loader image
Modern desk with blurred email, silhouetted hands; glass Google Cloud hosts data; ribbon arrow points to phishing threat.
Google Cloud Hosts Phishing Redirects

A sophisticated phishing campaign exploits Google Cloud by using its storage services to host malicious redirects, making fraudulent emails more convincing. This approach allows attackers to evade standard email security measures by leveraging Google’s trusted domain. Initially detected in March 2026, the campaign employs over 25 distinct phishing emails targeting a single user. These emails use varied social engineering themes, directing recipients to a Google-hosted URL before redirecting them to a separate, harmful website. A malicious file, located in a Google Cloud Storage bucket called “whilewait,” orchestrates these redirects. Victims are deceived into providing financial details, resulting in theft. Identifying emails with links starting with storage.googleapis.com is crucial to recognizing fraudulent communications. Security teams should report abusive GCS buckets to Google’s Cloud Abuse Team, which could disrupt such networks. For more in-depth information, read the full article at the following link:

https://cybersecuritynews.com/phishing-campaign-exploits-google-cloud/

Write a Reply or Comment

Your email address will not be published. Required fields are marked *