TechNewsReel
Live

Phishing Campaign Spoofs 75 Global Brands to Harvest Corporate Credentials

Attackers use AI-assisted kits and 'Browser-in-the-Browser' techniques to target marketing professionals at firms like Nvidia and Disney.

TechNewsReel Newsroom · September 3, 2026

A sophisticated phishing campaign is currently impersonating recruiters from more than 75 global brands to harvest sensitive corporate credentials. The operation specifically targets marketing and communications professionals to gain unauthorized access to corporate CMS systems and Ads Manager profiles.

According to reports from Industrial Equipment News, the attackers are spoofing high-profile names including Nvidia, Disney, Nike, Coca-Cola, and LVMH. The campaign utilizes a "Browser-in-the-Browser" (BitB) technique, which creates a fake login window that mimics legitimate sites such as accounts.google.com. This method allows attackers to spoof the address bar and bypass multi-factor authentication (MFA) in real-time as the victim enters their data.

Technical Sophistication

To evade detection, the campaign employs a chain of legitimate SaaS platforms, allowing the phishing links to bypass standard web filters that typically block known malicious domains. Analysis of the phishing kit indicates that the attackers likely used artificial intelligence to assist in building the infrastructure, increasing the polish and persuasiveness of the lures.

By focusing on Google Workspace and Facebook Business credentials, the attackers are positioning themselves to seize control of high-value corporate assets. The use of recruiter personas provides a plausible reason for contacting professionals, making the initial outreach less suspicious to the targeted employees.

Industry Implications

This campaign highlights a critical shift toward highly targeted Business Email Compromise (BEC) tactics. When attackers gain access to Ads Manager profiles or CMS systems, the consequences extend beyond simple data theft. They can manipulate corporate advertising spend, push fraudulent content to millions of followers, or use the trusted corporate identity to launch secondary attacks against partners and clients.

For the industrial and B2B sectors, the risk is amplified. The ability to bypass MFA via BitB techniques renders traditional security warnings insufficient, as the visual cues users are trained to trust—such as the URL in the browser bar—are effectively forged.

Future Outlook

Security teams are advised to monitor for unusual login patterns within Google Workspace and Facebook Business accounts, particularly among communications staff. As AI continues to lower the barrier for creating convincing phishing kits, the industry expects a rise in these "hyper-realistic" spoofing attempts.

While the exact number of successfully compromised accounts remains unknown, the scale of the impersonation suggests a wide-reaching effort to penetrate the marketing infrastructures of the world's largest brands.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.