mediumPhishing

Fake Job Interview Phishing Campaign Targeting Google Accounts

First seen Jul 7, 2026 · Updated Jul 7, 2026

phishingcredential-theftbrand-impersonationgoogle-accountssocial-engineeringrecruitment-scam

A large-scale phishing campaign impersonates over 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, using fake job interview lures to steal Google account credentials from marketing professionals. The attackers leverage trusted brand names and recruitment pretexts to bypass victim skepticism and harvest credentials likely for account takeover, further phishing, or resale.

Technical Analysis

The campaign uses spoofed recruitment communications and fake interview portals that mimic legitimate brand career pages, directing targets to credential-harvesting pages designed to capture Google OAuth or account login credentials. The impersonation of OpenAI as a lure brand is notable, as marketing and business professionals increasingly interact with AI-branded recruitment content, making them plausible targets for socially engineered credential theft. No malware payload or CVE is indicated; the attack relies entirely on social engineering and fake login pages rather than technical exploitation. Stolen Google credentials could be reused to compromise connected services, including Workspace-integrated AI agent tools, RAG pipelines, or third-party apps authorized via Google OAuth, if victims reuse credentials or have API keys/service integrations tied to their Google identity. Organizations whose employees use Google accounts to access AI agent platforms or automation tools face downstream risk of credential replay and unauthorized API access.

Affected Systems

Google account holders (Gmail, Google Workspace); marketing and recruitment professionals; any third-party services or AI agent platforms using Google OAuth/SSO for authentication

Indicators of Compromise

  • Fake job interview/recruitment phishing pages impersonating Adobe, Netflix, Coca-Cola, OpenAI, and 25+ other brands (specific domains/URLs not disclosed in source data)

Remediation Steps

  1. 1

    Enable Multi-Factor Authentication

    Enforce MFA/2FA on all Google accounts, especially for employees in marketing, HR, and recruitment roles who are frequent targets.

  2. 2

    User Awareness Training

    Educate employees on verifying recruitment communications directly through official company channels before clicking interview links or entering credentials.

  3. 3

    Review OAuth App Authorizations

    Audit and revoke unnecessary third-party OAuth grants tied to Google accounts, particularly those connected to AI agent tools, automation platforms, or API integrations.

  4. 4

    Monitor for Credential Reuse

    Check for suspicious login attempts or unusual OAuth token activity on Google Workspace and connected services following the campaign's disclosure.

  5. 5

    Report and Block Phishing Domains

    Report identified phishing domains/pages to security teams and email/web filtering solutions to block access organization-wide.

Industries Most Exposed

marketingmediaretailtechnologyprofessional services

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.