Phishing Campaign Exploits Google Infrastructure for Data Theft

Published September 11, 2026

Attackers send fake Google login pages to trick users into entering their passwords. The scam uses Google's own services to hide the real attack site.

Report priority
Medium
Targets
Google

How it works

  • Attackers send emails or messages pretending to be from Google.
  • These messages link to fake login pages that look real.
  • When users enter their Google passwords, the attacker steals them.
  • The fake pages use Google's own services to make the scam harder to spot.

What to do

If you use a Google account and clicked on a link from an unexpected email or message, check your Google account for any unfamiliar logins or password changes.

Enable two-factor authentication in your Google account to add extra security. Review your recent login activity and revoke any suspicious sessions. If you suspect your password was stolen, change it immediately via Google's security settings.

Technical details

A user receives an email saying their Google account is locked. The email links to a fake Google login page hosted on a Google service. When the user types in their password, the attacker captures it and can access their account.

A sophisticated phishing campaign uses redirect chains to abuse Google infrastructure. Learn how attackers abuse Google infrastructure to steal credentials.