Phishing Campaign Poses as “Job Interviews” from Netflix, OpenAI, and 30+ Brands to Harvest Google Passwords
What Happened — Threat researchers uncovered a large‑scale phishing operation that impersonates recruiters from more than 30 well‑known companies—including Netflix, OpenAI, Adobe, and Coca‑Cola—to lure job seekers into a fake “schedule interview” flow. Victims are prompted to click “Continue with Google,” where a browser‑in‑the‑browser dialog captures their Google credentials.
Why It Matters for Compliance & Audit Readiness
- Credential‑theft attacks directly test the effectiveness of SOC 2 Access Control (CC6.1) and Identity Management policies; a breach would constitute a control failure that must be documented and remediated.
- The campaign’s use of a legitimate HR platform (PeopleForce) highlights the need for continuous monitoring of third‑party integrations and evidence that only authorized applications can access corporate identity providers.
- Detailed, personalized spear‑phishing underscores the importance of Security Awareness Training and periodic testing to satisfy SOC 2 Security (CC6.2) audit requirements.
Who Is Affected – Technology SaaS firms, media & entertainment, advertising agencies, and any organization that recruits via public channels; broadly, any enterprise whose employees use Google Workspace for authentication.
Recommended Actions
- Map this incident to SOC 2 Access Control and Identity Management controls; verify that MFA is enforced for all Google sign‑ins.
- Capture and retain evidence of phishing email headers, malicious domains, and the PeopleForce integration as part of continuous control monitoring.
- Refresh Security Awareness Training with a module on recruiter‑impersonation phishing and conduct a simulated phishing test.
Technical Notes – Attack vector: phishing email → malicious domain → PeopleForce‑hosted scheduling page → browser‑in‑the‑browser Google OAuth prompt. No CVE is involved; the threat relies on social engineering and trusted third‑party services. Source: same as above