logo

Phishing campaign abuses Google Cloud services to steal Microsoft 365 logins

ID: 83f18258-ed03-5745-9f75-334ca292cfae

STIX ID: report--83f18258-ed03-5745-9f75-334ca292cfae

Feed Name: Malwarebytes Blog

Threat Score
60/100

Date Published: 2026-01-06

Date Updated: 2026-04-28

...
...

Attackers are using Google Cloud Application Integration to send seemingly legitimate emails from [email protected] that link to Google Cloud Storage and googleusercontent.com pages (including CAPTCHAs) before redirecting victims to a fraudulent Microsoft 365 sign-in page that captures credentials; Google has blocked several campaigns and advises continued caution. Recommended defenses include verifying actual login URLs, avoiding email links, enabling multi-factor authentication, using password managers, and reporting suspicious messages to protection tools like Malwarebytes Scam Guard.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.