Blog.Malwarebytes
Phishing Campaign Exploits Google Cloud to Steal Microsoft 365 Credentials
First seen 7 Jan 2026, 14:42 UTC
•

•24.3
Export
Article Content
Browse articles
A phishing campaign is utilizing Google Cloud services to bypass security measures and steal Microsoft 365 login credentials. By leveraging legitimate workflow automation tools, attackers are creating convincing phishing attacks that are difficult to detect. This sophisticated approach poses risks to users of Microsoft 365 as it blends with authentic communications.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Critical Appsmith Vulnerability Enables Account Takeovers
Google Chrome Zero-Day Vulnerability CVE-2025-13223 Exploited in the Wild
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials