The trap is not the fake brand alone. It starts inside legitimate HR and marketing-cloud services, so the message can look like normal recruiter traffic long before the victim reaches the credential page. That makes simple spoofing checks and weird-sender filters miss the part that matters: trust is being borrowed from real platforms and real identities.
Researchers say the five-month campaign impersonated more than 30 brands, including Adobe, Netflix, Coca-Cola, and OpenAI, and targeted marketing professionals for Google account theft. The operation abused PeopleForce and a Salesforce Marketing Cloud domain, used real recruiter names and photos, and chained redirects through legitimate services before landing on the phishing page.
The risk persists as long as users are taught to trust the early parts of the chain. If a real HR platform and a known cloud service can vouch for the first click, the final fake interview page arrives with far more credibility than a normal spoofed-domain lure.