Looker Studios spam is not solved, you did slow it down for a bit, but it is back in full force. Received 17 spam emails today. Some of the smartest folks but cannot figure out a way to stop the misuse of what you create or is it you just don't care.

Yesterday, I received 22 spam emails, ALL marked as PHISHING and
reported to SPAMCOP.
And I'm not even a user of the service.
This affects those who really use it seriously, but if Google doesn't
care, I don't care either.

These spammers taking advantage of Googles services, like whatever this Looker nonsense is, and Groups would not be a problem, if users emails weren't publicly listed. Same for all the other spammers trying to advertise new roofs, cheap medicine, and anything else people are getting sick of seeing in their email. Frankly I'm gods damned sick of people having access to my email address, that I haven't granted permission to have.

Not to mention forcing all of these features and services on folks that don't want, or need them, just makes things worse. Ninety-five percent off anything Google offers, I can honestly, and prefer to do without. Especially when it comes to my phone, all the apps are a waste of valuable space. Android phones have gotten worser and worser since Google has dug it's talons in the OS. Maps, Youtube, Drive, and the Play Store is all I really want, or need on my phone.

Google filters don't work, it is supposed to stop from receiving them. Google thinks they are immune

Even worse than Gmail filters not working, so-called "blocking" an email address does no such thing. Instead of BLOCKING the sender (and bouncing their email back to them as undeliverable), Gmail instead reroutes blocked email to the Junk folder. That is NOT "blocking", it is filtering. Google needs to look up the meaning of "block'.

@ian-rybak Please use the Report Content on Google form to report this. Thank you for your help. 

Hi @JenS, I tried that form, but there is no way to submit a report on there. The only "Non-Legal" option to submit one is for "Child sexual abuse material". 

The report page definitely needs review for more appropriate options or narrow the scope for a brief description.  It is too narrow scope...

That “Report Content on Google” form only allows reporting cp. Please provide the correct form for reporting abuse of the reporting tools. The email I received from Google was solicitation and dating website links with explicit language—not cp.

I see this text at the bottom of my email:

You received this email because someone scheduled it to be sent to you regularly. You can unsubscribe from this scheduled email here .

I will try the unsubscribe button. Hopefully that indirectly flags to Google that the account is spam, but it doesn’t give me that impression. That same footer should at the very least include a “report spam” button.

In fact, report email subscriptions should require the recipient to opt-in after following a link sent to them personally by the report creator. Google should never send arbitrary user content on the behalf of a report creator prior to the recipient opting in and specifically requesting to be subscribed to the report. I understand that if an organization is actually using these tools for something other than sending spam, it might be more convenient to be able to mark an account as “friend” or “trusted and allowed to subscribe me to any report they want”. But I think it is more important to stop spam than to make it convenient for legitimate users to use.

Thanks.

That is not helpful.  The Report Content on Google options are extremely limited and appear designed to frustrate users from attempting to provide information.  There is no clear way to simply report the EXCESSIVE SMUT coming from "looker-studio-noreply@google.com" and the only real option is to select "Child sexual abuse material" which is innacurate for this and takes one to a more governmental abuse area - not Google.  How do we provide details like this to Google - one of dozens of examples.  I have blocked out some of the words for language. 

BrianWMarine_0-1732045662160.png

 

 

 

Thank you guys for the help. I will proceed with the posted suggestions. All the best!

Hello, I know it's been a few days since this topic started but today was the first day me and my team received some of our daily scheduled reports as a Spam. Not all of them went to spam, not all of us got them in spam folder either, completely randomly it seems to be the case. This is the first day in a very long time something ended in spam. Is this related to the phishing scam as mentioned above and what's the quickest solution to my problem? Thank you

@Lobo-Google @JenS can you help me out with this please? It's been going on for a few days now?

@mvincic Please use the Report Content on Google form to report this. Thank you.

Hi Jen, thanks for the reply. Just to be sure we understand each other. Link you provided allows me to submit report with Legal or Non-Legal reasons...Just want to make sure I'm filling the correct form.

The reports I initially talked about are mine, me and my colleagues are now receiving them as spam instead of going to Inbox as before. 

I didn't see an option to submit something about report not working properly?

Thank you once again

@mvincic  This is exactly what should happen when a service like this is abused. The service’s email gets reported by spam by everyone and even legitimate users are affected. This can only be fixed if Google changes the way the scheduled report emails work to be opt-in so that only legitimate users are receiving the email in the first place.

Hello, 
We meet the same issue as @mvincic, starting from friday 08.11.2024 some of are scheduled report's become spam in gmail of our business users, how can we fix it? Or should we just wait ? 

Hey @Lobo-Google and @JenS  , are you aware how can I fix Couldn’t send scheduled email. I saw so many people are having this issue but no one found the right answer or fix. I am getting always error message from "data-studio-noreply@google.com" Data Studio encountered an error running this report and was unable to send scheduled email to recipients. View the report in your browser to troubleshoot the error. Event there is no way for troubleshooting. or is this schedule email only available for looker studio pro? 

I need to send the reports to the stackholders but with this way I can't. All the emails form google are in white list, still collecting error message. 

@mvincic and @akyrychenko, I created a new comment thread,  Scheduled emails are going to recipient's spam folder, to address this issue, as it is distinct from the original topic of this comment thread.

It is ridiculous to be receiving 50+ pornographic spam emails PER DAY from Looker Studio addresses. Google is responsible because they are sitting idly while this abuse continues to happen. If not resolved soon, I will be switching to a different email provider. This is absolutely ridiculous and intolerable.

I agree with Starbase comment above “

It is ridiculous to be receiving 50+ pornographic spam emails PER DAY from Looker Studio addresses. Google is responsible because they are sitting idly while this abuse continues to happen. If not resolved soon, I will be switching to a different email provider. This is absolutely ridiculous and intolerable.”

The issue of inviting people to have sex through the pornographic spam emails (via Looker Studio) needs to stop. It is inappropriate and completely unacceptable.

i have been looking at threads for a solution on this since 10/27/2024. From a technology perspective in a BA, PM, User Acceptance Tester, and Quality Assurance perspective … it seems like this would definitely have been prioritized by now. All the time techs are spending answering these threads rather than fixing the problem seems to be a waste of time all together. When you could actually have prioritized, corrected, tested and updated with correction rather than spending the time just responding with no solutions to each of these people’s reports since, some going back all the way to 2023 and now here we are still with same issue, never solved originally, it appears.

 
 

Completely agree this is ridiculous, getting close to 100 per day and all just filling up my trash folder, to be spammed by a service and to have no ability to stop it other than write a rule. I mean this service has no sign up or subscribe so any spammer who has an email can just blast away. Even looking at the headers, you cannot identify the individual who sent the mail. A service should have an opt out feature and allow feature. 

Can you just put a deny on the service side to stop emails to those of us who want to opt out. 

Updates? Google? Are you going to do something or….? Switching email providers if not 🤷‍♂️

We are investigating. Can someone provide the report ID of a report that was sent as a scheduled email? 

The one spam email I got I think has a report ID of 52af0e84-01e9-4338-9c57-de1c44e9c495.

There is no report ID as far as I can tell…

the report is empty as was described above in other comments.

IMG_5751.jpeg