Threat Actors Exploit Google Cloud Services to Steal Microsoft 365 Credentials
ID: 0da7a81a-1323-5d77-a450-c8f71130d698
STIX ID: report--0da7a81a-1323-5d77-a450-c8f71130d698
Feed Name: GBHackers
**Executive Summary:** A sophisticated phishing campaign abused Google Cloud Application Integration’s Send Email capability to deliver over 9,300 phishing messages to ~3,200 organizations in a 14-day period, leveraging legitimate Google domains and a fake CAPTCHA to bypass filters and harvest Microsoft 365 credentials; the operation primarily targeted manufacturing, technology/SaaS, and financial firms across the United States, APAC, and Europe, and prompted Google to implement mitigations while defenders are advised to use MFA, verify domains, and avoid clicking email links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
