Security News

Cybersecurity news aggregator

HIGH Attacks Dark Reading

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

A sophisticated phishing campaign targets marketing professionals by impersonating major brand recruiters to steal Google credentials. The attack uses legitimate HR platforms like PeopleForce to send emails and employs nested redirects through services like ExactTarget and Wise Agent to disguise the final phishing link hosted on Netlify, evading detection. Security professionals should educate users, especially in marketing roles, to scrutinize unsolicited job offers and verify URLs before entering credentials.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES CYBER RISK IDENTITY & ACCESS MANAGEMENT SECURITY THREAT INTELLIGENCE NEWS Big Brand Jobs Scam Targets Marketing Pros' Google Accounts The phishing campaign uses several tactics, including nested redirects, to evade detection and steal credentials from unsuspecting targets. Rob Wright,Senior News Director,Dark Reading July 7, 2026 3 Min Read SOURCE: SUPATMAN VIA GETTY IMAGES A job-recruiting-focused phishing campaign is abusing legitimate platforms and masquerading as some of the biggest corporate brands to get marketing professionals to give up their Google credentials. First spotted by Will Thomas, senior threat intelligence adviser at Team Cymru, the campaign poses as job recruiters looking to hire marketing professionals for major brands such as Coca-Cola, Louis Vuitton, McKinsey & Company, Netflix, OpenAI, and FIFA. "The email addresses the individual by their name and the individual works in the relevant field, therefore the attackers likely did some relevant research and collection," Thomas wrote in a GitHub post detailing the activity. Phishing campaigns that use job recruitment lures are quite common these days. In a related blog post today, Pieter Arntz, malware intelligence researcher at Malwarebytes, noted that such campaigns are likely effective because "entry-level positions remain highly competitive and AI continues to shape the job market." Related:'BusySnake' Infostealer Slithers Into Critical Infrastructure Networks The campaign is also notable because it uses legitimate platforms and several techniques, including nested redirects, to disguise the phishing links as trusted domains and avoid detection. Abusing Enterprise Platforms for Nested Redirects Thomas's post includes an example of a convincing-looking phishing email purportedly from McKinsey & Company, which contains a "view calendar & schedule call" link for a fake job interview. The email is sent via PeopleForce, a cloud-based human resources management platform. When a targeted individual clicks the link, they're sent to a seemingly legitimate domain — in this example, mckinsey-careers[.]com — that is actually an attacker-controlled phishing link. What potential victims do not see, however, is that they're rerouted through several stops before arriving at the phishing link in a technique known as nested redirects. In this campaign, victims are initially sent to a domain for ExactTarget, a Salesforce subsidiary, and then immediately redirected to Wise Agent, a real estate-focused CRM platform, and then finally to the phishing site hosted on Netlify, a cloud services platform. Arntz tells Dark Reading the technique is effective for reducing detections for the eventual phishing link. "The nested redirects through legitimate services are intended to install trust in the victim and can bypass basic Web filters that only look at the domain in the first link (i.e., email filters)," he says. "It also allows them to rotate the chain at any point that breaks the chain or gets detected often." Related:JadePuffer: The First Complete LLM-Driven Ransomware Attack It's unclear how the threat actors behind the campaign are abusing the legitimate platforms in the redirection chain. It's possible the attackers are simply using free trial or paid accounts, or stole account credentials from other customers. Defending Against Job Scam Phishing Attacks When an individual eventually lands on the phishing link, they're presented with a fake Google sign-in window. Thomas said this is likely generated via the browser-in-the-browser (BitB) tactic, in which attackers craft a legitimate-looking pop-in window, complete with a valid looking URL, that in reality is just HTML built into the existing page. According to a URLScan.io analysis of the McKinsey & Company link, the domain was created June 29 and has been flagged as potentially malicious. The IP address for the domain, meanwhile, has been flagged dozens of times over the last year for a variety of malicious activity, according to AbuseIPDB. Thomas's post listed more than 30 malicious domains posing as corporate URLs, four of which are FIFA-related. Arntz says it's hard to determine how effective job recruitment phishing campaigns are, but notes that if they didn't work, then threat analysts wouldn't be seeing so many of them. He also says using major brands has proven to be an effective lure. Related:Ransomware Thugs Masquerade as Interpol to Entice Small Biz "The bigger the brand and the more convincing it's impersonated (with the help of AI they can make them very convincing) the more likely the target is to follow the link," Arntz says. While social engineering training for employees may help them spot suspicious emails, there are other steps that organizations can take to avoid such campaigns. Artnz notes that reputation-based filtering often falls short when it comes to nested redirects, so organizations need to deploy more effective Web filtering. Additionally, he says, password managers can help because they prevent credentials from being filled out on websites they are not designed for. About the Author Rob Wright Senior News Director, Dark Reading Rob Wright is a longtime reporter with more than 25 years of experience as a technology journalist. Prior to joining Dark Reading as senior news director, he spent more than a decade at TechTarget's SearchSecurity in various roles, including senior news director, executive editor and editorial director. Before that, he worked for several years at CRN, Tom's Hardware Guide, and VARBusiness Magazine covering a variety of technology beats and trends. Prior to becoming a technology journalist in 2000, he worked as a weekly and daily newspaper reporter in Virginia, where he won three Virginia Press Association awards in 1998 and 1999. At TechTarget and Dark Reading, he has won several Azbee awards, including the 2026 National Silver Award for a series on vibe coding. At Dark Reading, Rob currently covers security operations, cloud security, and Internet infrastructure. He has a keen interest in malvertising activity and the certificate authority industry, and has written extensively on both topics. He graduated from the University of Richmond in 1997 with a degree in journalism and English. A native of Massachusetts, he lives in the Boston area. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets Say Yes to AI: Securing Innovation Without Compromise More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Critical Fortinet Flaws Under Active Attack by Jai Vijayan, Contributing Writer DEC 17, 2025 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES F5 BIG-IP Environment Breached by Nation-State Actor by Alexander Culafi OCT 15, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos, Contributing Writer OCT 03, 2025 Editor's Choice CYBERSECURITY OPERATIONS Why Identity Security Is Your Cyber Career Entry Point byKristina Beek JUN 30, 2026 CYBERATTACKS & DATA BREACHES EdTech Attackers Shift From Schools to Their Software Suppliers byArielle Waldman JUN 25, 2026 CYBERSECURITY OPERATIONS Do CISOs Need a Code of Ethics? byDark Reading Editorial Team JUN 24, 2026 Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article