Over a two-week span in December 2025, cybercriminals successfully dispatched more than 9,000 phishing emails to approximately 3,200 organizations across multiple regions, including the U.S. and Europe. These emails, which appeared to be routine notifications from Google Cloud, exploited a legitimate feature within the service, allowing attackers to bypass standard security measures.
The phishing campaign utilized Google Cloud Application Integration's "Send Email" function, enabling messages to originate from a genuine Google address. This authenticity made the emails seem trustworthy, effectively evading spam filters and fooling recipients into believing they were receiving standard workplace communications.
Security firm Check Point reported that the emails mimicked Google's official notification style, complete with familiar fonts and layouts. The messages included claims about voicemails or access to shared documents, further diminishing suspicion among users. As a result, many recipients unknowingly engaged with the malicious content, potentially compromising their sensitive information.