Skip to content
Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

Darkreading Rob Wright July 7, 2026

The phishing campaign uses several tactics, including nested redirects, to evade detection and steal credentials from unsuspecting targets.

A job-recruiting -focused phishing campaign is abusing legitimate platforms and masquerading as some of the biggest corporate brands to get marketing professionals to give up their Google credentials.

First spotted by Will Thomas, senior threat intelligence adviser at Team Cymru, the campaign poses as job recruiters looking to hire marketing professionals for major brands such as Coca-Cola, Louis Vuitton, McKinsey & Company, Netflix, OpenAI, and FIFA.

"The email addresses the individual by their name and the individual works in the relevant field, therefore the attackers likely did some relevant research and collection," Thomas wrote in a GitHub post detailing the activity.

Phishing campaigns that use job recruitment lures are quite common these days. In a related blog post today, Pieter Arntz, malware intelligence researcher at Malwarebytes, noted that such campaigns are likely effective because "entry-level positions remain highly competitive and AI continues to shape the job market."

The campaign is also notable because it uses legitimate platforms and several techniques, including nested redirects, to disguise the phishing links as trusted domains and avoid detection.

Thomas's post includes an example of a convincing-looking phishing email purportedly from McKinsey & Company, which contains a "view calendar & schedule call" link for a fake job interview. The email is sent via PeopleForce, a cloud-based human resources management platform.

When a targeted individual clicks the link, they're sent to a seemingly legitimate domain — in this example, mckinsey-careers[.]com — that is actually an attacker-controlled phishing link. What potential victims do not see, however, is that they're rerouted through several stops before arriving at the phishing link in a technique known as nested redirects.

In this campaign, victims are initially sent to a domain for ExactTarget, a Salesforce subsidiary, and then immediately redirected to Wise Agent, a real estate-focused CRM platform, and then finally to the phishing site hosted on Netlify, a cloud services platform.

Arntz tells Dark Reading the technique is effective for reducing detections for the eventual phishing link. "The nested redirects through legitimate services are intended to install trust in the victim and can bypass basic Web filters that only look at the domain in the first link (i.e., email filters)," he says. "It also allows them to rotate the chain at any point that breaks the chain or gets detected often."

It's unclear how the threat actors behind the campaign are abusing the legitimate platforms in the redirection chain. It's possible the attackers are simply using free trial or paid accounts, or stole account credentials from other customers.

When an individual eventually lands on the phishing link, they're presented with a fake Google sign-in window. Thomas said this is likely generated via the browser-in-the-browser (BitB) tactic, in which attackers craft a legitimate-looking pop-in window, complete with a valid looking URL, that in reality is just HTML built into the existing page.

According to a URLScan.io analysis of the McKinsey & Company link, the domain was created June 29 and has been flagged as potentially malicious. The IP address for the domain, meanwhile, has been flagged dozens of times over the last year for a variety of malicious activity, according to AbuseIPDB .

Thomas's post listed more than 30 malicious domains posing as corporate URLs, four of which are FIFA-related .

Arntz says it's hard to determine how effective job recruitment phishing campaigns are, but notes that if they didn't work, then threat analysts wouldn't be seeing so many of them. He also says using major brands has proven to be an effective lure.

"The bigger the brand and the more convincing it's impersonated (with the help of AI they can make them very convincing) the more likely the target is to follow the link," Arntz says.

While social engineering training for employees may help them spot suspicious emails, there are other steps that organizations can take to avoid such campaigns. Artnz notes that reputation-based filtering often falls short when it comes to nested redirects, so organizations need to deploy more effective Web filtering. Additionally, he says, password managers can help because they prevent credentials from being filled out on websites they are not designed for.

Senior News Director, Dark Reading

Rob Wright is a longtime reporter with more than 25 years of experience as a technology journalist. Prior to joining Dark Reading as senior news director, he spent more than a decade at TechTarget's SearchSecurity in various roles, including senior news director, executive editor and editorial director. Before that, he worked for several years at CRN, Tom's Hardware Guide, and VARBusiness Magazine covering a variety of technology beats and trends.

Prior to becoming a technology journalist in 2000, he worked as a weekly and daily newspaper reporter in Virginia, where he won three Virginia Press Association awards in 1998 and 1999. At TechTarget and Dark Reading, he has won several Azbee awards, including the 2026 National Silver Award for a series on vibe coding.

At Dark Reading, Rob currently covers security operations, cloud security, and Internet infrastructure. He has a keen interest in malvertising activity and the certificate authority industry, and has written extensively on both topics. He graduated from the University of Richmond in 1997 with a degree in journalism and English. A native of Massachusetts, he lives in the Boston area.

The State of Cloud Security: The Latest Challenges

The total economic impact™ of Snyk

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything

Practical Zero Trust Implementation on a Budget in the Age of Mythos

Building a Risk Based Vulnerability Management Program

Threat Hunting That Gets Big Results Despite Small Budgets

Say Yes to AI: Securing Innovation Without Compromise