A phishing campaign impersonating recruiters at Coca-Cola, Delta, Adidas, and dozens of other well-known companies routes victims through three legitimate platforms before showing them a convincing fake Google login window that isn't a real browser window at all.
What happened
A phishing campaign is impersonating recruiters at more than 30 well-known brands to steal Gmail credentials from job seekers, using personalized emails that address targets by name and accurately show their current job title. According to BleepingComputer, the campaign has been running for at least five months and impersonates companies across airlines and travel, food and beverage, apparel, consulting, and sports, including Coca-Cola, Delta Air Lines, Adidas, Netflix, OpenAI, and FIFA. The emails claim to come from a recruiter seeking to fill a marketing role and invite the recipient to click a link and schedule an interview. That link starts a chain of redirects through three separate legitimate cloud platforms before landing on a fake Google sign-in page designed to capture the victim's password.
Going deeper
The attack begins with an email sent through PeopleForce, a genuine cloud-based human resources and applicant tracking platform, which allows the initial message to pass through email security filters that trust the sending domain. Clicking the interview link then redirects through Salesforce Marketing Cloud, the rebranded version of the ExactTarget marketing platform Salesforce acquired years ago, before forwarding again through Wise Agent, a legitimate customer relationship management platform built for real estate professionals. Only after passing through all three services does the victim reach the actual phishing page. There, the site displays what looks like a standard Google login pop-up, complete with a URL bar showing a legitimate-looking address and a security padlock icon. In reality, that entire pop-up window is fabricated using HTML and CSS code rendered inside the phishing page itself, a technique known as browser-in-the-browser, meaning nothing about it is a real browser window, regardless of how convincing it appears.
What was said
BleepingComputer reported that the phishing campaign relies on at least 34 fake domains designed to imitate well-known companies across multiple industries, helping the emails appear more legitimate. The publication shared one example in which a phishing email claimed to be from a recruiter at a major sportswear brand, inviting the recipient to discuss a potential job opportunity. The message included a real person's name and profile photo to make the scam appear more convincing.
In the know
Browser-in-the-browser phishing has spread rapidly across major phishing-as-a-service platforms over the past year. BleepingComputer's earlier reporting also mentions a widely used platform called Sneaky2FA, which added the same fake pop-up technique to its Microsoft credential theft toolkit in late 2025, and separate campaigns have used it to target Facebook and Google advertising accounts as well. The technique's growing popularity across multiple unrelated criminal platforms suggests it has become a standard component of modern credential phishing rather than a one-off innovation tied to any single operation.
The big picture
Healthcare staff searching for new roles, whether administrative, clinical, or IT positions, use their personal or work Gmail accounts the same way any other job seeker does, and a convincing fake recruiting email carries no visible signal tying it to a specific industry the recipient works in. A compromised personal Gmail account can expose password reuse across other services, and staff who use the same Google account for work-adjacent tasks such as scheduling or file sharing extend that risk further. According to Paubox's Shadow AI report, healthcare staff routinely use personal accounts for work-related tasks without formal approval, a pattern that widens the practical impact of a personal account compromise well beyond what the account itself was intended to hold.
FAQs
How does routing an email through a legitimate HR platform help it bypass spam filters?
Email security tools assess the reputation of the domain a message originates from. A message sent through a genuine, widely used HR platform inherits that platform's trusted reputation, allowing it to pass checks that would flag an email from an unknown or newly registered domain.
What is browser-in-the-browser phishing, and why is it hard to detect visually?
Browser-in-the-browser is a technique that uses HTML and CSS code to construct a fake pop-up window inside a webpage, designed to look exactly like a real browser authentication window complete with a URL bar and security icons. Because the fake window is rendered within the page itself rather than opening as an actual separate browser window, it can display any URL the attacker chooses, making it visually indistinguishable from a genuine login prompt.
What is the simplest way to tell a browser-in-the-browser pop-up from a real one?
A genuine browser pop-up window can be dragged and moved independently outside the boundaries of the main browser window, or resized separately from it. A fake browser-in-the-browser window is locked inside the page and cannot be moved past the edges of the browser tab it appears in, which is the most reliable way to identify the deception.
Why does personalizing the phishing email with a recipient's real name and job title increase its effectiveness?
Generic phishing emails often get filtered by pattern-based detection or dismissed by recipients as obviously fake. An email that addresses the recipient by name and accurately references their actual industry or job title suggests the attacker has already done background research, which lends unearned credibility and makes the recipient less likely to question the message's legitimacy before clicking through.
What should someone do if they receive an unsolicited recruiting email with an interview scheduling link?
Rather than clicking the link directly, the recipient should navigate to the company's official careers page independently and verify whether the position and recruiter actually exist. If a login prompt appears after clicking a link from an email, checking whether that window can be dragged outside the browser's edges is a fast way to confirm whether it is a genuine authentication pop-up or a fabricated one.
