Phishing Campaign Impersonates Google Careers Recruiters

KnowBe4 Team | Oct 24, 2025

iStock-1199040494-1A phishing campaign is impersonating Google Careers to target job seekers, according to researchers at Sublime Security.

“The scam is simple,” the researchers write. “An adversary sends an ‘are you open to talk?’ message impersonating an outreach email from Google Careers. If the target clicks the link, they’re taken to a landing page designed to look like a Google Careers meeting scheduler. From there, they’re taken to the phishing page.

“What makes this attack particularly interesting is that it is in active development. We have observed threat actors refining and adjusting their tactics and techniques over time, evolving to evade detection.”

The phishing pages are designed to steal users’ Google account credentials, as well as their names, email addresses, and phone numbers. Most of the phishing emails are in English, but the researchers also found samples in Spanish, Swedish, and other languages.

Sublime Security outlines the following red flags associated with this campaign:

  • “Brand impersonation: These messages impersonated Google Careers, but were delivered on non-Google Careers infrastructure.
  • Domain deception: Links to domain that mimics Google branding but is not a Google domain (ex: gteamcareers[.]com).
  • Newly registered domain: The sender and/or links within the message use domains that were registered within the past 30 days.
  • Suspicious sender domain: Misalignment between claimed sender identity (Google Careers) and actual sender domain (varied).
  • Response urgency: Job offers came with vague details, but required immediate action (scheduling a call).
  • Deceptive recruitment outreach: Follows typical job scam patterns with flattering language and limited specifics.”

AI-powered security awareness training can give your employees a healthy sense of suspicion so they can recognize social engineering tactics. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.

Sublime Security has the story.

See PhishER Plus in Action

Keep users safe where the most dangers lie: their inboxes

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.