HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Fake Job‑Offer Phishing Campaign Impersonates Netflix, Coca‑Cola, and FIFA to Target Marketing Professionals

Attackers sent bogus recruiter emails that routed victims through legitimate HR and marketing SaaS platforms before presenting a fake Google login page. The scheme targets marketers and highlights the need for SOC 2‑aligned security awareness and access‑control evidence.

LiveThreat™ Intelligence · 📅 July 08, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
malwarebytes.com

Fake Job‑Offer Phishing Campaign Impersonates Netflix, Coca‑Cola, and FIFA to Target Marketing Professionals

What Happened – Attackers registered at least 34 look‑alike domains and sent unsolicited “recruiter” emails promising interviews with high‑profile brands. The messages direct victims through a chain of legitimate services (PeopleForce HR platform and Salesforce Marketing Cloud) before landing on a malicious page that displays a fake Google sign‑in pop‑up, harvesting credentials.

Why It Matters for Compliance & Audit Readiness

  • The scenario is a textbook example of a Business Email Compromise (BEC) that SOC 2 access‑control criteria (CC6.1) are designed to prevent and evidence.
  • Continuous monitoring of third‑party SaaS usage and documented security‑awareness training provide the audit trail needed to demonstrate reasonable diligence.
  • A breach of employee credentials can trigger downstream data‑exfiltration findings, affecting the confidentiality principle of SOC 2.

Who Is Affected – Marketing professionals (entry‑level to senior) across all industries; HR and recruiting SaaS platforms that are abused as transit points.

Recommended Actions

  • Map the incident to SOC 2 CC6.1 (Logical Access) and CC7.1 (Security Awareness) controls; verify that MFA and least‑privilege policies are enforced for all cloud services.
  • Deploy a formal security‑awareness program that includes simulated phishing and specific job‑scam detection training; retain completion logs as audit evidence.
  • Implement continuous SaaS‑vendor monitoring to detect anomalous domain registrations and redirect chains.

Source: Malwarebytes Labs – Fake Netflix, Coca‑Cola, and FIFA job scams target marketers

Technical Notes – The campaign uses a multi‑hop redirect (A → B → C → D) to obscure the final malicious landing page, leverages the PeopleForce HR platform and a Salesforce Marketing Cloud domain, and injects an embedded Google sign‑in iframe to harvest credentials. No public CVE is involved; the vector is social engineering/phishing.

📰 Original Source
https://www.malwarebytes.com/blog/scams/2026/07/fake-netflix-coca-cola-and-fifa-job-scams-target-marketers

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →