Gmail's Security Hole Could Lead to Mass Harvesting of Accounts
technologyreview.com
technologyreview.com
The different sources of the SMS may not cause alarm. The victim may not go back to original message to verify the numbers. Many companies have multiple legitimate phone numbers. The phisher may try to find phone numbers that are variations of Google's so the user is less likely to notice.
The phishing page could be secure in the sense of having SSL and looking professional. I haven't use Google's SMS verification, but I'm hoping that the text they send raises red flags about only entering the code in Google's web site. If not, e.g. if it's just the code, I could very easily see a victim entering the code into a legimate site. If Google's SMS does have warnings, the attacker could get a domain like https://gmailgiftcardverification.com that may still get some victims to enter the verification code.
I think this is more dangerous than page directly phishing for a google password. Users are conditioned to look for google.com and a green address bar before revealing their password. On the other hand, SMS verification is relatively new, and users may be less familiar with what to expect regarding the format and origins of the text messages.