Hackers Route Phishing Through Google to Steal Microsoft Credentials
Attackers send fake Google emails to trick corporate workers into clicking links that look real. The links route through Google services before landing on a fake Microsoft login page that steals work email passwords.
- Report priority
- Medium
- Targets
- Google+1 more
How it works
- Attackers send fake emails that look like they come from Google.
- The links in these emails first go through real Google services like Meet, Search, or DoubleClick.
- This tricks security filters into letting the link through.
- After passing those checks, the link finally leads to a fake Microsoft login page.
- The fake page tries to look like your real company's login screen to steal your work email password.
What to do
If you work for a company and recently clicked a link in an email that looked like it came from Google, check your email for any suspicious messages from Google or your company. If you didn't click anything, you're likely not affected.
If you clicked a link and entered your password, change your Microsoft work email password immediately. Go to your company's IT support or security team for help. If you're unsure whether you clicked anything, check your email for any suspicious messages and report them to your IT team. They can help you determine if you were targeted.
Technical details
An employee at a company gets an email that looks like it's from Google. The email says something like 'Your Google account needs updating.' The link in the email first goes to a real Google Meet page, then to a fake Microsoft login page. The fake page shows the company's real logo and asks for the employee's work email password. If the employee types in their password, the attackers steal it.
This phishing campaign abuses legitimate Google services to bypass security filters and deliver tailored credential theft. Attackers route victims through Google Meet, Search, and DoubleClick in a multi-stage redirect chain, hiding the final malicious page from early scans. Once a target passes automated checks, they're served a phishing page mimicking their employer's branding, with pre-filled email fields and language support for 16 languages.
The campaign targets manufacturing, government, finance, and nonprofit sectors, using lures like document reviews and mailbox warnings. Some victims are directed to fake Microsoft sign-in pages to steal credentials, while others encounter false identity prompts that trick them into installing ScreenConnect, a legitimate remote access tool repurposed for persistent, interactive control of compromised endpoints.