A massive job interview phishing scam is directly targeting marketing professionals by impersonating over 30 global brands (Netflix, Adidas, OpenAI). Hackers utilize sophisticated nested redirects through legitimate platforms (Salesforce, PeopleForce) and a fake login window (Browser-in-the-Browser) to steal Google accounts. Organizations must deploy advanced email security solutions to stop this threat.
Just received an interview invitation from OpenAI, Coca-Cola, or Netflix?
Do not celebrate just yet! Recent reports reveal that over 30 of the world's top corporations are being impersonated in a massive job interview phishing scam aimed directly at your Google account. If you rush to click the scheduling link, total control of your personal data and your company's digital resources could fall into the hands of hackers in an instant.
This article will expose this highly sophisticated phishing tactic and guide you on how to thoroughly protect your systems.
Which brands and targets is this job interview phishing scam impersonating?
This campaign primarily targets marketing professionals by posing as recruiters from over 30 major brands across various sectors, ranging from airlines, food and beverage, to tech and sports.
Aviation and tourism
- American Airlines
- Booking. com
- Delta Air Lines
- United Airlines
Food and drinks
- Coca-Cola
- PepsiCo
- Red Bull
Fashion and luxury goods
- Adidas
- Louis Vuitton
- Sephora
- Levi's
Recruitment, consulting, and technology
- Adobe
- Aquent
- ManpowerGroup
- McKinsey & Company
- OpenAI Hotel and marketing
- Marriott
- Omnicom Group
Entertainment and sports
- FIFA
- Netflix
According to an analysis by Will Thomas at Team Cymru, this malicious activity has been operating covertly for at least five months. To establish absolute trust, the attackers use the real names and photos of actual human resources specialists (recruiters) working at the impersonated companies.
Fake website impersonating Adidas for scheduling meetings.
Fake website impersonating Adidas for scheduling meetings.
Targeting marketing personnel is a clearly calculated strategy. The Google accounts of these individuals are often linked to the enterprise's advertising management systems, customer databases, and social media networks. Therefore, successfully compromising a Google account creates a perfect stepping stone for hackers to infiltrate deeper into the organization's digital infrastructure.
How do the email phishing tactics and nested redirect techniques work?
Attackers distribute emails containing interview scheduling links, but instead of leading directly to a malicious website, they utilize nested redirects through legitimate platforms to bypass security scanning tools.
Specifically, when candidates click the link in the email, they are routed through the PeopleForce system (a legitimate HR platform), pass through Salesforce Marketing Cloud's domain (ExactTarget), and transit via Wise Agent CRM. Abusing the reputation of these cloud systems allows the phishing links to easily bypass traditional email filters, which typically only evaluate the credibility of the initial link. Only after completing this loop are victims pushed to fake domains that are meticulously designed to look exactly like the original career pages (e.g., adidas-hiring[.]com).
How does the Browser-in-the-Browser (BitB) technique steal Google login credentials?
The Browser-in-the-Browser (BitB) technique creates a fake login window using HTML and CSS directly inside the current webpage, perfectly simulating Google's authentication interface to visually deceive users.
On the fake landing page, users are prompted to click a "Continue with Google" button to confirm their interview schedule. Instead of opening a genuine Google browser window, the site displays a fake pop-up complete with a drawn-on address bar and a security padlock icon. Under the pressure of a job search, most victims drop their guard and proceed to log in. All emails and passwords entered into this virtual interface frame are immediately transmitted straight to the hacker's command server.
The combination of social engineering and the abuse of legitimate cloud infrastructure has turned this campaign into a persistent threat for office workers.
For individuals and internal IT departments, the vital rule is to always verify the recruiter's identity directly through the company's official careers page instead of trusting attached links. To identify BitB techniques, try dragging and dropping the login pop-up window outside the browser's boundaries; if it gets stuck inside the webpage, it is definitively a fake.
Most importantly, enable two-factor authentication (2FA/MFA) for Google accounts to create a shield that blocks unauthorized login attempts even if the password is compromised.
The job interview phishing scam targeting Google accounts exemplifies the dangerous evolution of cybercriminals as they thoroughly exploit trust and legitimate digital platforms. Awareness of redirect tactics or BitB virtual login techniques is essential. However, at the enterprise level, investing in specialized email security solutions is the only key to securing the doorway to the organization's data infrastructure.
Source:
Red alert: Job interview phishing scam impersonates 30 big brands to steal Google accounts


Top comments (0)