Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

AISURU/Kimwolf botnet launches record 31.4 Tbps DDoS attack

Data breach at government tech giant Conduent balloon affects millions more Americans

Fundamental raises $255 million in Series A for new big data analytics initiative

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Cybercriminals exploit Google Cloud email capabilities in multi-step phishing campaign
Identity

Cybercriminals exploit Google Cloud email capabilities in multi-step phishing campaign

userBy userJanuary 2, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 2, 2026Ravi LakshmananCloud security/email security

Cybersecurity researchers have detailed a phishing campaign in which attackers exploited Google Cloud’s application integration services to distribute emails that masqueraded as legitimate messages generated by Google.

According to Check Point, this activity leverages the trust associated with Google Cloud infrastructure to send messages from a legitimate email address (‘noreply-application-integration@google’).[.]com”), it has a better chance of bypassing traditional email security filters and reaching users’ inboxes.

“This email mimics routine corporate notifications, such as voicemail alerts or requests to access files or permissions, and appears normal and trustworthy to the recipient,” the cybersecurity firm said.

During an observed 14-day period in December 2025, attackers were observed sending 9,394 phishing emails targeting approximately 3,200 customers, with affected organizations located in the United States, Asia Pacific, Europe, Canada, and Latin America.

cyber security

At the heart of this campaign is the exploitation of the application integration’s “send email” task, which allows users to send custom email notifications from the integration. Google says in its support documentation that you can only add up to 30 recipients to a task.

The fact that these emails can be configured to be sent to any email address indicates that attackers can exploit legitimate automation to send emails from Google-owned domains, effectively bypassing DMARC and SPF checks.

“To further enhance authenticity, the email closely followed Google’s notification style and structure, including familiar format and language,” Check Point said. “These decoys typically refer to a voicemail message or claim that the recipient has permission to access shared files or documents (for example, accessing the ‘Q4’ file), prompting the recipient to take immediate action by clicking on the embedded link.”

The attack chain is a multi-step redirect flow that begins when an email recipient clicks a link hosted on storage.cloud.google.[.]com is also a trusted Google Cloud service. This effort is being seen as another effort to reduce user suspicion and provide a semblance of legitimacy.

This link redirects the user to content provided by googleusercontent.[.]com presents a fake CAPTCHA or image-based verification, blocking automated scanners and security tools from scrutinizing the attack infrastructure and acting as a barrier to allow real users through.

Once the verification phase is complete, the user is directed to a fake Microsoft login page hosted on a non-Microsoft domain, ultimately stealing the credentials entered by the victim.

cyber security

In response to the findings, Google added that it will stop phishing attempts that exploit the email notification feature within Google Cloud Application Integration and will take further steps to prevent further abuse.

Check Point’s analysis reveals that the campaign primarily targets manufacturing, technology, finance, professional services, and retail industries, but also names other industries such as media, education, healthcare, energy, government, travel, and transportation.

“Google-branded alerts are particularly compelling because these areas typically rely on automated notifications, shared documents, and permission-based workflows,” it added. “This campaign highlights how attackers can exploit legitimate cloud automation and workflow capabilities to distribute phishing at scale without traditional spoofing.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleIndia’s Arya.ag attracts investors and remains profitable despite falling global crop prices
Next Article A simple test reveals PFAS contamination in firefighter uniforms
user
  • Website

Related Posts

AISURU/Kimwolf botnet launches record 31.4 Tbps DDoS attack

February 5, 2026

Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ Stories

February 5, 2026

Buyer’s Guide to AI Usage Control

February 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

AISURU/Kimwolf botnet launches record 31.4 Tbps DDoS attack

Data breach at government tech giant Conduent balloon affects millions more Americans

Fundamental raises $255 million in Series A for new big data analytics initiative

Eleven Lab CEO: Voice is the next interface for AI

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.