Phishing

Google Classroom exploited to facilitate widespread phishing campaign

Google logo on one of the buildings situated in Googleplex, the company's main campus in Silicon Valley

Nearly 13,500 education, healthcare, manufacturing, and finance organizations around the world, particularly in North America, Europe, and Asia, have been subjected to a sweeping phishing campaign exploiting the widely used educational platform Google Classroom earlier this month, GBHackers News reports.

Over 115,000 illicit emails have been delivered as part of the campaign between August 6 and 12, according to an analysis from Check Point researchers. Threat actors have crafted the emails to impersonate real classroom join requests with unrelated commercial lures aimed at deceiving recipients into communicating with an attacker-controlled WhatsApp number, which further cemented the clandestine nature of the operation. Such an attack campaign's reliance on social engineering for external fraud should prompt organizations to strengthen email systems' security defenses with machine learning-based models that could identify potentially malicious content, as well as implement multi-factor authentication, advanced threat protection layers, and regular security awareness training programs, said researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds