{"id":62733,"date":"2026-07-10T04:08:18","date_gmt":"2026-07-10T08:08:18","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=62733"},"modified":"2026-07-10T04:08:18","modified_gmt":"2026-07-10T08:08:18","slug":"job-phishing-campaign-fake-interviews","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/job-phishing-campaign-fake-interviews\/","title":{"rendered":"Job Phishing Campaign Steals Google Passwords via Fake Interview Invites"},"content":{"rendered":"<p>A sophisticated phishing campaign targeting job seekers is impersonating more than 30 major brands, using fake interview invitations to steal <a href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Google<\/a> account credentials. Security researchers have identified a network of malicious domains spoofing companies including Adobe, <a href=\"https:\/\/overcentral.com\/en\/website-shames-instagram-netflix-spotify-no-passkeys\/\" title=\"New Website Shames Instagram, Netflix, Spotify for No Passkeys\" data-iacss-internal=\"1\">Netflix<\/a>, OpenAI, Coca-Cola, Delta Air Lines, Marriott, and Louis Vuitton, among others. The campaign, which has been active for at least <a href=\"https:\/\/overcentral.com\/en\/barret-zoph-leaves-openai\/\" title=\"Barret Zoph Leaves OpenAI Again After Five Months\" data-iacss-internal=\"1\">five months<\/a>, leverages the anxiety surrounding job security in a tightening market to lure victims into surrendering their login details.<\/p>\n<p>The attack begins with an email that appears to come from a recruiter at a well-known company. Rather than using generic salutations, the messages address recipients by name, suggesting the attackers harvested professional data from platforms such as LinkedIn. The emails also include the names and photographs of genuine recruiters employed at the impersonated firms, lending a veneer of authenticity that makes the phishing attempt far more convincing than typical spam.<\/p>\n<h2>How the Fake Interview Phishing Campaign Works<\/h2>\n<p>Threat intelligence researcher Will Thomas of Team Cymru identified the infrastructure behind the operation. The phishing emails appear to have been sent through PeopleForce, a legitimate human resources and applicant tracking platform. Links within the emails route through multiple trusted domains before landing on a malicious page designed to capture Google credentials.<\/p>\n<p>The landing page invites the recipient to schedule an interview using what looks like a calendar booking tool. When the victim clicks &#8220;Continue with Google,&#8221; a pop-up window appears that mimics the official Google authentication dialog. This is a browser-in-the-browser attack, a technique in which a fake window rendered within the real browser captures everything the user types. Any credentials entered are sent directly to the attackers, not to Google.<\/p>\n<p>One important technical detail provides a potential safeguard: a reputable password manager will typically refuse to auto-fill credentials into the phishing pop-up, because it recognizes that the underlying domain does not belong to Google. This behavior can alert attentive users that something is wrong before they compromise their account.<\/p>\n<h2>Why This Campaign Is Particularly Dangerous<\/h2>\n<p>The scale of the operation is notable. The list of impersonated brands spans industries from airlines and hospitality to entertainment and consumer goods, including Adidas, American Airlines, Booking.com, FIFA, Levi&#8217;s, PepsiCo, Red Bull, Sephora, and United Airlines. The breadth of targets means that professionals across many sectors could receive a convincing message tailored to their field.<\/p>\n<p>The context of the current job market amplifies the threat. With many companies reducing headcount, often citing artificial intelligence as a factor in workforce reductions, marketing departments and other content-heavy roles are under particular pressure. An unsolicited offer from a prestigious brand can feel like a lifeline to someone worried about their position, making them less likely to scrutinize the message critically.<\/p>\n<h2>What Should You Do If You Receive a Suspicious Job Interview Email<\/h2>\n<p>If you receive an unexpected interview invitation from a recruiter at a major company, do not click any links or sign in with your Google account. Verify the offer independently by contacting the company through its official careers portal or by reaching out to the recruiter using contact information listed on the company&#8217;s legitimate website. A genuine recruiter will not object to verification, and the brief delay is far less costly than recovering a compromised account.<\/p>\n<p>The <a href=\"https:\/\/overcentral.com\/en\/fbi-seizes-netnut-popabotnet\/\" title=\"FBI Seizes NetNut Proxy Platform, Popa Botnet\" data-iacss-internal=\"1\">FBI<\/a> has previously warned the public about fake job advertisements used to steal money and personal information from applicants. This campaign demonstrates that the tactics have evolved: the attackers are now using real names, real photographs, and legitimate HR platforms to lower their targets&#8217; defenses.<\/p>\n<h2>How to Protect Yourself from Recruitment Phishing Attacks<\/h2>\n<p>Several practical measures can reduce your risk. First, use a zero-knowledge password manager that will refuse to auto-fill credentials on unfamiliar domains \u2014 this can serve as a direct technical signal of a phishing attempt. Second, enable two-factor authentication on your Google account using an authenticator app or hardware security key, which can prevent credential theft from succeeding even if your password is compromised. Third, treat any unsolicited job offer with skepticism, particularly if it asks you to sign in to a third-party service or provide sensitive information before you have spoken with anyone directly. Finally, monitor your accounts for suspicious activity and report phishing emails to the impersonated company and to relevant authorities. The combination of technical defenses and cautious behavior remains the most effective protection against increasingly sophisticated recruitment scams.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A sophisticated phishing campaign targeting job seekers is impersonating more than 30 major brands, using fake interview invitations to steal Google account credentials. Security researchers have identified a network of malicious domains spoofing companies including Adobe, Netflix, OpenAI, Coca-Cola, Delta Air Lines, Marriott, and Louis Vuitton, among others. The campaign, which has been active for [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":74460,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/C0O9VVI.jpg","fifu_image_alt":"Job Phishing Campaign Steals Google Passwords via Fake Interview Invites","footnotes":""},"categories":[349],"tags":[],"class_list":["post-62733","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/C0O9VVI.jpg","fifu_image_alt":"Job Phishing Campaign Steals Google Passwords via Fake Interview Invites","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=62733"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62733\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/74460"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=62733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=62733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=62733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}