Phishing Campaign Abuses Google’s Infrastructure to Bypass Defenses
ID: 721e00a0-267b-597e-b15b-ad4397dde91f
STIX ID: report--721e00a0-267b-597e-b15b-ad4397dde91f
Feed Name: KnowBe4 Blog
Researchers at RavenMail report a widespread phishing campaign that targeted more than 3,000 organizations—mostly in the manufacturing sector—by using legitimate Google infrastructure (Google Cloud Storage, Google Forms/Classroom and Google-hosted URLs) to host credential-harvesting pages and multi-stage redirects. Because the emails originated via trusted Google services and passed SPF/DKIM/DMARC, they frequently bypassed secure email gateways and native email protections; RavenMail notes attackers manipulated workflow automation rather than breaching Google systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
