Hackers Route Phishing Through Google to Steal Microsoft Credentials

KnowBe4 found hackers abusing trusted Google services to hide phishing pages that steal Microsoft credentials and enable persistent ScreenConnect remote access.

Written By
LT
Liz Ticong
Sep 9, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A familiar Google address in a suspicious email may be exactly what attackers want you to trust.

KnowBe4 Threat Lab uncovered an active, wide-scale phishing campaign that routes corporate targets through legitimate Google services before redirecting them to malicious pages. Researchers found the setup can help links survive early security checks.

The attack becomes increasingly personalized as the redirect chain progresses, with some victims receiving phishing pages tailored to their employer and email address.

Redirect tricks keep the phishing page out of sight

Campaign variants moved through services such as Google Meet, Search, and DoubleClick in different combinations, complicating attempts to block one fixed path. 

Some links also carried targeting details in a part of the URL that earlier services did not receive, keeping useful information away from some automated checks.

Before showing the final phishing page, the attacker-controlled site checks whether the visitor appears to be a real corporate target. Fake human-verification prompts and company-domain checks can reduce the chance that researchers or automated scanners see the malicious page.

Victims arrive at pages built around their own workplace

Visitors who clear those checks can land on a page assembled around their employer. The kit can reportedly pull the company’s real logo and place the login prompt over an image of its public website. Victim email addresses can also arrive pre-filled.

Support for 16 languages points to global targeting. KnowBe4 observed corporate targets across manufacturing and government, as well as finance and nonprofit organizations. Lures included document reviews and mailbox-expiration warnings, among other business messages.

Some sessions lead to fake Microsoft sign-in pages built to capture credentials or device authorization codes. Others use a false identity-verification prompt to install ScreenConnect, a legitimate remote administration tool attackers have abused in other compromises.

ScreenConnect raises the potential damage by giving an attacker interactive access to the endpoint instead of stopping at account theft.

Advertisement

The ScreenConnect path raises the stakes because it can give an attacker interactive access to the endpoint rather than limiting the compromise to stolen account credentials.

Employees should treat familiarity as a reason to verify, not as proof that a request is safe. A legitimate service at the start of a link or a polished login page at the end can still be part of a phishing attack.

Who should actWhat to watch forWhat to do
Employees receiving a suspicious messageUnexpected document, voicemail, or account notices that send you through several pages before asking you to sign inOpen the service directly in its app or website instead of continuing through the message. Report suspicious requests to IT or security.
Anyone who entered credentialsUnexpected sign-in prompts or account activity after clicking a linkChange the password from a known-good device and alert the security team so recent sign-ins and active sessions can be reviewed.
Anyone who installed ScreenConnectAn identity-verification request that installed software or opened remote accessContact IT or security immediately and have the endpoint checked for unauthorized access.
Security and IT teamsTrusted redirects ending at unfamiliar domains, suspicious authentication activity, or unapproved remote access toolsReview affected accounts and sessions, inspect endpoints, check for unauthorized ScreenConnect deployments, and hunt using the published campaign indicators.

Security teams should not stop at a password reset if remote-access software may have been installed. MFA and credential resets can help protect the account, but they do not remove an attacker who already has control of the endpoint through an active remote-access session.

In those cases, the device itself should be treated as potentially compromised and investigated accordingly.

More cybersecurity news: Fake Minecraft sites kept WeedHack in circulation after defenders disrupted the malware operation’s original backend.

LT

Liz Ticong is a technology writer specializing in artificial intelligence, cybersecurity, software reviews, and emerging business technologies. With more than a decade of professional writing experience and over five years contributing technology content for TechnologyAdvice, she helps readers understand complex technologies and evaluate the tools that best fit their needs. Liz has extensive experience researching, testing, and analyzing software platforms, AI tools, and technology solutions. Her work includes in-depth software reviews, buyer’s guides, product comparisons, and technology news coverage designed to help businesses make informed purchasing and implementation decisions. She regularly evaluates AI applications, automation tools, cybersecurity solutions, and business software, providing practical insights based on hands-on testing and research. In addition to her work with TechnologyAdvice, Liz has contributed technology content to leading industry publications, including eWeek and TechRepublic. Her background in technical writing and software analysis enables her to translate complex technical concepts into clear, actionable guidance for both business and technology audiences. Liz holds a bachelor's degree in Broadcast Communication from the Polytechnic University of the Philippines and continues to expand her expertise through ongoing education in artificial intelligence and emerging technologies. Through her writing, she helps readers navigate a rapidly evolving technology landscape with practical, research-driven insights and real-world product analysis.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.