Big Brand Jobs Scam Targets Marketing Pros’ Google Accounts

**Job Scam Phishing Campaign Targets Marketing Pros with Google Credentials Heist**

A sophisticated phishing campaign is duping marketing professionals into handing over their sensitive Google credentials by posing as job recruiters for top brands. The scammers are using legitimate platforms and techniques to evade detection, making it essential for victims to be vigilant.

The campaign, first spotted by Will Thomas, senior threat intelligence adviser at Team Cymru, pretends to offer job opportunities with big-name companies like Coca-Cola, Louis Vuitton, McKinsey & Company, Netflix, OpenAI, and FIFA. The emails are tailored to the individual’s profession and name, suggesting that attackers have conducted research on their targets.

Phishing campaigns using job recruitment lures are common, but this one is notable for its use of nested redirects. When a targeted individual clicks on the link, they’re initially sent to a legitimate domain, only to be redirected through multiple stops before arriving at the phishing site. This technique makes it harder to detect the malicious link and install trust in the victim.

The campaign’s effectiveness lies in its ability to bypass basic web filters that rely solely on the initial domain in the email. The use of nested redirects also allows attackers to rotate the chain, making it easier for them to evade detection if one part of the redirect chain is broken or flagged.

It’s unclear how the threat actors are abusing legitimate platforms in the redirection chain. However, it’s possible that they’re using free trial or paid accounts, or stolen account credentials from other customers.

When victims eventually land on the phishing link, they’re presented with a fake Google sign-in window generated via the browser-in-the-browser (BitB) tactic. This is where attackers craft a legitimate-looking pop-in window, complete with a valid looking URL, that’s actually just HTML built into the existing page.

The domains used in this campaign have been flagged as potentially malicious by various security tools, including URLScan.io and AbuseIPDB. More than 30 malicious domains posing as corporate URLs have been listed by Thomas, with four of them related to FIFA.

While it’s hard to determine how effective job recruitment phishing campaigns are, experts agree that using major brands has proven to be an effective lure for attackers. As Arntz noted, “if they didn’t work, then threat analysts wouldn’t be seeing so many of them.”

**Protecting Yourself from Job Scam Phishing Attacks**

To avoid falling victim to this campaign, it’s essential to exercise caution when receiving unsolicited job offers via email. Be wary of emails that ask for sensitive information or direct you to suspicious links. Always verify the authenticity of a job offer by contacting the company directly and checking their official website.

When dealing with legitimate platforms like PeopleForce or ExactTarget, be aware that attackers may be using them as part of their redirection chain. Regularly update your security software, use strong passwords, and enable two-factor authentication to prevent credential theft.


Source: Dark Reading — 2026-07-07