February 25, 2020 By Shane Schick 2 min read

Phishing campaigns aimed at stealing Microsoft user credentials are using Google Forms to dupe potential victims, security researchers warn.

Cybercriminals managed to increase their odds of success by breaking into a legitimate website to host and send bogus email messages, according to a report from Cofense.

The phishing messages masquerade as important alerts from the company’s IT department asking recipients to update their Office 365 suite of applications or face having their account suspended. Clicking on an “Update Now” button in Google Forms after entering their username and password sends the victim’s credentials to the attackers.

Take a Closer Look

The external Google webpage provides an authentic SSL certificate, researchers explained, which makes it even more likely that users will be fooled into complying with the phishing email’s request.

If they take the time to look more carefully, however, Office 365 users might notice some aberrations in the phony Microsoft login page. Some of the tell-tale signs include the use of asterisks rather than letters and capitalizing more than half of the letters on the page. Unlike a legitimate login page where passwords would be obscured, the credentials appear in plain text as a victim types them in. This happens even before they click the “Update Now” button on the form.

Researchers suggested the technique has been used in multiple phishing campaigns, most of which have been discovered over the past several weeks. Google is not alone in having its technology harnessed for nefarious purposes. Just last month researchers uncovered a phishing technique that made use of Microsoft’s Sway application.

Don’t Fall for Fraudulent Google Forms

Unfortunately, most organizations don’t think through how they would react to a successful phishing attempt, which is why simulation exercises can be helpful. Sometimes attackers will still be successful, so ensure remediation measures for phishing attacks are woven into an incident response plan that involves all departments from human resources to IT.

More from

Social engineering in the era of generative AI: Predictions for 2024

5 min read - Breakthroughs in large language models (LLMs) are driving an arms race between cybersecurity and social engineering scammers. Here’s how it’s set to play out in 2024.For businesses, generative AI is both a curse and an opportunity. As enterprises race to adopt the technology, they also take on a whole new layer of cyber risk. The constant fear of missing out isn’t helping either. But it’s not just AI models themselves that cyber criminals are targeting. In a time when fakery…

Change Healthcare attack expected to exceed $1 billion in costs

3 min read - The impact of the recent Change Healthcare cyberattack is unprecedented — and so are the costs. Rick Pollack, President and CEO of the American Hospital Association, stated, “The Change Healthcare cyberattack is the most significant and consequential incident of its kind against the U.S. healthcare system in history.”In a recent earnings call, UnitedHealth Group, the parent company of Change Healthcare, speculated on the overall data breach costs. When all is said and done, the total tally may reach $1 billion…

Remote access risks on the rise with CVE-2024-1708 and CVE-2024-1709

4 min read - On February 19, ConnectWise reported two vulnerabilities in its ScreenConnect product, CVE-2024-1708 and 1709. The first is an authentication bypass vulnerability, and the second is a path traversal vulnerability. Both made it possible for attackers to bypass authentication processes and execute remote code.While ConnectWise initially reported that the vulnerabilities had proof-of-concept but hadn’t been spotted in the wild, reports from customers quickly made it clear that hackers were actively exploring both flaws. As a result, the company created patches for…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today