logo

Phishing Attacks Are Now Leveraging Google Ads to Hijack Employee Payments

ID: bede82eb-0c14-5e14-af3d-c6a785125fcc

STIX ID: report--bede82eb-0c14-5e14-af3d-c6a785125fcc

Feed Name: KnowBe4 Blog

Threat Score
68/100

Date Published: 2024-12-10

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Researchers warn of an active payroll-redirect phishing campaign that uses malicious Google Ads to promote spoofed HR/Workday pages; attackers harvest employee credentials and change direct-deposit information to steal paychecks, leveraging website builders and newly-registered domains across registrars and dedicated IP ranges to rapidly spin up infrastructure targeting numerous high-profile organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.