
Fake Recruiter Emails From Big Brands Are Stealing Google Logins
A message lands in your inbox from a recruiter at a household name. Netflix, Coca-Cola, maybe OpenAI. They say they have seen your work, they think you would be a strong fit for a marketing role, and they would like to book a short call. The email uses your real name, it arrives through a recognised HR platform, and the recruiter's photo matches a real person on LinkedIn. Everything about it feels legitimate. That is exactly the problem. Security researchers have documented a phishing campaign that uses this setup to steal Google account credentials from marketing professionals, and it has been running quietly for months.
What the campaign is doing
Will Thomas, a senior threat intelligence adviser at Team Cymru, analysed the operation and published his findings in early July 2026. The emails pose as recruiters hiring for marketing positions at more than thirty well known brands, among them Coca-Cola, Louis Vuitton, McKinsey & Company, Netflix, OpenAI and FIFA. To make the approach convincing, the attacker uses the names and photographs of real recruiters who work at those companies, and addresses each target by name. As BleepingComputer reported, the operation has been active for at least five months.
The spread of brands is wide enough to catch almost anyone. Thomas found at least thirty-four lookalike domains across airlines and travel, food and drink, luxury goods, staffing and consulting, hospitality and sport. Adidas, PepsiCo, Marriott, American Airlines and ManpowerGroup all appear alongside the bigger names. The variety is not random. It gives the attacker a plausible cover story for whatever role a given target might realistically be offered.
The lure is a job interview. The email invites the recipient to view a calendar and schedule a call. Clicking the link starts a short journey that ends on a page asking the target to sign in with Google before they can book the meeting. Hand over those details and the attacker has the account, along with everything the victim uses it to reach: email, cloud storage, and any service that lets people log in with Google.
Why marketing professionals, and why it works
The targeting is deliberate. Marketing teams expect recruiter outreach, they are used to being approached about new roles, and many are active on the platforms where these lures appear. A flattering message from a brand you admire is easy to take at face value, especially when it uses your name and your field. Pieter Arntz, a malware intelligence researcher at Malwarebytes, noted that campaigns like this are likely effective because entry level positions remain highly competitive and AI continues to reshape the job market.
None of this is about the target being careless. The emails are researched, personalised, and delivered through channels people already trust. Falling for a well built approach like this says more about the effort behind it than the judgement of the person who received it.
The trick that makes the links look trusted
The clever part is how the links dodge suspicion. The emails are sent through PeopleForce, a genuine cloud based HR platform, so they arrive from a real service rather than a throwaway address. When the target clicks, they are not sent straight to the phishing page. They pass through a chain of legitimate services first: a Salesforce owned domain from the old ExactTarget marketing platform, then Wise Agent, a real estate CRM, before landing on the final page hosted on the Netlify cloud platform. This technique is known as nested redirects.
Why go to the trouble? Because many email filters only inspect the first domain in a link. If that first hop is a trusted Salesforce address, the message often sails straight through. Arntz explained that the redirect chain both builds trust with the victim and lets the attacker swap out any link that starts getting flagged, which keeps the operation running even as individual pieces are detected.
The fake Google sign-in
The final page presents what looks like a standard Google sign-in window. It is not. Thomas assessed that it uses a technique called browser-in-the-browser, where the pop-up you see is not a real browser window at all. It is HTML and CSS drawn inside the phishing page, complete with a convincing address bar. Because it mirrors the genuine Google prompt down to the detail, people type their password without a second thought.
One example domain, mckinsey-careers.com, was registered on 29 June 2026 and was quickly flagged as potentially malicious. Fresh domains like this appear and disappear throughout a campaign, which is part of why blocking them one at a time rarely keeps pace.

How to protect your organisation
No single control stops an attack this well researched, but a few layers together make it far harder to land:
- Treat unexpected recruiter emails with calm caution. If a role interests you, go to the company's official careers site directly rather than following the link in the message.
- Check any sign-in pop-up properly. A browser-in-the-browser window cannot leave the page it sits on, so try to drag it beyond the edge of the main window. A real browser window moves; a fake one stays put.
- Use a password manager. It will only fill your credentials on the real Google domain, so it quietly declines on a lookalike page, which is a useful early warning.
- Turn on phishing resistant multi-factor authentication, such as passkeys, wherever you can, so a stolen password on its own is not enough to open the account.
- Do not rely on domain reputation filtering alone. Nested redirects defeat filters that only read the first link, so web filtering needs to follow the whole chain.
- Give staff a fast, blame free way to report a suspicious message, and thank the ones who do. Early reports are often the first sign of a new campaign.
The bottom line
The most effective phishing rarely looks like phishing. It looks like an opportunity, delivered through familiar platforms, wearing the name of a brand you respect. This campaign works because it is patient, personalised, and built on trust the attacker has borrowed rather than earned. The answer is not to treat every message as a threat, but to give people the context to recognise the pattern, the tools that fail safely when something is wrong, and the confidence to check before they click. People who know what a modern lure looks like are one of the strongest defences an organisation has.
Phishing Tackle offers the tools businesses need to strengthen their human risk strategies, with multi-platform testing, real-time behavioural insights, and actionable data to keep your organisation ahead of modern cyber threats.
Contact us today to learn how Phishing Tackle can help safeguard your organisation from the growing array of cyber risks.
