< Back to situation

[REVISION HISTORY]

Phishing campaigns targeting Google and Microsoft platforms

Updated 2 times since CLSTR started tracking revisions of this situation.

What changed

2026-08-12 09:35 UTC → 2026-08-20 22:34 UTC · added removed

In late July 2026, security researchers documented two linked phishing operations. One spoofed operations spoofing Google Ads MMC synchronization notifications, directing victims to a malicious Blogspot page that harvested credentials. The other abused and abusing Microsoft’s OAuth 2.0 device-authorization flow: a law-firm-styled email with a password-protected PDF led users to a Microsoft-hosted URL that redirected to a phishing site, where attackers used pre-obtained one-time codes flow to hijack Outlook, OneDrive OneDrive, and Teams sessions. Microsoft’s security team later Microsoft reported roughly approximately 7.6 billion email-phishing attempts worldwide in Q2 2026, highlighting noting a surge in attacks delivered via Microsoft Teams and voice-phishing (vishing). At the same time, voice-phishing. Concurrently, CTM360 identified a real-time insurance-account hijacking scheme that leveraged via sponsored Google ads to lure victims to counterfeit insurer login portals, synchronising credential capture with active sessions. The campaign was observed ads, primarily in Saudi Arabia but also in Europe, the United States US, and India. By early August, researchers warned of a new wave that exploits attackers began exploiting authentic Microsoft sign-in pages. Over 200 fake Teams messages, masquerading as internal HR communications, directed users to genuine Microsoft login pages before requesting domains to request permissions for malicious applications, reducing the effectiveness of URL-based detection. applications. In parallel, the Lumma Stealer malware began circulating disguised as circulated via counterfeit film-download executables, harvesting executables to harvest passwords, browser data, cryptocurrency wallet credentials and two-factor authentication tokens from Windows users. Further tokens. Mid-August developments in mid-August indicate show a 49 percent increase in phishing attacks utilizing via calendar invitations over a six-month period. invitations. Attackers exploit the trust in use malicious .ics files on platforms like Zoom, Microsoft Teams, Zoom and Google Calendar by using malicious .ics files that automatically populate user schedules. These campaigns Calendar, often employ employing an ‘end-of-day-blur’ tactic, timing attacks tactic to coincide with target users during periods of high cognitive load load. Further sophistication was identified in a business email compromise (BEC) campaign uncovered by TrendAI. This campaign used personalized spear-phishing emails regarding denied paid-time-off (PTO) requests to increase success rates. bypass multi-factor authentication (MFA). By utilizing adversary-in-the-middle (AiTM) relays to capture live authenticated session tokens, attackers hijacked Microsoft 365 sessions. They then implemented inbox rules to auto-archive vendor emails, allowing them to impersonate suppliers and redirect company payments for approximately 30 days.

Versions

  1. 2026-08-20 22:34 UTC Phishing campaigns targeting Google and Microsoft platforms
  2. 2026-08-12 09:35 UTC Phishing campaigns targeting Google and Microsoft platforms
  3. 2026-08-07 07:04 UTC Phishing campaigns targeting Google and Microsoft platforms

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.