Attackers Abuse Google’s AppSheet to Send Phishing Emails

KnowBe4 Team | Sep 23, 2025

Google WorkspacesHackread reports that attackers are abusing Google’s AppSheet platform to send phishing emails.

The campaign was spotted by researchers at Raven, who warn that attackers are sending messages that impersonate AppSheet, informing users of phony trademark violations.

Notably, the emails are sent from AppSheet’s legitimate infrastructure, making them more likely to bypass security controls and appear legitimate to human recipients.

“As a Google Cloud service, AppSheet inherits the trust and reputation that organizations place in Google's infrastructure,” the researchers write. “When employees see ‘appsheet.com’ in their inbox, they naturally associate it with the same security standards they expect from Gmail or Google Drive....With millions of business users building applications on the platform, AppSheet communications are common in corporate environments, making malicious emails appear routine.”

Attackers have abused AppSheet for this purpose since at least March 2025, accounting for a good chunk of global phishing emails. Attackers are always looking for ways to slip past security filters and are increasingly abusing legitimate platforms to evade detection.

“This AppSheet campaign represents a broader trend of legitimate service abuse,” the researchers explain. “Attackers are discovering they can achieve better results by using trusted platforms rather than building their own infrastructure.”

Erich Kron, security awareness advocate at KnowBe4, told Hackread in a statement, “The reliance on commonly used or well-known brands in social engineering attacks is nothing new; however, these attacks still remain quite effective....These types of attacks are meant to blend in with normal day-to-day activities, further increasing the trust level of the potential victim.”

AI-powered security awareness training can give your organization an essential layer of defense by teaching your employees to recognize red flags associated with social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.

Hackread has the story.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Gartner Magic Quadrant




Get the latest insights, trends and security news. Subscribe to CyberheistNews.