Big Brand Jobs Scam Targets Marketing Pros’ Google Accounts

**Job Scam Phishing Campaign Tricks Marketing Pros into Handing Over Google Credentials**

A sophisticated phishing campaign is targeting marketing professionals’ Google accounts by posing as major corporate brands, such as Coca-Cola and Netflix, in an attempt to steal sensitive credentials. The campaign uses a range of tactics, including nested redirects and browser-in-the-browser attacks, to evade detection and trick victims into surrendering their login details.

The scam, which was first spotted by Will Thomas, senior threat intelligence adviser at Team Cymru, involves sending targeted emails that appear to be from job recruiters looking to hire marketing professionals for top brands. The emails often address the individual by name and reference their relevant field of work, suggesting that the attackers have conducted some level of research on their targets.

Phishing campaigns using job recruitment lures are increasingly common, and experts say they are effective because entry-level positions remain highly competitive and AI is shaping the job market. According to Pieter Arntz, malware intelligence researcher at Malwarebytes, these types of campaigns rely on exploiting the desire for employment among young professionals, who may be more likely to click on a link or provide sensitive information without proper verification.

The campaign’s use of nested redirects is particularly noteworthy. When a targeted individual clicks on a phishing link, they are sent to a seemingly legitimate domain that is actually an attacker-controlled phishing link. This technique involves redirecting the victim through multiple stops before arriving at the final destination, making it difficult for security filters to detect the malicious activity.

Abusing Enterprise Platforms for Nested Redirects

The attackers are using legitimate platforms, such as PeopleForce and Netlify, to host their phishing links. In one example, a convincing-looking email purportedly from McKinsey & Company contains a link that sends the victim to a domain hosted on ExactTarget, which is then redirected through Wise Agent before finally landing on the phishing site.

This technique allows attackers to rotate the chain of redirects at any point if it becomes detected or breaks, making it harder for security filters to detect the malicious activity. Experts say this approach can bypass basic web filters that only look at the domain in the first link and install trust in the victim.

**Why It Matters**

The success of this campaign highlights the ongoing threat posed by phishing attacks, particularly those using job recruitment lures. With so many professionals seeking employment, these types of campaigns can be effective in tricking victims into handing over sensitive information.

As a result, it’s essential for marketing professionals and anyone who uses Google accounts to be vigilant when receiving emails from unknown senders. Always verify the authenticity of job offers by contacting the company directly and never provide login credentials via email or through suspicious links.

**Stay Safe**

To avoid falling victim to this type of scam, always verify the authenticity of job offers by contacting the company directly and never click on suspicious links. Use strong passwords and enable two-factor authentication to protect your Google account from unauthorized access. Additionally, be cautious when using public Wi-Fi networks or accessing sensitive information through shared devices.


Source: Dark Reading — 2026-07-07