Executive Summary
In July 2026, a sophisticated phishing campaign targeted marketing professionals by impersonating over 30 renowned brands, including Adobe, Netflix, Coca-Cola, and OpenAI. Attackers utilized legitimate platforms like PeopleForce and Salesforce Marketing Cloud to send fraudulent job interview invitations, leading recipients through a series of redirects to malicious landing pages designed to steal Google account credentials. The campaign employed real recruiters' names and photos to enhance credibility, exploiting nested redirects through trusted services to evade detection. (bleepingcomputer.com)
This incident underscores the evolving tactics of cybercriminals who leverage legitimate platforms and trusted brand identities to execute credential theft. The use of nested redirects and impersonation of real recruiters highlight the need for heightened vigilance and advanced security measures to protect against such deceptive attacks.
Why This Matters Now
The increasing sophistication of phishing campaigns, as demonstrated by this incident, poses a significant threat to organizations and individuals. The exploitation of trusted platforms and brands necessitates immediate attention to enhance security protocols and user awareness to prevent credential theft and potential data breaches.
Attack Path Analysis
The attack began with phishing emails impersonating recruiters from well-known brands, leading victims to a fake job interview page that mimicked Google’s login portal. Upon entering their credentials, victims unknowingly provided attackers with access to their Google accounts. With these credentials, attackers could escalate privileges within the victim's Google services, potentially accessing sensitive data. The compromised accounts could then be used to move laterally, targeting other services or contacts associated with the victim. Attackers established command and control by maintaining access to the compromised Google accounts, allowing continuous monitoring and data extraction. Sensitive information was exfiltrated from the victim's Google accounts to external servers controlled by the attackers. The impact included unauthorized access to personal and professional data, potential identity theft, and further phishing campaigns using the compromised accounts.
Kill Chain Progression
Initial Compromise
Description
Phishing emails impersonated recruiters from reputable companies, directing victims to a fake job interview page that mimicked Google's login portal.
MITRE ATT&CK® Techniques
Spearphishing via Service
Spearphishing Service
Search Open Websites/Domains: Social Media
Impersonation
Spearphishing Link
User Execution: Malicious File
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security Awareness Training
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Awareness Training
Control ID: 500.14(b)
DORA – ICT Risk Management Framework
Control ID: Article 13
CISA ZTMM 2.0 – User Training and Awareness
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Staffing/Recruiting
Direct targeting through fake job interviews exploiting recruitment processes, requiring enhanced email security and candidate verification protocols to prevent credential theft.
Marketing/Advertising/Sales
Specific targeting of marketing professionals through phishing campaigns, necessitating strengthened authentication controls and employee awareness training for social engineering attacks.
Information Technology/IT
High-value targets for Google account compromise with potential access to cloud infrastructure, requiring zero trust segmentation and enhanced egress security controls.
Airlines/Aviation
Brand impersonation attacks targeting American Airlines, Delta, and United requiring reputation protection measures and customer communication security protocols against phishing.
Sources
- Phishing poses as big-brand job interview to steal Google accountshttps://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/Verified
- Fake Calendly invite phishing campaignhttps://cybernews.com/security/calendly-invite-phishing-recruitment-scam-targets-google-facebook-business-account-users/Verified
- Fake Calendly Invites Used To Steal Google And Facebook Ad Accountshttps://www.techworm.net/2025/12/fake-calendly-invites-used-to-steal-google-facebook-ad-accounts.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to escalate privileges, move laterally, and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF primarily focuses on network segmentation and workload isolation, it may not directly prevent initial credential theft through phishing attacks.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely constrain the attacker's ability to escalate privileges by enforcing strict identity-based access controls, reducing unauthorized access to sensitive data.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict segmentation and monitoring of internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely constrain the attacker's ability to maintain command and control by providing comprehensive monitoring and control over multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by controlling and monitoring outbound traffic.
Aviatrix Zero Trust CNSF would likely reduce the overall impact by limiting the attacker's ability to access and exploit sensitive data, thereby reducing the scope of unauthorized access and potential identity theft.
Impact at a Glance
Affected Business Functions
- Recruitment
- Human Resources
- Marketing Operations
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of Google account credentials, leading to unauthorized access to emails, documents, and other sensitive information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access between workloads and services, minimizing lateral movement opportunities.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Enforce Multi-Factor Authentication (MFA) to add an additional layer of security beyond just passwords.
- • Conduct regular security awareness training to educate users on recognizing and reporting phishing attempts.



