HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Phishing Campaign Impersonates 30 Brands in Fake Job Interviews to Harvest Google Credentials

A multi‑brand phishing operation leverages PeopleForce, Salesforce Marketing Cloud, and Wise Agent to trick marketing professionals into a fake Google sign‑in, exposing gaps in access‑control and awareness controls that SOC 2 audits scrutinize.

LiveThreat™ Intelligence · 📅 July 07, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Phishing Campaign Impersonates 30 Brands in Fake Job Interviews to Harvest Google Credentials

What Happened — A coordinated phishing operation masquerades as recruiters from more than 30 well‑known companies, using fake job‑interview emails to lure marketing professionals into a malicious “Continue with Google” sign‑in flow. The campaign abuses the legitimate PeopleForce HR platform and redirects through Salesforce Marketing Cloud and Wise Agent CRM before landing on a credential‑stealing page.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a gap in SOC 2 CC6.1 (Logical Access) and CC6.2 (User Authentication) controls when employees are not required to verify email origins or use MFA for third‑party sign‑ins.
  • Highlights the need for documented Security Awareness Training and phishing‑simulation evidence, a key audit artifact for the SOC 2 Security principle.
  • Shows why continuous monitoring of third‑party email domains and DMARC/DKIM enforcement must be captured as evidence of due‑diligence.

Who Is Affected — Marketing and recruiting teams across sectors such as travel, consumer goods, apparel, consulting, hospitality, entertainment, and technology; any organization that uses Google Workspace for authentication.

Recommended Actions

  • Enforce MFA for all Google Workspace accounts and require SSO for third‑party applications.
  • Update phishing‑awareness training to include “job‑interview” lure scenarios and run regular simulated attacks.
  • Implement DMARC, DKIM, and SPF controls on all outbound domains; monitor for unauthorized use of brand‑related domains.
  • Document the controls and evidence in your SOC 2 readiness repository.

Technical Notes – The attack chain uses nested redirects: PeopleForce → Salesforce Marketing Cloud (exct.net) → Wise Agent (wiseagent.com) → malicious landing page (e.g., adidas‑hiring.com). The final page hosts a counterfeit Google OAuth popup to capture credentials. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →