Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A phishing campaign targeting marketing professionals impersonates major brands like Coca-Cola, Netflix, OpenAI, and FIFA to steal Google credentials. Discovered by Team Cymru's Will Thomas, the campaign sends convincing job recruitment emails via legitimate HR platform PeopleForce. Victims are routed through nested redirects — passing through Salesforce's ExactTarget and Wise Agent CRM — before landing on a Netlify-hosted phishing site. The final page uses a browser-in-the-browser (BitB) technique to display a fake Google sign-in popup. Over 30 malicious domains impersonating corporate brands have been identified. Defenders are advised to deploy advanced web filtering beyond reputation-based tools and use password managers, which won't autofill credentials on spoofed sites.

4m read timeFrom darkreading.com
Post cover image
Table of contents
Abusing Enterprise Platforms for Nested RedirectsDefending Against Job Scam Phishing Attacks
228 Impressions