[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fiYkoj-F4iuc5CsYcjqkzjGWkmTVqb7r1Ym_9riB-Qjk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"5188b6a9-f8e8-4726-b58c-d84c47bc1588","fake-job-interview-phishing-steals-google-credentials-via-browser-in-the-browser-attack","43cda713-2acf-4937-aa6c-b455282adae6","Fake Job Interview Phishing Steals Google Credentials via Browser-in-the-Browser Attack","Attackers are exploiting the trust professionals place in well-known brands by crafting convincing fake job interview scenarios that impersonate over 30 major companies. By abusing legitimate SaaS platforms like Salesforce Marketing Cloud and PeopleForce for delivery, the malicious emails bypass standard reputation-based email filters. The browser-in-the-browser technique renders a fake login popup that appears visually identical to a real Google authentication page, making it extremely difficult for untrained users to detect. This attack highlights that even cautious users can be deceived when attackers weaponize brand credibility and trusted infrastructure simultaneously. Credential theft of this nature can cascade into full account takeovers, data breaches, and lateral movement across connected services.","**Immediate actions:**\n- Enable multi-factor authentication (MFA) on all Google Workspace and corporate accounts to render stolen passwords alone insufficient.\n- Train employees to verify job interview communications by independently contacting the recruiting company through official channels before clicking any links.\n- Report and block any suspicious recruitment emails using your organization's security incident reporting process.\n\n**Long-term improvements:**\n- Conduct regular phishing simulation exercises specifically targeting social engineering lures like fake job offers and brand impersonation scenarios.\n- Implement FIDO2\u002Fpasskey-based authentication to eliminate phishing-susceptible password entry entirely.\n- Establish a verified vendor and recruiter communication policy that mandates all external HR interactions occur through company-approved channels.\n\n**Detection measures:**\n- Deploy browser isolation or anti-phishing browser extensions that can detect and flag browser-in-the-browser overlay attacks.\n- Monitor Google account login activity for anomalous geolocations or device fingerprints and trigger automatic step-up authentication challenges.\n- Integrate email gateway solutions that analyze sending infrastructure reputation, flagging legitimate platforms being abused for phishing delivery.",[12,13,14,15,16,17,18,19,20],"CIS Control 14 - Security Awareness and Skills Training","CIS Control 6 - Access Control Management","NIST SP 800-53 AT-2 (Security Awareness Training)","NIST SP 800-53 IA-5 (Authenticator Management)","NIST SP 800-63B (Digital Identity Guidelines - Phishing-Resistant MFA)","NIST CSF PR.AT-1 (Awareness and Training)","GDPR Article 32 (Security of Processing)","MITRE ATT&CK T1566.002 (Phishing: Spearphishing Link)","MITRE ATT&CK T1185 (Browser Session Hijacking)","published","2026-07-06T22:21:00.806703+00:00","2026-07-06T22:21:00.482+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fphishing-poses-as-big-brand-job-interview-to-steal-google-accounts\u002F","phishing-poses-as-big-brand-job-interview-to-steal-google-accounts-6f6081","Phishing poses as big-brand job interview to steal Google accounts",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]