Google's Free Services and Phishing Campaigns: A Likely Pair

Stu Sjouwerman | Nov 19, 2020

Google Service Phishing CampaignCybercriminals are now launching phishing campaigns that abuse Google's free productivity tools while also using social engineering to trick you into installing malware.

Some of Google's free offerings range from documents, spreadsheets, online forms, and free websites. These tools are primarily used by the education sector, which can be an easy target for the bad guys to infiltrate. A new report released by email security firm ArmorBlox showed how the bad guys are creating these elaborate campaigns that look convincing but avoid any detection of a scam. 

In this example, threat actors are abusing Google Forms to steal your credentials: 

Screen Shot 2020-11-19 at 11.20.47 AM

 

To protect your organization from these types of attacks, it's important to observe subject sensitive emails, especially when it's related to money. Treat all email that have links and/or attachments as suspicious, and report any unsuspecting email to your security team. 

New-school security awareness training can teach your users how to thoroughly examine a suspicious email, and apply their knowledge to everyday tasks. 

Bleeping Computer has the full story

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.