Gmail users are warned of a phishing scam targeting their passwords, where fake emails mimic legitimate Google communications, urging users to follow links that could lock them out of their accounts. The warning follows a sophisticated attack highlighted by developer Nick Johnson, who received a phishing email that asked him to sign in on a fake Google page. Google advises users to set up two-factor authentication and Password Alerts to enhance security, stressing that they will never ask for login credentials via email or phone.