logo

Threat Actors Exploit Google Cloud Services to Steal Microsoft 365 Credentials

ID: 0da7a81a-1323-5d77-a450-c8f71130d698

STIX ID: report--0da7a81a-1323-5d77-a450-c8f71130d698

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive Summary:** A sophisticated phishing campaign abused Google Cloud Application Integration’s Send Email capability to deliver over 9,300 phishing messages to ~3,200 organizations in a 14-day period, leveraging legitimate Google domains and a fake CAPTCHA to bypass filters and harvest Microsoft 365 credentials; the operation primarily targeted manufacturing, technology/SaaS, and financial firms across the United States, APAC, and Europe, and prompted Google to implement mitigations while defenders are advised to use MFA, verify domains, and avoid clicking email links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.