February 25, 2020 By Shane Schick 2 min read

Phishing campaigns aimed at stealing Microsoft user credentials are using Google Forms to dupe potential victims, security researchers warn.

Cybercriminals managed to increase their odds of success by breaking into a legitimate website to host and send bogus email messages, according to a report from Cofense.

The phishing messages masquerade as important alerts from the company’s IT department asking recipients to update their Office 365 suite of applications or face having their account suspended. Clicking on an “Update Now” button in Google Forms after entering their username and password sends the victim’s credentials to the attackers.

Take a Closer Look

The external Google webpage provides an authentic SSL certificate, researchers explained, which makes it even more likely that users will be fooled into complying with the phishing email’s request.

If they take the time to look more carefully, however, Office 365 users might notice some aberrations in the phony Microsoft login page. Some of the tell-tale signs include the use of asterisks rather than letters and capitalizing more than half of the letters on the page. Unlike a legitimate login page where passwords would be obscured, the credentials appear in plain text as a victim types them in. This happens even before they click the “Update Now” button on the form.

Researchers suggested the technique has been used in multiple phishing campaigns, most of which have been discovered over the past several weeks. Google is not alone in having its technology harnessed for nefarious purposes. Just last month researchers uncovered a phishing technique that made use of Microsoft’s Sway application.

Don’t Fall for Fraudulent Google Forms

Unfortunately, most organizations don’t think through how they would react to a successful phishing attempt, which is why simulation exercises can be helpful. Sometimes attackers will still be successful, so ensure remediation measures for phishing attacks are woven into an incident response plan that involves all departments from human resources to IT.

More from

On holiday: Most important policies for reduced staff

4 min read - On Christmas Eve, 2023, the Ohio State Lottery had to shut down some of its systems because of a cyberattack. Around the same time, the Dark Web had a “Leaksmas” event, where cyber criminals shared stolen information for free as a holiday gift. In fact, the month of December 2023 saw more than 2 billion records breached and 1,351 disclosed security incidents, according to research from IT Governance — an increase of 332% and 187%, respectively, over the month of…

How I got started: Incident responder

3 min read - As a cybersecurity incident responder, life can go from chill to chaos in seconds. What is it about being an incident responder that makes people want to step up for this crucial cybersecurity role?With our How I Got Started series, we learn from experts in their field and find out how they got started and what advice they have for anyone looking to get into the field.In this Q&A, we spoke with IBM’s own Dave Bales, co-lead X-Force Incident Command…

Zero-day exploits underscore rising risks for internet-facing interfaces

3 min read - Recent reports confirm the active exploitation of a critical zero-day vulnerability targeting Palo Alto Networks’ Next-Generation Firewalls (NGFW) management interfaces. While Palo Alto’s swift advisories and mitigation guidance offer a starting point for remediation, the broader implications of such vulnerabilities demand attention from organizations globally. The surge in attacks on internet-facing management interfaces highlights an evolving threat landscape and necessitates rethinking how organizations secure critical assets. Who is exploiting the NGFW zero-day? As of now, little is known about the…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today