Cloud Security, Identity, Email security

Phishing campaign abuses Google Cloud Application Integration

Email security system identifies phishing attempts, detects suspicious messages, and protects users from data theft and malware through intelligent monitoring and alerts.

Attackers impersonating legitimate Google-generated messages launched a phishing campaign by abusing Google Cloud Application Integration to distribute malicious emails that look like trusted Google apps.

CheckPoint researchers said in a Dec. 22 post that the emails mimic routine enterprise notifications, such as voicemail alerts and file access or permission requests, making them appear normal and trustworthy to recipients.

Based on the observed email characteristics and sender infrastructure, the campaign appears to leverage Google Cloud’s Application Integration “Send Email” task, a feature intended for legitimate workflow automation and system notifications.

According to the researchers, the attackers sent 9,394 phishing emails targeting approximately 3,200 customers starting in mid-December.

Trusted cloud platforms abused

Jason Soroko, a senior fellow at Sectigo, said the exploitation of Google Cloud’s Application Integration service underscores a critical vulnerability inherent in trusted cloud automation platforms, in which attackers weaponize the very tools designed to streamline enterprise connectivity.


Related reading


While development and IT teams legitimately use the Google integration service to synchronize data across disparate SaaS applications and orchestrate complex business workflows, Soroko said threat actors successfully subverted its "Send Email" function to launch high-fidelity phishing attacks from an authoritative Google domain. 

“Because these communications originate from verified infrastructure and bypass standard SPF and DMARC filters, organizations must pivot from reliance on gateway reputation checks to a more granular defense strategy,” said Soroko. “That would include advanced content analysis to inspect message payloads, and rigorous security awareness training to help employees scrutinize unexpected voicemail or permission requests, regardless of the sender's technical authenticity,” said Soroko.



Kevin Surace, chair at Token, added that these attacks do not rely on fake domains or obvious spoofing, the emails originate from real Google-owned infrastructure and pass SPF, DKIM, and DMARC checks by design. Surace said that makes them appear indistinguishable from legitimate system notifications.

“Detection fails because security tools are trained to look for bad domains, malformed headers, or suspicious senders,” said Surace. “None of those signals exist here. This is why auth apps and legacy MFA collapse. They can be relayed in real-time once a user clicks. Only wireless biometric proximity based FIDO2 hardware authentication breaks this chain by cryptographically rejecting spoofed origins outright.”

Randolph Barr, chief information security officer at Cequence Security, said this campaign doesn't show that the cloud provider failed, but rather that it indicates that there’s a gap in shared responsibilities. Barr said IT teams typically regulate access to these services, DevOps teams create and manage the workflows, and security teams establish guidelines for their use and monitor potential misuse. If such responsibilities aren't in sync, Barr said people can exploit trusted automation in ways that extend beyond standard security measures.

Barr said to reduce risk, companies should limit who can set up external emails, use least-privilege access to automation services, and keep track of and report workflow activities like any other API or non-human identity. He said security teams also need to understand how automation features are used, and at the same time, IT and DevOps teams will need guardrails built into configuration and code.

An In-Depth Guide to Cloud Security

Get essential knowledge and practical strategies to fortify your cloud security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds