Google’s latest push to bring end-to-end encryption to Gmail has drawn praise for improving email security—but experts are sounding the alarm that it may also open a dangerous new avenue for phishing attacks. As reported by Wired, the feature, currently in beta for enterprise Google Workspace users, allows organizations to send encrypted emails that can be accessed even by non-Gmail users. And that, researchers say, is where the risks begin.
The tool, which aims to simplify a notoriously complex process, lets Workspace users send secure emails via a restricted Gmail viewer to recipients outside of Google’s ecosystem. These recipients are prompted to view messages using a guest Google account—a workflow that, while streamlined, could be easily mimicked by scammers.
“This new invitation system creates a perfect phishing template,” said Jérôme Segura, senior director of threat intelligence at Malwarebytes. “Non-Gmail users may not recognize what a legitimate encrypted email invitation from Google looks like, and could easily fall for fakes that steal their login credentials.”
End-to-end encryption ensures that only the sender and recipient can read a message, with data remaining encrypted throughout its journey. However, Gmail’s version isn’t true end-to-end encryption in the strictest sense. The encryption keys are managed centrally by the sender’s Workspace environment, rather than stored locally by the user. Still, Wired notes that for compliance-heavy industries like finance or healthcare, the solution may strike the right balance between security and usability.
Security researchers warn that phishing attacks exploiting the new feature could resemble longstanding scams using fake Google Docs or Drive sharing invitations. Although Gmail’s internal spam and fraud detection systems will be active for Gmail users receiving these messages, the broader rollout means anyone with an email address—including users on Outlook, Yahoo, and other platforms—could be targeted.
Google is aware of the risks. “We built this particular technology with this risk in mind,” said Google spokesperson Ross Richendrfer. He emphasized that the warnings included in encrypted email invitations—such as prompts to verify the sender’s identity—mirror familiar Google Drive alerts and are backed by existing anti-phishing mechanisms.
Despite these safeguards, the effectiveness of those protections remains limited outside Google’s walled garden. “It’s almost as if someone at Google knew this was a bad idea and asked for a warning to be added,” Segura told Wired. “But the truth is, scammers will absolutely exploit this.”
As more Google Workspace users begin sending encrypted emails to external recipients, security professionals urge caution. “End-to-end encryption is a powerful tool,” Segura added, “but when it’s implemented in a way that encourages unfamiliar workflows, it becomes bait for social engineering.”

