Hackers Abusing Google Tasks Notification for Sophisticated Phishing Attack
ID: 87aa422e-09f3-5e67-951e-2b13deed491b
STIX ID: report--87aa422e-09f3-5e67-951e-2b13deed491b
Feed Name: cybersecurityNews.com
A December 2025 phishing campaign leveraged Google’s Application Integration service and Google Cloud Storage to send legitimate-appearing Google Tasks notifications to more than 3,000 organizations (mainly manufacturing). Messages came from a legitimate Google address, passed email authentication (SPF/DKIM/DMARC/CompAuth), and redirected recipients to credential-harvesting pages hosted on storage.cloud.google.com, allowing attackers to bypass conventional email security that relies on sender reputation and domain trust.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
