A phishing campaign is impersonating more than 30 well-known brands — including Adobe, Netflix, Coca-Cola, and OpenAI — in fake job interviews designed to steal Google account credentials from marketing professionals, according to analysis by Will Thomas of Team Cymru and reporting by BleepingComputer. The emails pose as recruiters offering marketing roles and route victims through legitimate cloud services before landing on a malicious page.
By abusing trusted platforms, using real recruiters' names and photos, and rendering a fake Google sign-in with a browser-in-the-browser technique, the operation is unusually convincing and has reportedly been running for at least five months.
Key takeaways
- The campaign impersonates more than 30 major brands via fake recruiter emails aimed at marketing professionals.
- At least 34 domains impersonate high-value companies across airlines, food and beverage, apparel, tech, hospitality, and entertainment.
- Attackers abuse legitimate services — PeopleForce, Salesforce's exct[.]net (ExactTarget), and Wise Agent — in a nested redirect chain.
- A browser-in-the-browser (BitB) fake Google login popup harvests Gmail credentials.
- BleepingComputer reports the operation has run for at least five months; a domain list is published in Will Thomas' GitHub analysis.
Affected
What happened
A phishing campaign is impersonating more than 30 well-known brands in fake job interviews to steal Google account credentials from marketing professionals. The phishing email pretends to be from a recruiter looking to hire people for marketing roles, according to Will Thomas, senior advisor at Team Cymru, who analyzed the operation.
To build trust, the threat actor uses the names and pictures of real recruiters at the impersonated companies. One sample email posed as a message from an Adidas recruiter, asking the recipient to schedule a conversation about a potential role.
Clicking the link to schedule a meeting redirects the target to an attacker-controlled landing page — such as adidas-hiring[.]com — where they are asked to sign into their Google account to continue the process.
- More than 30 brands impersonated in fake recruiter emails
- At least 34 malicious domains identified
- Campaign has reportedly run for at least five months
How the redirect chain and fake login work
The campaign relies on nested redirects, routing visitors through multiple legitimate services before reaching the malicious landing page. While the phishing emails appear to originate from PeopleForce, the underlying links resolve to the exct[.]net domain operated by Salesforce following its acquisition of the ExactTarget marketing automation platform, now rebranded as Salesforce Marketing Cloud.
ExactTarget then redirects to Wise Agent (wiseagent[.]com), a cloud-based real estate CRM, which forwards to the phishing landing page.
On the landing page, clicking a 'Continue with Google' button triggers a fake Google sign-in popup rendered inside the phishing page. Although it may appear as a legitimate browser window, it is only HTML and CSS rendered within the page — a technique known as browser-in-the-browser (BitB). Using modern web development tools, the attacker imitates all the elements of a genuine authentication popup.
Browser-in-the-browser (BitB)
A BitB popup is not a real browser window. Try dragging it outside the browser boundary or resizing the actual window — a fake popup will not behave like a separate window.
- Redirect chain: PeopleForce → exct[.]net (Salesforce/ExactTarget) → wiseagent[.]com → phishing page
Who is being targeted
The campaign targets marketing professionals with fake recruiter outreach. Thomas found at least 34 domains impersonating high-value companies across several sectors:
- Airlines and travel: American Airlines, Booking.com, Delta Air Lines, United Airlines
- Food and beverage: Coca-Cola, PepsiCo, Red Bull
- Apparel and luxury goods: Adidas, Louis Vuitton, Sephora, Levi's
- Staffing, consulting, and tech: Adobe, Aquent, ManpowerGroup, McKinsey & Company, OpenAI
- Hospitality and marketing: Marriott, Omnicom Group
- Entertainment and sports: FIFA, Netflix
Abuse of legitimate platforms
It is unclear how the threat actor gained access to the legitimate platforms used in the redirect chain, but abusing them does not imply the services themselves were compromised. Possible avenues include creating a genuine account specifically for the campaign or using compromised logins to configure the redirect chain and landing page.
BleepingComputer reports that the operation has been running for at least five months and initially used Outlook email addresses bearing the name of the impersonated company.
How to protect against this campaign
- Treat unsolicited recruiter emails that require a Google login to 'schedule' an interview as suspicious.
- Verify recruiters and job offers through official company career pages and verified contacts.
- Inspect the destination URL carefully — landing pages use brand-lookalike domains such as adidas-hiring[.]com.
- Be skeptical of Google sign-in popups inside a page; a real Google login is a separate browser window, not embedded HTML.
- Enable phishing-resistant multi-factor authentication (such as passkeys or security keys) on Google accounts.
- Consult the domain list published in Will Thomas' GitHub analysis to block known indicators.
Impact & actions
Marketing professionals lured by fake brand recruiter emails risk having their Google account credentials stolen through a convincing fake sign-in page.
Security: Stolen Google credentials could give attackers access to email, cloud storage and other linked accounts.
Privacy: Personal and professional data tied to victims' Google accounts could be exposed.
Recommended actions · High urgency
- 1Verify recruiter outreach through official channels before acting
- 2Never enter Google credentials on pages reached from unsolicited links
- 3Enable phishing-resistant MFA (passkeys or security keys) on Google accounts
- 4Block known malicious domains from the published indicator list
Technical details
- Exploitation
- Exploited in the wild
- Attack vector
- Phishing email impersonating brand recruiters, leading through a nested redirect chain of legitimate services to a fake Google login (browser-in-the-browser).
Indicators of compromise
- Domain
- adidas-hiring[.]com — Phishing landing page impersonating Adidas recruiting
- Domain
- exct[.]net — Legitimate Salesforce (ExactTarget) domain abused in the redirect chain
- Domain
- wiseagent[.]com — Legitimate Wise Agent CRM domain abused in the redirect chain
Mitigations
- Block known malicious lookalike domains from the published indicator list
- Deploy phishing-resistant MFA (passkeys/security keys) on Google accounts
- User awareness training on fake recruiter and browser-in-the-browser attacks
Response
Customer guidance
Users should verify recruiter outreach through official company channels, avoid entering Google credentials on pages reached from unsolicited links, and enable phishing-resistant multi-factor authentication.
FAQ
What is this phishing campaign?
It is a phishing operation that impersonates more than 30 well-known brands in fake job interviews, targeting marketing professionals to steal their Google account credentials.
How does the attack trick victims?
Fake recruiter emails use real recruiters' names and photos and route victims through legitimate cloud services (PeopleForce, Salesforce's ExactTarget, and Wise Agent) to a phishing page that shows a fake Google login rendered with HTML and CSS — a browser-in-the-browser technique.
Which brands are impersonated?
At least 34 domains impersonate companies including Adobe, Netflix, Coca-Cola, OpenAI, Adidas, American Airlines, Booking.com, Delta, United, PepsiCo, Red Bull, Louis Vuitton, Sephora, Levi's, Aquent, ManpowerGroup, McKinsey, Marriott, Omnicom Group and FIFA.
How can I protect myself?
Verify recruiters through official channels, never enter Google credentials on pages reached from unsolicited links, be wary of sign-in popups embedded in a page, and enable phishing-resistant MFA such as passkeys or security keys.
The bottom line
A phishing campaign impersonating 30+ major brands lures marketing professionals with fake job interviews, abusing legitimate cloud services and a browser-in-the-browser fake Google login to steal account credentials.
What happens next
What to do






