www.paubox.com Phishing Campaign Exploits Google Services to Evade Detection
Article Content
- •Phishing campaign exploits Google services to bypass email security checks.
- •Victims are routed through multiple trusted Google domains before reaching malicious sites.
- •Hundreds of organizations across various sectors have been targeted since July 2026.
A sophisticated phishing campaign has been identified that routes victims through Google services, including Google Meet and Google Ads, before landing on a credential-harvesting page for Microsoft 365. This method exploits the trust that email security tools place in these legitimate platforms, allowing malicious links to bypass reputation checks. Hundreds of organizations across the U.S., Canada, and Europe have been targeted, with confirmed intrusions affecting sectors such as healthcare, education, and government. The attackers use various lures, such as fake voicemail notifications and document requests, to prompt victims to click. Once the victim clicks, they are led through a series of Google domains, ultimately reaching a phishing site that captures login credentials or OAuth tokens. The campaign has been active since at least July 2026, with researchers urging organizations to scrutinize emails containing nested redirect chains.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Payroll Pirates, W3LL Kit and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…