Threat Intelligence

That Dream Job at Netflix Is a Phishing Page. They Want Your Google Account, Not Your Resume. 

That Dream Job at Netflix Is a Phishing Page. They Want Your Google Account, Not Your Resume. 

Someone pretending to be an Adidas recruiter sent me a meeting invitation last week. At least, that is what the email looked like. The branding was right.  

The recruiter’s name was real. The company logo was there. Everything looked legitimate except for one thing: the link did not go to Adidas. 

Team Cymru analyst Will Thomas documented a phishing campaign on July 6 that impersonates more than 30 major brands, including Adobe, Netflix, Coca-Cola, OpenAI, Adidas, and Louis Vuitton (BleepingComputer, 6 Jul 2026). The targets are marketing professionals. The goal is Google account credentials. The method is a fake job interview. 

The Hook 

The phishing email pretends to be from a recruiter at a well-known company. It uses the real names and pictures of actual recruiters. The email appears to come from PeopleForce, a legitimate HR platform. The link chain routes through multiple legitimate services: PeopleForce to ExactTarget (Salesforce Marketing Cloud) to Wise Agent CRM to the attacker’s landing page. 

The victim who clicks is taken to a page that looks like a meeting scheduler for the brand being impersonated: adidas-hiring[.]com, netflix-jobs[.]com, coca-cola-careers[.]com. There are at least 34 domains. 

To book the interview, the victim is asked to sign in with Google. The sign-in page is a browser-in-the-browser overlay: HTML and CSS rendered inside the phishing page to look exactly like a real Google authentication popup. The credentials go to the attacker. 

The Scale 

At least 34 domains impersonating companies across airlines, food and beverage, apparel, consulting, tech, hospitality, entertainment, and sports. The campaign has been running for at least five months. Early versions used Outlook email addresses with the impersonated company name. The current version uses the legitimate PeopleForce platform for delivery. 

The redirect chain is worth noting: PeopleForce to Salesforce Marketing Cloud infrastructure to Wise Agent CRM to the phishing page. Each hop is a legitimate service. Blocking one hop does not break the chain because the attacker controls the configuration, not the service. 

What to Look For 

If you work in marketing, you are the target. Unsolicited job interview emails from recruiters at major brands should be treated with the same suspicion as any other unsolicited message. Verify through a separate channel. Go to the company’s careers page directly. Do not click the link in the email. 

The browser-in-the-browser technique is hard to spot but has a tell: a real Google sign-in popup opens as a separate browser window, not an overlay within the same page. If the sign-in form is inside the same browser tab as the rest of the page, it is fake. 

Sources 

 BleepingComputer: Phishing Poses as Big-Brand Job Interview to Steal Google Accounts, 6 Jul 2026 – https://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/