Phishing Scam Poses as Big Brands to Steal Google Credentials from Marketing Pros
Want more insights like this?
A sophisticated phishing campaign is targeting marketing professionals by impersonating major brands including Coca-Cola, Netflix, OpenAI, McKinsey & Company, Louis Vuitton and FIFA. First spotted by Team Cymru's Will Thomas, the attackers send personalized job recruitment emails via legitimate HR platform PeopleForce, then route victims through nested redirects — bouncing through Salesforce's ExactTarget and real estate CRM Wise Agent — before landing on a fake Google sign-in page hosted on Netlify.
The multi-hop redirect chain bypasses basic email filters and builds false trust. Over 30 malicious domains have been identified, on convincing addresses like mckinsey-careers[.]com.
The final page uses a browser-in-the-browser trick: the Google login window is drawn inside the web page rather than being a real browser window. That's the tell — a genuine login window can be dragged outside the page, and a fake one can't. Password managers help too, since they won't autofill on a spoofed domain. Advanced web filtering and social engineering training round out the defenses.
Source: Dark Reading