Fake job interviews from 'Adidas', 'Netflix' and 'OpenAI' recruiters are stealing Google logins
A phishing crew is impersonating more than 30 major brands, hiding behind real business software from PeopleForce and Salesforce to trick marketing staff into handing over their Gmail passwords.

Key points
- A phishing operation is impersonating at least 34 major brands, including Adobe, Netflix, Coca-Cola and OpenAI, to steal Google account passwords from marketing professionals.
- The criminals abuse legitimate cloud services: PeopleForce HR software and a Salesforce Marketing Cloud domain (exct.net), bouncing victims through trusted links before landing on a fake sign-in page.
- The campaign has been running for at least five months and uses names and photos of real recruiters at the impersonated companies.
- Victims see a fake Google login popup built with browser-in-the-browser, a technique that draws a counterfeit browser window inside the phishing page itself.
- Team Cymru senior advisor Will Thomas published the domain list and analysis on GitHub.
The pitch is flattering: a recruiter at a brand you know wants to talk about a marketing job. The email looks like it came from a real HR system, and the calendar link checks out too.
It's all bait.
Security researcher Will Thomas of Team Cymru has tracked a phishing campaign, first reported by BleepingComputer, that impersonates recruiters at more than 30 big-name companies to steal Google account credentials. The targets are marketing professionals. The lure is a fake job interview.
How does the scam actually work?
The criminals send an email pretending to come from PeopleForce, a real cloud-based HR platform companies use to manage hiring. Because the sending infrastructure is legitimate, the message clears many spam filters.
Click the calendar link and you're bounced through a chain of trusted services: first to exct.net, a domain Salesforce operates through its Marketing Cloud product (formerly ExactTarget); then to wiseagent.com, a real estate CRM tool; and finally to the attacker's page, something like adidas-hiring.com. That page looks like a meeting-scheduling site. To book the interview, it asks you to sign in with Google.
The sign-in window that pops up isn't a real browser window. It's drawn inside the phishing page using ordinary web code (HTML and CSS), a trick researchers call browser-in-the-browser. Type your password and it goes straight to the criminals. Salesforce's own infrastructure appeared in a different context in our June reporting on the Klue OAuth breach, a reminder that trusted platforms make effective cover for attackers.
Which brands are being impersonated?
Thomas identified at least 34 lookalike domains covering airlines and travel (American Airlines, Booking.com, Delta, United), food and drink (Coca-Cola, PepsiCo, Red Bull), fashion and luxury (Adidas, Louis Vuitton, Sephora, Levis), consulting and tech (Adobe, Aquent, ManpowerGroup, McKinsey, OpenAI), hospitality and marketing (Marriott, Omnicom), and entertainment and sport (FIFA, Netflix).
One sample email seen by researchers came from a fake Adidas recruiter named Paulina Manzo, a real person whose name and photo the criminals borrowed to look authentic.
Should you worry if you got one of these emails?
If you clicked and entered your Google password any time in the past five months, change it immediately and enable two-factor authentication, which requires a second code from your phone at login.
Check your Google account's recent activity. Look for logins from unfamiliar locations.
Real recruiters don't need your Gmail password to book a meeting. If a scheduling page demands a Google sign-in before showing you a calendar, close the tab.
How the criminals got access to PeopleForce and Salesforce's legitimate services isn't clear. They may have signed up as ordinary paying customers or used stolen credentials from a previous breach. Neither platform was compromised. The abuse works because both services are trusted, and trust is exactly what a phishing crew needs to borrow.
The detail worth watching here isn't the browser-in-the-browser trick, which has appeared in campaigns before. It's the layered redirect chain through two unrelated legitimate platforms. That construction makes domain-based blocking nearly useless and puts the full burden of detection on the individual who receives the email.



