Phishing Campaign Impersonates 30 Brands in Fake Job Interviews to Harvest Google Credentials
What Happened — A coordinated phishing operation masquerades as recruiters from more than 30 well‑known companies, using fake job‑interview emails to lure marketing professionals into a malicious “Continue with Google” sign‑in flow. The campaign abuses the legitimate PeopleForce HR platform and redirects through Salesforce Marketing Cloud and Wise Agent CRM before landing on a credential‑stealing page.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a gap in SOC 2 CC6.1 (Logical Access) and CC6.2 (User Authentication) controls when employees are not required to verify email origins or use MFA for third‑party sign‑ins.
- Highlights the need for documented Security Awareness Training and phishing‑simulation evidence, a key audit artifact for the SOC 2 Security principle.
- Shows why continuous monitoring of third‑party email domains and DMARC/DKIM enforcement must be captured as evidence of due‑diligence.
Who Is Affected — Marketing and recruiting teams across sectors such as travel, consumer goods, apparel, consulting, hospitality, entertainment, and technology; any organization that uses Google Workspace for authentication.
Recommended Actions
- Enforce MFA for all Google Workspace accounts and require SSO for third‑party applications.
- Update phishing‑awareness training to include “job‑interview” lure scenarios and run regular simulated attacks.
- Implement DMARC, DKIM, and SPF controls on all outbound domains; monitor for unauthorized use of brand‑related domains.
- Document the controls and evidence in your SOC 2 readiness repository.
Technical Notes – The attack chain uses nested redirects: PeopleForce → Salesforce Marketing Cloud (exct.net) → Wise Agent (wiseagent.com) → malicious landing page (e.g., adidas‑hiring.com). The final page hosts a counterfeit Google OAuth popup to capture credentials. Source: BleepingComputer