The following content is a press release provided by a third-party.

NordVPN uncovers global phishing campaign impersonating 75+ brands to hijack corporate accounts


Attackers use fake job interviews to seize control of business platforms

NordVPN’s Threat Intelligence research team has identified a phishing campaign that impersonates recruiters from more than 75 global brands to harvest corporate Google Workspace and Facebook Business credentials. The operation deliberately targets marketing and communications professionals rather than finance or IT staff.

A compromised marketing professional's account typically controls Google and Facebook Ads Manager profiles, often with a payment method attached. It also gives access to corporate CMS systems, customer lists, and social media profiles with large follower counts. For attackers, this means immediate monetization. They can burn advertising budgets on malvertising campaigns served from a verified business account, or simply resell the access to other criminals.

Victims are contacted by a fake recruiter, often using the real name and photo of an actual HR employee, and invited to schedule an interview via a page that looks identical to Calendly. During the “booking” process, the victim is prompted to “Sign in with Google.”

ADVERTISEMENT

“The scam is particularly dangerous because it targets a person's professional credibility to gain a foothold in their company,” says Adrianus Warmenhoven, cybersecurity advisor at NordVPN. “The attacker orchestrates a login through a fake window that looks so real the victim never suspects they might be handing over the keys to their company’s internal systems.”

Phishing page impersonating a Disney recruiter
Phishing page impersonating a Disney recruiter, hosted at careers-disney[.]com

The “browser-in-the-browser” trap

The campaign’s success relies on a technique known as browser-in-the-browser (BitB). When a victim clicks a login button, the phishing kit generates an HTML drawing that perfectly imitates a separate browser window. This includes a fake address bar with a security padlock and the correct URL, such as accounts.google.com.

Because the victim believes they are interacting with a genuine prompt, they enter their credentials and approve two-factor authentication (MFA) codes. The attackers relay these codes to the real platforms in real time, allowing them to bypass security measures and obtain a fully authenticated session.

fake sign in with google
Fake "Sign in with Google" window drawn on top of a phishing page impersonating Salesforce, hosted at jobs-salesforce[.]com

Sophisticated infrastructure and brand abuse

The research team found that this is a structured, professional operation rather than a one-off scam, using hundreds of domains in continuous rotation. The hackers rely on a technique that passes their phishing links through multiple legitimate SaaS platforms in sequence. By bouncing through an HR scheduling tool, an email marketing platform, and a CRM platform, they can defeat web filters that only evaluate the first link in a message.

ADVERTISEMENT

NordVPN analysts also discovered that the phishing kit itself was likely built with AI assistance, given the unusually descriptive inline comments and emojis found in the source code.

The campaign has been seen impersonating a wide range of organizations, including:

  • Tech and software: Nvidia, Adobe, Salesforce, and SoundCloud.
  • Retail and apparel: Nike, Adidas, Louis Vuitton, Levi’s, and Sephora.
  • Entertainment and gaming: Disney, Epic Games, and Ubisoft.
  • Food and beverage: Coca-Cola, Starbucks, Heineken, and Red Bull.
  • Travel and hospitality: Booking.com, Marriott, and Expedia.
  • Airlines: American Airlines, Delta Air Lines, Emirates, and United Airlines.
  • Sports and luxury: FIFA, Formula 1, UEFA Champions League, and Lamborghini.
Phishing page impersonating a Nike
Phishing page impersonating a Nike recruiter, hosted at hiring-nike[.]com

How to stay safe

To help job seekers protect themselves, NordVPN’s cybersecurity advisor has recorded a short video with practical tips on recognizing and avoiding recruitment scams: Adrianus_video_2.mp4

Journalists are welcome to embed the video and pictures in their coverage.

Methodology

NordVPN's Threat Intelligence team analyzed the phishing kit’s client-side code and mapped the campaign’s infrastructure, examining domain registration and hosting patterns across hundreds of linked domains. Analysts reviewed redirect chains and identified multiple live command-and-control backend servers used to relay stolen sessions in real time. Internal code components were extracted to assess the campaign’s technical capabilities.

Disclaimer: NordVPN is not endorsed by, affiliated with, or sponsored by Google, Facebook, or any other brand mentioned in this press release. These brand names are included solely to describe the impersonation tactics identified in NordVPN’s research and to help readers recognize how scammers misuse trusted names for phishing.

ADVERTISEMENT

ABOUT NORDVPN

NordVPN is an all-in-one digital privacy and security app trusted by millions of internet users worldwide. The NordVPN app combines the world’s most advanced VPN, a next-generation antivirus, and other built-in security features, such as Dark Web Monitor™, designed to help users stay safer and more private online. NordVPN helps protect against phishing, scams, malicious websites, trackers, intrusive ads, and malware, while strengthening online privacy. For more information, visit nordvpn.com.

Disclaimer

ADVERTISEMENT