CyberheistNews Vol 16 #37 [Bypassing the Gatekeepers] Global Phishing Turns Google into a Trust Proxy

KnowBe4 Team | Sep 15, 2026
Cyberheist News

CyberheistNews Vol 16 #37  |   September 15th, 2026

[Bypassing the Gatekeepers] Global Phishing Turns Google into a Trust Proxy

In addition to everyday users, Google's infrastructure is trusted by email security gateways, enterprise firewalls and automated URL detonation platforms.

Threat actors know this.

In this KnowBe4 Threat Lab analysis, we break down an active, wide-scale phishing campaign that routes victims through a deliberate chain of legitimate Google services before landing them on credential harvesters or deploying remote access tools.

The campaign abuses six Google properties across multiple redirect paths. Its landing page impersonates the victim's organization in real time. Depending on the lure, the attack either steals credentials or establishes persistent remote access.

The page pulls live company logos from Clearbit, real-time website screenshots from a third-party screenshot API and uses Google's public DNS to validate the victim's corporate email domain.

The result is a campaign that looks legitimate at every layer a defender is likely to inspect: the sending domain, the link, the intermediate hops and the page that finally collects credentials.

What Sets This Campaign Apart?

Unlike typical campaigns that rely on gateways missing malicious links, this operation provides security systems with exactly what they expect: trusted Google domains at every hop.

By the time a defender inspects the sending domain, the embedded link or the intermediate hops, everything still looks clean. The harvester at the end of the chain is built to wait for that inspection to pass.

Most phishing campaigns embed a malicious link and bet on the gateway missing it. This one does not need the gateway to miss anything. It feeds the gateway exactly what it expects: trusted Google domains at every hop.

[CONTINUED WITH SCREENSHOTS] At the Knowbe4 blog:
https://blog.knowbe4.com/bypassing-the-gatekeepers-how-a-global-phishing-campaign-turns-googles-infrastructure-into-a-trust-proxy

Your Gmail Security Has a Blind Spot. Here's What's Exploiting It.

85.8% of phishing attacks now use AI-generated content. 84.4% of evasive phishing emails pass DMARC, SPF and DKIM checks without a hitch. Native Gmail filters weren't built to catch threats with no malicious link and no payload, and attackers know it.

Introducing KnowBe4 Defend for Google Workspace

Today we're bringing Defend natively to Gmail. Get the same behavioral AI, explainable threat evidence and point-of-risk coaching trusted across Microsoft 365, built for Google Workspace.

When a threat is intercepted, Defend doesn't just block it in a silent box; it turns the threat into a teachable moment inside Gmail for your end users. In fact, 97% of users stop a high-risk action the moment a teachable moment appears.

Key Capabilities:

  • Catches evasive inbound threats: Evaluates conversational intent, display-name spoofing, prompt injections and zero-payload BEC using specialized AI models.
  • Visual labels that teach in the moment: Immediately prompts users to stop, evaluate and think before taking action on suspicious messages.
  • Explainable AI verdict evidence: Explains precisely why an email was flagged, giving your team actionable context to spot future threats.
  • Automated graymail and spam filtering: Triage unwanted messages to keep user inboxes clean and focused on critical work.

See it in action. Join our live demo on Sept. 30 to see how Defend for Google Workspace can help you protect every conversation.

Date/Time: Wednesday, Sept. 30, @ 2:00 PM (ET)

Save My Spot
https://info.knowbe4.com/ces-demo-3?partnerref=CHN

Greatness Phishing Kit Can Now Launch Sophisticated Attacks

Researchers at ZeroBEC are tracking a phishing platform called "Greatness" that's been significantly upgraded since it surfaced in 2023.

"Since its initial discovery, the platform has evolved significantly," the researchers write. "It now supports adversary-in-the-middle (AiTM) credential and token theft, device code phishing, and targets across multiple platforms, including Microsoft 365, iCloud, Yahoo and Google Workspace."

The platform's operators can launch either AiTM attacks or device code phishing attacks to bypass multi-factor authentication.

"The device code phishing approach complements the AiTM technique," ZeroBEC says. "While AiTM requires real-time interaction and proxy infrastructure, device code phishing is asynchronous. The attacker generates codes in advance, and the victim's approval can happen at any time.

"This dual capability gives Greatness operators flexibility to choose the most appropriate technique based on their target and campaign goals." Notably, all of the phishing emails observed by ZeroBEC were delivered to end users because the targeted organization had marked all RingCentral domains as safe.

"RingCentral's published email policy demands rejection of unauthenticated messages with 100% enforcement," the researchers write. "Under normal conditions, these emails should have been rejected at the gateway. Instead, all four were delivered to the inbox.

"The target organization is a legitimate RingCentral customer and has added the domain to its safe-sender configuration across its email security stack. This domain-based exclusion overrode the authentication failure, instructing the security controls to treat the spoofed messages as trusted. The messages were assigned a Spam Confidence Level of negative one (safe), bypassing all subsequent filtering."

More at the KnowBe4 Blog:
https://blog.knowbe4.com/greatness-phishing-kit-can-now-launch-sophisticated-attacks

Prompt Injection 101: What It Is and How to Stay Ahead

Every AI agent your company deploys will follow instructions; that's the point. What it can't do is reliably tell whose instructions those are: yours, or an attacker's, hidden inside an email, a shared document or a webpage it was just asked to read.

Join Javvad Malik, Lead CISO Advisor at KnowBe4, and Jack Chapman, SVP Threat Intelligence at KnowBe4, for a walk through both attack paths, direct and indirect prompt injection, and what changes when you start treating your AI agent like a new colleague instead of a piece of software.

You'll walk away learning:

  • What indirect prompt injection actually is and why it's fundamentally different from phishing a human
  • How attackers are hiding instructions in the everyday content your AI agent reads on your behalf
  • Real-world prompt injection incidents from 2025-2026: attacks on production systems, not just examples from research papers
  • Three "what if" scenarios to get you thinking about your own environment
  • Why the controls that protect people from phishing don't automatically transfer to AI agents and what to put in place instead

Register now for a clear look at the attack reshaping how we think about AI agent security.

Date/Time: TOMORROW, Wednesday, Sept. 16, @ 2:00 PM (ET)

Save My Spot
https://info.knowbe4.com/prompt-injection-101?partnerref=CHN2

he Workforce Has a Blind Spot, and It's Ringing

With inboxes increasingly well-guarded, cybercriminals are turning to a more vulnerable front in their attacks against your digital workforce.

Voice is the fastest-growing attack vector, and it's because it's dangerously effective. According to Verizon's 2026 Data Breach Investigation Report, phone-centric attacks are 40% more successful than traditional email-based phishing.

Voice phishing (vishing) is a smart attack vector, especially with AI enabling comprehensive target reconnaissance and tailoring. But the real problem is deeper: vishing tests a skillset that is underdeveloped among most workforces.

How is Vishing Different from Phishing?

Security teams have spent years training their workforce to spot phishing emails. They've drilled them to scrutinize the sender address and watch out for email typos. But vishing tests a different muscle entirely. Users can't stop and analyze a call mid-conversation like they can an email, and that turns into more mistakes at the moment of risk.

Security awareness training provides a strong baseline, but it doesn't build muscle memory. People forget close to 90% of what they learn within a month when that knowledge isn't tested and reinforced in the real world. Closing this gap takes real practice against the actual attack.

And that's exactly what Simulated Vishing is built to deliver.

Practice Against the Real Thing

Simulated Vishing extends KnowBe4's attack simulation capabilities across the voice channel, giving your workforce practice against the automated vishing attacks behind some of today's costliest breaches. Test your workforce with sophisticated simulations based on current attacks so they're better able to spot the red flags and shut down cybercriminals.

  • Real attack patterns, ready to launch: Pick from dozens of templates modeled on real-world scenarios, such as tax form verification and IT helpdesk scams.
  • Put your high-risk workflows to the test: Create custom simulations using uploaded audio or AI text-to-speech to test voice-based workflows used at your organization.
  • Test security behavior, not language proficiency: Pre-built and custom templates support 25+ languages and dialects, so you can run tests at global scale without worrying about language barriers.
  • Make practice feel real: Localized caller ID and automatic number cycling mean wrong area codes and carrier spam flags don't tip off users before they pick up.

New Attack Vector, Proven Risk Reduction Formula

Realistic simulations expose vulnerabilities, but closing these gaps and driving real behavior change is another matter entirely. This is where KnowBe4 excels, tapping into 16+ years of experience analyzing threat intelligence and behavioral signals to drive real risk reduction.

Every Simulated Vishing campaign feeds into a Vish-prone Percentage and rolls into the Risk Score already guiding your security awareness program.

Pass or fail, each simulation can also trigger an automated response, adjusting the difficulty and frequency of future simulations and auto-enrolling high-risk users into remedial vishing training. With 100+ vishing-specific training modules, including quick video micro-lessons and interactive games, you can design remedial training programs for learners of all types.

You can even trigger in-the-moment SecurityTips with Real-Time Coaching, reinforcing training as simulations happen. This continuous learning loop is what makes the difference between discovering risk and actually driving the behavior change that reduces it.

And while bad actors may be re-discovering voice as an attack channel, the methodology behind the KnowBe4 risk reduction loop has a proven track record: the average customer sees the share of employees susceptible to phishing drop from 33.1% to 4.1% within a year.

Attackers are always looking for an edge, and they've found it with voice. With Simulated Vishing, give your workforce real, repeatable practice spotting the red flags before they find themselves in the crosshairs. Schedule a demo today to learn more.

More at the KnowBe4 Blog:
https://blog.knowbe4.com/workforce-blind-spot-vishing

[NEW] Your Guide to Custom Security Awareness Content: The Why and How

Pairing a strong training library with content built specifically for your company, your policies, your risks, your people, is what makes security awareness stick. Training that reflects those things, in your own leadership's voice, builds a different kind of trust.

The best part: you don't need a production background to unlock it. Create content. No studio. No video team. No timeline measured in months.

Join Martin Tschammer, Head of Security at Synthesia, and Erich Kron, CISO Advisor at KnowBe4, for a practical look at exactly how.

You'll walk away knowing:

  • What custom security content needs to cover, from real internal risk scenarios to regulatory requirements
  • How to make it short and digestible enough that people actually watch it and retain it
  • How a consistent, familiar voice and brand shape whether people follow a policy or quietly work around it
  • A simple approach to producing content without a studio, a video team or months of lead time (demo included)

Register now for the steps and tools to make your first custom video in minutes.

Date/Time: Wednesday, Sept. 23, @ 2:00 PM (ET)

Save My Spot:
https://info.knowbe4.com/your-guide-to-custom-security-awareness-content?partnerref=CHN2

Direct Send: How Attackers Weaponize Your Infrastructure Against You

An employee at your company receives an email from hr@yourcompany.com. The domain matches. There is no warning banner. The message asks them to review a payment approval document. They click.

That email was never sent by your HR team. An attacker sent it, and your own Microsoft email infrastructure delivered it, with no password and no credentials required.

How Direct Send Works

Microsoft 365 includes a built-in delivery path called Direct Send. It was designed for a practical, unglamorous purpose: letting office printers, scanners and legacy on-premises applications send email without needing a dedicated account and also bypassing security gateways. To support that, Exchange Online keeps a publicly accessible mail entry point open by default.

Attackers have found that this path works just as well for them. By connecting to that same open endpoint, they can send an email claiming to be from anyone at your organization's HR, accounting, admin or your CEO. The email arrives looking like it came from an internal address, because technically, it entered through your own infrastructure.

Your email security checks notice something is off. The sending source does not match the claimed sender. They log it. But in most organizations, the DMARC policy is set to monitoring mode, meaning the mismatch is recorded and the email is delivered anyway. The attacker counted on exactly that.

[CONTINUED] At the KnowBe4 blog:
https://blog.knowbe4.com/direct-send-how-attackers-weaponize-your-infrastructure-against-you

[MUST-READ ANTHROPIC REPORT] Countering Misuse Of AI: September 2026

It covers real examples including Yemeni actors building guided rockets and ballistic missiles, Malian intelligence creating mass SIM surveillance, Iranian security harvesting identities via fake apps and Chinese groups using AI for zero-day discovery and Uyghur targeting. The report concludes that AI collapses the skill gaps for sophisticated attacks in cyber ops, surveillance, weapons, bio research and influence campaigns, prompting Anthropic to disclose cases and strengthen safeguards.

Read it here:
https://www.anthropic.com/threat-intelligence-report-september-2026


Let's stay safe out there.

Warm regards,

Stu Sjouwerman, SACP
Executive Chairman
KnowBe4, Inc.

PS: Your KnowBe4 Fresh Content Updates from August 2026:
https://blog.knowbe4.com/your-knowbe4-fresh-content-updates-from-august-2026

PPS: Yours Truly in Forbes: Seven Rules For Evaluating Voice AI Research Platforms:
https://www.forbes.com/councils/forbestechcouncil/2026/09/08/seven-rules-for-evaluating-voice-ai-research-platforms/

Quotes of the Week  
"Everything we hear is an opinion, not a fact. Everything we see is a perspective, not the truth."
- Marcus Aurelius - Roman Emperor (121-180 AD)

"All truths are easy to understand once they are discovered; the point is to discover them."
- Galileo Galilei (1564-1642)

Thanks for reading CyberheistNews

You can read CyberheistNews online at our Blog
https://blog.knowbe4.com/cyberheistnews-vol-16-37-bypassing-the-gatekeepers-global-phishing-turns-google-into-a-trust-proxy

Security News

Report: Threat Actors Are Now Using Agentic AI Workflows to Automate Attacks

Threat actors are quickly improving the sophistication of AI-assisted attacks, according to a new report from Google.

These actors are using AI to decrease the time needed for attacks from weeks to just hours. "Google Threat Intelligence Group (GTIG) has observed forward-leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation," the researchers write.

"In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond." In one instance, an attacker used AI agents to conduct a massive credential harvesting operation in under six hours.

"Mandiant observed a suspected financially motivated threat actor compromise an organization's cloud infrastructure to deploy an autonomous, multi-agent attack framework, which allowed the attacker to operate at a scale and velocity typically associated with larger and more resource-heavy groups.

"The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours. Using preconfigured markdown instruction sets as operational playbooks, the threat actor conducted automated scanning and credential harvesting, compromising thousands of third-party credentials.

"The agent instructions enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute Internet Protocol (IP) rotation logic without manual intervention--significantly reducing the human-in-the-loop latency."

Attackers at every level are adopting these tools, from top-tier nation-state actors to unskilled cybercriminals.

"Threat actors continue to misuse Gemini to enhance all stages of their operations, from reconnaissance and phishing lure creation to C2 development and data exfiltration," GTIG says. "Key examples from the last quarter include PRC- and Russia-nexus espionage groups; financially-motivated and espionage-related activity attributed to the Democratic People's Republic of Korea (DPRK); financially-motivated cyber crime groups; and state-sponsored IO groups."

KnowBe4 empowers your workforce to make smarter security decisions every day.

Google has the story:
https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai

Attackers Use Passkey-Themed Phishing to Breach Cloud Environments

Researchers at Microsoft are tracking a social engineering campaign that uses passkey-themed lures to trick users into granting persistent access to their accounts and online work environments.

"The attack often begins with a seemingly routine call or message on a user's personal phone number from someone claiming to be from the organization's IT helpdesk," the researchers write. "The caller creates a sense of urgency, explaining that a passkey, multifactor authentication (MFA) or single sign-on (SSO) configuration must be updated immediately to avoid disruption.

"Employees are directed to a website that closely resembles a legitimate Microsoft sign-in experience and may receive the link through SMS messages sent directly to their personal mobile phones."

The attacker's goal is to trick the victim into performing actions that will allow the attacker to intercept device codes and session tokens, rather than stealing the victim's password.

"Despite the frequent use of passkey-themed lures, passkey enrollment is often not the actor's true objective," Microsoft explains. "Instead, the passkey narrative serves as a convincing pretext to guide victims through adversary-in-the-middle (AiTM) phishing or device-code authentication flows.

"In AiTM scenarios, the actor captures credentials and session tokens; in device code attacks, the victim unknowingly authorizes access on the actor's behalf. This initial interaction may leave very little forensic evidence. If the victim opens the phishing link on a personal mobile device that is not onboarded to Microsoft Defender for Endpoint, the related activity may be absent from endpoint telemetry."

The threat actors behind this activity perform extensive reconnaissance on the targeted organizations to craft highly personalized social engineering attacks. Microsoft attributes the attacks to various threat actors associated with extortion groups.

"Together, the phone-based social engineering, personalized targeting, trusted internal messaging and rapidly changing phishing infrastructure form the opening chapter of a highly coordinated intrusion designed to blend technical deception with human trust," Microsoft concludes.

Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.

Microsoft has the story:
https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/

What KnowBe4 Customers Say

"Hey Bryan, Thanks for reaching out. We have just started using KnowBe4 for phishing simulations and training. Alan A. has been a great resource for guidance on best practices.

"I am very happy with the products and service from KnowBe4. Thank you."

– C.J., Director of Information Technology and Technological Operations

The 10 Interesting News Items This Week
  1. U.S. offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructure:
    https://rewardsforjustice.net/rewards/amir-yaryab/

  2. Singapore Man to Plead Guilty in $263 Million(!) Bitcoin Social-Engineering Theft:
    https://www.blockhead.co/2026/09/08/malone-lam-set-to-plead-guilty-in-263-million-bitcoin-social-engineering-theft/

  3. OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor:
    https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-gpt-6-astra-can-find-zero-days-but-is-also-harder-to-monitor/

  4. Boston Scientific Won't Meet Guidance Due to (probably Ransomware) Cyberattack:
    https://www.wsj.com/business/boston-scientific-wont-meet-guidance-due-to-cyberattack-feb29ee1?

  5. Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023:
    https://www.fincen.gov/system/files/2026-08/FinCEN-Alert-Scam-Centers.pdf

  6. North Korean threat actors use AI to mass-produce phishing lures:
    https://www.genians.co.kr/en/blog/threat_intelligence/ai-agent-opencode

  7. Ukrainian hacker gets four years in US prison over Conti ransomware attacks:
    https://therecord.media/conti-ransomware-ukraine-hacker

  8. Phishing attacks spread mobile ransomware that doubles as spyware:
    https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration

  9. SynkLoader malware spreads via Microsoft Teams phishing:
    https://www.msspalert.com/brief/new-synkloader-malware-distributed-via-microsoft-teams-phishing

  10. Health-ISAC warns of ShinyHunters phishing attacks targeting healthcare organizations:
    https://health-isac.org/urgent-threat-alert-shinyhunters-vishing-campaigns-and-domain-impersonation/

Cyberheist 'Fave' Links
This Week's Links We Like, Tips, Hints and Fun Stuff

Topics: Cybercrime

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, email and collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.