logo

Phishing Campaign Abuses Google’s Infrastructure to Bypass Defenses

ID: 721e00a0-267b-597e-b15b-ad4397dde91f

STIX ID: report--721e00a0-267b-597e-b15b-ad4397dde91f

Feed Name: KnowBe4 Blog

Threat Score
65/100

Date Published: 2026-01-14

Date Updated: 2026-04-28

Author: KnowBe4 Team

...
...

Researchers at RavenMail report a widespread phishing campaign that targeted more than 3,000 organizations—mostly in the manufacturing sector—by using legitimate Google infrastructure (Google Cloud Storage, Google Forms/Classroom and Google-hosted URLs) to host credential-harvesting pages and multi-stage redirects. Because the emails originated via trusted Google services and passed SPF/DKIM/DMARC, they frequently bypassed secure email gateways and native email protections; RavenMail notes attackers manipulated workflow automation rather than breaching Google systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.