Google Cloud Phishing!
Cybersecurity researchers have uncovered a new phishing campaign in which attackers exploited Google Cloud’s Application Integration service to send scam emails that appeared fully legitimate. According to Check Point, the emails were sent from an authentic Google address, allowing them to bypass traditional email security filters and land directly in users’ inboxes.
The phishing messages were designed to look like routine workplace notifications, such as voicemail alerts, document access requests, or permission updates, making them difficult for recipients to identify as malicious. By abusing trusted Google Cloud infrastructure, attackers increased the likelihood that users would interact with the emails.
Check out if your email address has ever been compromised in any data breach ever through here.
During a two-week period in December 2025, researchers observed nearly 9,400 phishing emails sent to around 3,200 targets across the United States, Europe, Asia-Pacific, Canada, and Latin America. The campaign primarily targeted industries that rely heavily on automated workflows, including manufacturing, technology, finance, professional services, and retail. Other affected sectors included healthcare, education, media, energy, government, and transportation.
Google has since blocked the misuse of its email notification feature and said additional safeguards are being implemented to prevent similar attacks. Researchers warn that the incident highlights how attackers are increasingly abusing legitimate cloud-based tools to conduct phishing campaigns at scale, without relying on traditional email spoofing techniques.
If you are wondering what phishing is, let us explain in simple terms. Phishing is a cyberattack where criminals impersonate legitimate entities (like banks, companies, or colleagues) via fake emails, texts, or calls to trick you into revealing sensitive information (passwords, credit card numbers) or downloading malware, using social engineering tactics like urgency or authority to gain your trust and steal data for identity theft or financial fraud.

