Free Phishing Test
CYBER THREATS

Fake Recruitment Conversations Impersonating Adobe, Netflix, Coca-Cola and OpenAI: Marketers Targeted by a Phishing Campaign

09-jul-2026 12 minutes read

A phishing campaign using false job offers from over 30 recognizable brands steals login details to Google accounts belonging to marketing specialists. Will Thomas, senior advisor at Team Cymru, identified at least 34 domains used in this operation, which has been running continuously for at least five months

What is this phishing campaign and who does it attack?

The attack impersonates recruitment. The victim receives a message from a “recruiter” looking for candidates for marketing positions. The message contains the recipient’s name and surname and refers to his/her actual industry, which indicates prior recognition of the target’s professional profile before the fake message was sent.

What is phishing in this release?

Classically, it is an attempt to extort data or money by impersonating a trusted entity. Here, the role of a trusted entity is played by a well-known brand (Adobe, Netflix, Coca-Cola, OpenAI and several others) and by a specific, named recruiter.

The campaign differs from typical phishing attacks in that it does not lead the victim immediately to a malicious domain. It first passes it through several legitimate SaaS platforms, making it difficult to detect by standard security filters.

The operation targets only people working in marketing. This choice is not accidental. The marketing department regularly contacts external recruiters, agencies and partners, so employees in this area have a lower natural vigilance towards recruitment messages than, for example, the IT or security departments.

How the attack works: fake job offer step by step

Message from the “recruiter” with real name and photo

Attackers sign messages with the name and photo of a real recruiter employed in the impersonated company, which gives the fake job offer credibility that is difficult to verify at first glance. In one documented case, fake news impersonated Paulina Manzo, an Adidas recruiter, who publicly warned about the use of her identity on LinkedIn. She never sent such an email herself.

Source: https://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/

Redirection chain through four platforms with two different functions

Instead of taking the victim straight to the malicious domain, the attack passes them through four successive platforms before reaching the final phishing site. It is worth distinguishing two different functions that these platforms perform in the chain.

The first three links are used to “borrow” the domain’s trust and reputation. The email is sent from PeopleForce, a real, cloud-based HR and ATS (Applicant Tracking System) platform. The link continues to exct.net, a Salesforce Marketing Cloud domain operating under the former ExactTarget brand. From exct.net, traffic is redirected to Wise Agent, a cloud-based CRM system for real estate agents, completely unrelated to recruitment. Each of these three domains has an established reputation and real business use, so spam filters that evaluate the first link in the message have no reason to block it.

The fourth link is the phishing site itself, hosted on Netlify, a free platform for publishing static websites, such as mckinsey-careers[.]com. Netlify isn’t borrowing brand reputation here like the previous three platforms. Its role is different: it is a fast, free and easy-to-rotate hosting that allows attackers to set up and replace landing pages without affecting earlier stages of the email chain. This difference is important for defenders because it requires two different types of detection: analysis of the reputation of intermediary domains and monitoring of newly registered, cheap hosting sites that are confusingly similar to your own brand name.

It is unknown how attackers gained access to PeopleForce, Salesforce Marketing Cloud and Wise Agent. They could set up test accounts specifically for the campaign or use the compromised login details of an existing customer. None of these paths require hacking into the infrastructure of the service providers themselves.

Fake Google Login Window: Browser-in-the-Browser (BitB) Technique

After reaching the final phishing page, the victim sees a “Continue with Google” button and a button to schedule a call. Clicking opens a window that closely resembles a native browser window with a Google login form, complete with a URL bar, icons, and a layout typical of a real OAuth window. In fact, it’s just HTML and CSS rendered inside the phishing page itself, not a separate system window.

This technique, known as Browser-in-the-Browser, neutralizes the most popular piece of advice given to employees: check the address in the browser bar before entering your login credentials. Since the address bar is also part of the fake graphic, the victim has no easy way to distinguish it from the real Google login page unless they pay attention to the fact that the entire window does not behave like an independent system process, for example, it cannot be moved beyond the borders of a browser tab.

What brands and sectors were used in the campaign

The campaign covers at least 34 domains impersonating companies from six different industries, which shows that the attackers did not limit themselves to one sector, but built infrastructure for a wide range of potential victims.

  • Airlines and Travel American Airlines, Booking.com, Delta Air Lines and United Airlines were impersonated.
  • In the food industry the name Coca-Cola (four separate domains, including cocacola-hr[.]com and cocacola-careerhub[.]com), PepsiCo and Red Bull were used.
  • In the clothing and luxury goods segment, Adidas, Louis Vuitton, Sephora and Levis became victims of impersonation.
  • In the area of ​​staffing, consulting and technologythe brands used were Adobe (jobs-adobe[.]com), Aquent, ManpowerGroup, McKinsey & Company and OpenAI (careers-openai[.]com).
  • In hospitality and marketingMarriott and Omnicom Group suffered, and in entertainment and sports FIFA (six separate domains) and Netflix (jobsatnetflix[.]com).

The scale and sectoral scope of this campaign indicate anorganized and well-planned operation, conducted on a continuous basis, rather than a one-off incident. This does not have to mean a large budget: registering a domain and setting up a template career subpage on free hosting is a cheap and partially automated process today. It proves operational consistency and a long operating horizon rather than the scale of financing, which is difficult to estimate based on the number of domains alone.

Why marketers are the main target of this attack

Marketers fall victim to this campaign not by accident, but because their everyday work requires openness to contact with previously unknown people: agencies, freelancers, influencers, potential business partners and recruiters. This professional openness, which is an advantage in other circumstances, becomes a weakness in the context of phishing. The natural vigilance towards an unknown sender is lower in this group than, for example, in the IT or security department, where contact with external entities is subject to stricter procedures.

A marketer’s Google account can also be a gateway to resources that go far beyond just your mailbox. Many organizations use Google Workspace as a central login (SSO) mechanism for other tools, from Google Analytics and Google Ads through campaign data spreadsheets to content management platforms. So taking over one account can open access to advertising budgets, brand social media accounts and campaign data simultaneously, not just to private correspondence.

An additional risk factor is that marketers regularly click on links from external sources as part of their work: they track competitors’ campaigns, test landing pages, and analyze marketing tools. This means that clicking on a link from a “recruiter” does not evoke the same suspicion that it would in a team accustomed to a limited, verified set of external contacts.

What risk do fake recruitments pose to the organization

Operational risk: escalation via Google account and SSO

The takeover of one Google account rarely ends with the theft of private correspondence. In many organizations, this account acts as a central login mechanism for other systems, so its loss opens the door to a much wider security incident.

An attacker with access to the marketer’s mailbox gains insight into the history of communication with agencies, suppliers and internal teams, material sufficient to prepare another, even more credible attack, for example in the Business Email Compromise formula, where the compromised account is used to sending fake payment orders or changing transfer details on behalf of a real employee.

The consequence may also be the leakage of data, contact lists or access data to other tools saved in the mailbox or in Google Workspace.

Reputational risk: use of recruiters’ identity and brand

Using the name and photo of a real recruiter without his knowledge damages the company’s credibility, even when the organization itself is not to blame for the attack.

Paulina Manzo, an Adidas recruiter, had to publicly warn her network of contacts on LinkedIn that she had never sent the disputed message. This is a situation that no employee should be put into by the actions of third parties.

Candidates, partners and customers who encounter a fake job offer may persistently associate the brand with the scam, regardless of how quickly the company responded. Organizations with a recognizable name should treat monitoring domains that are confusingly similar to their own brand as a permanent element of reputation protection, not a one-time reaction to a report.

Regulatory risk: incident reporting obligations

Large organizations covered by the National Cybersecurity System and the EU NIS2 directive are obliged to report significant security incidents within specified deadlines. Taking over an employee’s Google account, which led to the leak of customer data, campaigns or access to subsequent systems, may qualify as such an incident, which shifts the responsibility for the response from the marketing department straight to the desk CISO and management.

How companies and employees can protect themselves

Browser-in-the-Browser Technique

The most effective technical answer to the Browser-in-the-Browser technique is phishing-resistant authentication: FIDO2 keys or passkeys, which bind the login process to a specific domain address. They cannot be captured through a fake window rendered in HTML because they will simply refuse to work on a page that is not real Google, no matter how legitimate it looks.

This distinguishes them from the password and classic one-time code: there is no publicly confirmed evidence that this particular campaign captures and uses an SMS or OTP code in real time to log into a real account, so simple two-factor authentication is still a real barrier to simple password capture.

FIDO2 and passkeys, however, remain the strongest security because they eliminate the risk of providing data on a fake website, regardless of how exactly the attacker’s background works.

Verification procedure

The second pillar of protection is the procedure of verifying the recruiter through company channels before the employee clicks on any link in the job message. A simple rule, checking the recruiter’s profile on the company’s website or contacting him via the official address and not via an email link, neutralizes most variants of this attack, because attackers do not have access to the real communication channels of the impersonated organization.

Monitoring of registered domains

Organizations with a recognizable brand should implement constant monitoring of registered domains that are confusingly similar to their own name (such as “-careers”, “-hiring”, “-jobs”) and have a ready procedure for reporting such domains to block fake websites at registrars and browsers, instead of reacting only after reporting from an employee or candidate.

Monitoring full redirect chains in links

IT and security teams should additionally analyze full redirect chains in links contained in emails, not just the first visible URL. This campaign shows that a filter that evaluates only the first hop of the link (the PeopleForce domain) will pass a message that leads several redirects to a phishing website. Link sandboxing and full redirect chain tracking at the mail gateway detects this technique much more effectively than static domain reputation lists.

Persistent procedures

If login details have already been provided on a suspicious website, the speed of response is key. The employee should immediately change the password to the Google account, and the IT administrator should log out all active sessions, check the mail forwarding rules and review the list of third-party applications connected to the account via OAuth. The access token for such an application may survive a password change alone, so without this review, an attacker may retain access even after the credentials are reset.

High security awareness – Practical Anti-Phishing Training

The most lasting element of defense remains the preparation of people, because this entire campaign is based on social engineering, not on malware or technical exploits. Social engineering tests show in numbers how many employees would click on a similar message, but the diagnosis itself does not build immunity – practical training in response to a specific attack scenario is needed.

Practical Anti-Phishing Training teaches the team to recognize warning signals in current, real attack scenarios. Unlike one-time theoretical training, training is based on cyclical simulations of cyberattacks tailored to the specificity of a given department, which is particularly important in teams with naturally lower vigilance towards external contacts, such as marketing. Building cybersecurity culture in such teams requires more frequent and focused exercises than standard annual company-wide training.

Thanks to PTA you can

  • reduce the click-through rate on phishing messages even below 4% after just a year of systematic training, and employees will start to actively report suspicious messages thanks to a dedicated extension for Gmail and Outlook,
  • relieve the workload of the IT team, which no longer has to prepare, conduct and analyze campaigns on its own – full responsibility for planning, simulations and reporting is taken over by Secawa team, and the involvement of the client-side coordinator is a maximum of approximately 3 hours per month,
  • prepare employees for a real attack. The scenarios are tailored to the nature of your industry and organizationand to the systems used in everyday work, and each failure triggersimmediate micro-training exactly at the moment when attention and memorization are the highest.
  • meet regulatory requirements of DORA, NIS-2, ISO 27001 and GDPR in the area of ​​cybersecurity education – the platform automatically generates reports ready for audit or control, which constitute evidence of due diligence.

Organizations that want to see how their team would react to a message similar to the one described in this article can start with Free Phishing Test – with no cost or obligation.

Get to know our original phishing simulation platform – personalized scenarios (instead of generic templates), Polish solution (data stays in the EU) and readiness for audits and controls (GDPR, DORA, UKSC/NIS2).

Gain specialised knowledge about cybersecurity

Build a resilient cybersecurity culture with our support

Let's discuss your organization's cyber needs

Fill in the form

Would you like to test the resilience of your systems?

Fill in the form to schedule a free, no-obligation consultation. We will discuss the scope of the penetration tests and prepare a proposed approach tailored to your organization and infrastructure.
Would you prefer to speak to us directly?
+48 732 123 579