Recruitment-Themed Phishing Campaign Targets Enterprise Users

KnowBe4 Team | Sep 2, 2026

Researchers at Zimperium are tracking widespread phishing campaigns that use Browser-in-the-Browser (BitB) attacks to trick users into handing over their enterprise credentials. The attackers impersonate real HR employees at major companies and target job seekers with extremely realistic interview processes.

“In our sample, the most notably targeted entities span e-commerce, luxury goods, big tech, aviation, and retail, such as: Amazon, Louis Vuitton, Apple, FIFA, Emirates Group, Boeing, Heineken, Deloitte, Central Network Retail Group (CNRG), and Lego, among others,” the researchers write.

Mobile users need to be particularly careful, since phone screens show fewer clues that could signal a phishing attack.

“While desktop users encounter a simulated popup browser window, mobile devices present a unique vulnerability,” Zimperium says. “On smaller screens, the attack automatically adapts, replacing the BitB frame with a full-screen counterfeit login page. Without traditional desktop browser chrome or visible URL bars, mobile victims have virtually no visual indicators to distinguish a fake login from a legitimate OAuth prompt.”

Notably, the phishing kit automatically screens out personal devices in order to target enterprise users. The attackers are intentionally targeting accounts that can serve as a foothold within a company.

“A critical finding in this campaign is the attacker's strict pre-qualification logic,” the researchers explain. “The phishing kit does not process every victim; it actively screens inputs and rejects personal email domains. By enforcing the use of corporate credentials, threat actors specifically target high-value enterprise access. Once inside a single corporate account, attackers gain immediate access to OAuth tokens, internal communications, and cloud applications, enabling rapid lateral movement across the organization.”

AI-native security awareness training can give your employees a healthy sense of suspicion so they can avoid falling for social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce human risk.

Zimperium has the story: https://zimperium.com/blog/extended-rapid-response-zimperium-identifies-recruittrap-recruit-scams-are-targeting-enterprise-credentials-on-mobile

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, email and collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.