www.paubox.com
Phishing Campaign Exploits Google Services to Evade Detection
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A sophisticated phishing campaign has been identified that routes victims through Google services, including Google Meet and Google Ads, before landing on a credential-harvesting page for Microsoft 365. This method exploits the trust that email security tools place in these legitimate platforms, allowing malicious links to bypass reputation checks. Hundreds of organizations across the U.S., Canada, and Europe have been targeted, with confirmed intrusions affecting sectors such as healthcare, education, and government. The attackers use various lures, such as fake voicemail notifications and document requests, to prompt victims to click. Once the victim clicks, they are led through a series of Google domains, ultimately reaching a phishing site that captures login credentials or OAuth tokens. The campaign has been active since at least July 2026, with researchers urging organizations to scrutinize emails containing nested redirect chains.
Key Points: • Phishing campaign exploits Google services to bypass email security checks. • Victims are routed through multiple trusted Google domains before reaching malicious sites. • Hundreds of organizations across various sectors have been targeted since July 2026.