Global Phishing Campaign Exploits Google Services for Credential Theft

Global Phishing Campaign Exploits Google Services for Credential Theft

First seen 7 Sep 2026, 13:06 UTC Blog.Knowbe4Gbhackers 69.5

Article Content

Browse articles
ThreatCluster

A large-scale phishing campaign is leveraging trusted Google infrastructure to bypass email security measures and steal credentials. The operation uses a multi-stage redirect network that includes six distinct Google services, making it difficult for security systems to detect malicious activity. Victims are presented with highly personalized credential-harvesting pages that dynamically pull company logos and screenshots to appear legitimate. In some instances, the campaign also installs remote access tools like ScreenConnect. The attack targets both everyday users and organizations, exploiting their trust in Google's services. The campaign's sophistication allows it to evade detection by security gateways, which expect to see trusted domains at every stage. As of now, the campaign is active and continues to evolve, posing a significant threat to users and organizations alike.

Key Points: • Phishing campaign uses six Google services to evade detection. • Targets both individual users and organizations with personalized pages. • Employs a multi-stage redirect network for credential theft and remote access.

Ask AI about this cluster

Timeline

2026-09-04
Phishing campaign analysis published
KnowBe4 Threat Lab released an analysis detailing the sophisticated phishing campaign utilizing Google services.
Blog.Knowbe4
2026-09-07
Gbhackers report on phishing campaign
Gbhackers confirmed the ongoing phishing campaign exploiting Google infrastructure to steal credentials.
Gbhackers