{"id":9668,"date":"2026-01-06T10:04:40","date_gmt":"2026-01-06T10:04:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/06\/new-sophisticated-phishing-attack-mimic-as-google-support-to-steal-logins\/"},"modified":"2026-01-06T10:04:40","modified_gmt":"2026-01-06T10:04:40","slug":"new-sophisticated-phishing-attack-mimic-as-google-support-to-steal-logins","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/06\/new-sophisticated-phishing-attack-mimic-as-google-support-to-steal-logins\/","title":{"rendered":"New Sophisticated Phishing Attack Mimic as Google Support to Steal Logins"},"content":{"rendered":"<p>    New Sophisticated Phishing Attack Mimic as Google Support to Steal Logins<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybersecurity researchers have uncovered a dangerous new phishing campaign that tricks users into surrendering their credentials by impersonating legitimate Google support and notifications.<\/p>\n<p>The attack combines vishing (voice phishing), <a href=\"https:\/\/cybersecuritynews.com\/rise-in-phishing-activity-using-spoofed-sharepoint-domains\/\" target=\"_blank\" rel=\"noreferrer noopener\">spoofed domains<\/a>, and Google\u2019s own trusted infrastructure to achieve exceptional success rates against organizations worldwide.<\/p>\n<p>The attack employs a multi-layered <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> approach. Threat actors initiate contact by phone, using voice-spoofing technology to mimic Google support representatives.<\/p>\n<p>These calls reference suspicious account activity or security concerns, building urgency and trust.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-google-support-based-phishing-campaign\"><strong>Google Support-Based Phishing Campaign<\/strong><\/h2>\n<p>The attacker then directs victims to click links in follow-up emails that appear to originate from legitimate Google addresses, bypassing traditional email authentication checks like SPF, DKIM, and <a href=\"https:\/\/cybersecuritynews.com\/stop-email-impersonation-your-complete-guide-to-detecting-spoofing-with-dmarc\/\" target=\"_blank\" rel=\"noreferrer noopener\">DMARC<\/a>.<\/p>\n<p>What makes this campaign particularly insidious is its abuse of Google\u2019s own cloud infrastructure.<\/p>\n<p>Rather than creating fake domains that might trigger security filters, attackers leverage Google Cloud Application Integration services to send phishing emails directly from legitimate Google infrastructure.<\/p>\n<p>In December 2025 alone, researchers documented over 9,000 phishing emails targeting approximately 3,200 businesses across the United States, Europe, Asia-Pacific, Canada, and Latin America.<\/p>\n<p>The attack flow follows a sophisticated redirection chain. When victims click embedded links, they land on pages hosted on trusted Google <a href=\"https:\/\/cybersecuritynews.com\/cloud-attacks-raises-by-five-times\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cloud Storage<\/a> domains, making URL reputation filters ineffective.<\/p>\n<p>These pages display fake CAPTCHA verification screens that block automated security scanning while allowing human users through, as <a href=\"https:\/\/x.com\/ddd1ms\/status\/2008156104438780364\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported<\/a> by Dmitrn Gmilnanets.<a href=\"https:\/\/x.com\/ddd1ms\"><\/a><\/p>\n<p>After verification, victims are <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">redirected to credential-harvesting pages\u00a0<a href=\"https:\/\/cybersecuritynews.com\/scattered-lapsus-hunters-registered-40-domains\/\" target=\"_blank\" rel=\"noopener\">that mimic<\/a><\/span> Google login screens or Microsoft 365 interfaces, where their usernames and passwords are stolen.<\/p>\n<p>Security experts emphasize that cloud providers never initiate contact to request login credentials or direct users to external verification pages.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi8N7ordQeRBBwTZ9lVUkpcpodzSIThHMzZmjzaKjnp67tWAOOuLcDFjfPtFFEAr5NJt0hH_VQhIQ1FzOyrQbleAApS9uKXGRCUQFjOCAgOMfk4WnQ78CYlivN5P8zIrDh_mqD68Z9ni55d3YTSACwKbSFL5Fu4PcR4-28Fo-z9Je0AllF4g4gt9W83Oq0\/s1600\/Screenshot%25202026-01-06%2520111337%2520%25281%2529.webp?ssl=1\" alt=\"Fake Google Cloud Support email\"><figcaption class=\"wp-element-caption\">Fake Google Cloud Support email<\/figcaption><\/figure>\n<\/div>\n<p>Users should always navigate directly to official service portals they already use rather than clicking links in unsolicited communications.<\/p>\n<p>Organizations should implement multi-factor authentication (<a href=\"https:\/\/cybersecuritynews.com\/mandate-mfa-for-azure\/\" target=\"_blank\" rel=\"noreferrer noopener\">MFA<\/a>), enforce the use of a password manager, restrict login locations by IP range, and provide regular security awareness training.<\/p>\n<p>Additionally, security teams must move beyond traditional domain-reputation defenses and implement behavioral analysis and contextual threat detection to identify legitimate infrastructure that is being weaponized for malicious purposes.<\/p>\n<p>This campaign underscores a critical shift in phishing tactics: attackers are increasingly abusing legitimate platforms rather than spoofing domains, requiring a fundamental rethink of email security strategies.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/phishing-attack-mimic-as-google-support\/\">New Sophisticated Phishing Attack Mimic as Google Support to Steal Logins<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/phishing-attack-mimic-as-google-support\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Sophisticated Phishing Attack Mimic as Google Support to Steal Logins Cybersecurity researchers have uncovered a dangerous new phishing campaign that tricks users into surrendering their credentials by impersonating legitimate Google support and notifications. The attack combines vishing (voice phishing), spoofed domains, and Google\u2019s own trusted infrastructure to achieve exceptional success rates against organizations worldwide. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,163,124],"tags":[130],"class_list":["post-9668","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-google","category-phishing","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9668"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9668"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9668\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}