Back to news
Cybersecurity Alert
September 8, 2026 by EmailMeNow IT Consulting

Hackers Are Hiding Scam Emails Behind Trusted Google Tools

Scammers route fake work emails through real Google services before a sign-in page or remote-access install. Google is not reported hacked. Audits (ideal 100%): connectwise.com 77%, knowbe4.com 73%, microsoft.com 71%, google.com 55%.

Source: KnowBe4 Threat Lab · Paubox · Mimecast

NewsPhishingGoogleMicrosoft 365MFAYubiKeyAuthenticator AppsCybersecurity
Office laptop showing a work inbox with a shared-document email and a sticky note that says type the site yourself

KnowBe4 Threat Lab published on September 4, 2026 that an active campaign sends work-looking mail — shared documents, mailbox expiry, deliveries, bills, voicemail — then routes the click through real Google services before a harmful sign-in page. Paubox summarized the same trust-proxy pattern. Google is not reported hacked. The first hops inherit Google’s reputation, so mailbox filters and people both see a familiar hostname.

This is feature abuse, not a Google outage. It is not a duplicate of Gmail recovery-contact injection (a real Google-authenticated message with a fake review link). It is also not ChatGPT share-link malware or Chameleon search-result phishing. Those are different delivery paths.

Office laptop showing a work inbox with a shared-document email and a sticky note that says type the site yourself

Snapshot

FieldDetail
PatternReal Google hops, then a fake work sign-in or remote-access lure
Who is at riskAnyone who uses email for work — especially shared docs, account alerts, deliveries, bills, voicemail
Google statusNot reported breached
CourtListenerNo matching campaign dockets as of Sept 8, 2026

Who is at risk

Anyone who uses email for work. KnowBe4 says the observed templates hit manufacturing, government, finance, and non-profits. The subject lines look like everyday office mail.

What to watch for

  1. An unexpected “review this document,” “mailbox expires today,” “package waiting,” “payment received,” “benefit update,” or “new voicemail” message.
  2. A link that starts on a Google property (Meet, Search, ads, Custom Search, Tag Manager, or Analytics) and then leaves Google.
  3. A sign-in page that already shows your work email, your company name, or a live screenshot of your own website.
  4. A first password attempt that “fails,” then asks you to type it again.
  5. A fake identity verification prompt that wants you to run or install software.

Hover is not enough. The first hop is supposed to look clean. Type google.com, workspace.google.com, or your own Microsoft 365 / document host yourself.

Printed email with a circled link beside a notepad that says first hop looks trusted

What the researchers described

KnowBe4 says every URL in this wave starts on legitimate Google-owned infrastructure. Mail gateways that inspect hop-by-hop therefore see trusted names until a person finishes the chain. Mimecast treats Google redirect abuse as a durable class of phishing, not a one-off kit.

After the last Google hop, KnowBe4 says the page can:

  • Pull a live company logo and website screenshot from the address in the link
  • Check that the email domain has real mail records (to skip sandboxes)
  • Show a Microsoft-styled sign-in, sometimes with a device pairing code instead of a password
  • Or show a fake identity check that installs ScreenConnect, a legitimate remote-access tool, on the PC

We are not publishing attacker hostnames, sample links, hashes, or install steps. Report a suspicious message to your IT team or mail provider and let them hunt.

A hardware key does not save you if you type the password on the fake page, approve a device code, or install the remote-access prompt. MFA still cuts a lot of follow-on reuse against the real Google or Microsoft login.

What to do

  1. Do not click the link. Open the real app or type the company site yourself.
  2. If you already clicked: do not enter a password or a device code. Close the tab.
  3. If you typed a password: change it on the host you typed, revoke sessions, and tell IT.
  4. If you ran an “identity verification” installer: disconnect, call IT, and treat it as a possible remote-access foothold. KnowBe4 says that path can survive a later password reset.
  5. Report the message. Do not forward the raw link in a way that invites a colleague to click it.

MFA: YubiKey and Google Authenticator

Grades match our MFA directory. Strong MFA on the real account does not stop a paste-in password on a lookalike page.

GradeMeaning
FailDocumented second factor is SMS, voice, or email OTP — or no public path
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PlatformGradeYubiKeyAuthenticator
Google AccountStrongYesYes
Microsoft AccountStrongYesYes
KnowBe4PassNoYes
ScreenConnectStrongYesYes

Google documents security keys, Google Authenticator / 2-Step, and passkeys. Microsoft documents a security key. KnowBe4 names Google Authenticator (and Authy / LastPass) — Pass, not Strong. ConnectWise ScreenConnect names YubiKey and Google Authenticator. That protects the admin console. It does not stop a user from installing a rogue ScreenConnect agent from a fake prompt.

Directory: MFA support directory · Category → Email & Identity and Business Apps.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key and phone authenticator beside a note that MFA does not stop a fake sign-in page

Independent cybersecurity audits

We audited the official Google, Microsoft, KnowBe4, and ConnectWise hosts on September 8, 2026. 100% is the idealnone reach it. These scores are public email / transport / website posture. They do not mean Google was breached.

OrganizationDomainOverallvs 100%
ConnectWiseconnectwise.com77%−23
KnowBe4knowbe4.com73%−27
Microsoftmicrosoft.com71%−29
Googlegoogle.com55%−45
DomainIdentityTransportWebsite
connectwise.com75%15%87%
knowbe4.com75%45%68%
microsoft.com90%70%37%
google.com50%70%37%

Audit links: connectwise.com · knowbe4.com · microsoft.com · google.com

google.com at 55% is the product host, not proof the campaign used a spoofed Google From line. KnowBe4 says the first hops are Google. connectwise.com Transport 15% is mail-transport posture on the ScreenConnect vendor — not a finding that ScreenConnect itself was hacked.

Domain audit scoreboard versus the 100 percent ideal

Website stack note

Passive website-tech probes on September 8, 2026:

DomainStack signal
google.comStack undetected; Google Trust TLS expires 2026-10-09 (30d); HTTP→HTTPS redirect not confirmed
knowbe4.comHubSpot (vendor-managed); Amazon Trust TLS expires 2027-03-14
microsoft.comStack undetected; Microsoft TLS expires 2027-01-17
connectwise.comStack undetected; Google Trust TLS expires 2026-12-01

Point-in-time only. A live marketing homepage is not a forensic finding on the redirect hops.

Blacklist and lookalike domains

Email blacklist checks (public DoH, September 8, 2026): google.com, knowbe4.com, microsoft.com, and connectwise.com were clear on mail/domain lists we can query. Microsoft and ConnectWise web/CDN IPs showed informational SPFBL notes — not mail-reputation hits. Do not lead as “Microsoft is blacklisted.”

DNS lookalike scans (BEC profile, registered signals only):

Brand scannedTo reviewLikely ownedBEC staging
google.com111103
microsoft.com134170
knowbe4.com3512
connectwise.com2601

High-interest registered names (investigate; not proof this campaign used them):

LookalikeTechniqueNote
logingoogle.comphishing-hostBEC staging (NS + MX)
googl3.comhomoglyphBEC staging (NS + MX)
knoowbe4.cominsertionBEC staging (NS + MX)
connectwise.nettld-swapBEC staging (NS + MX)
login-microsoft.comaffixLive NS + A + MX

Type google.com and your real Microsoft 365 host, not a one-letter swap. Continuous monitoring: Cybersquat Domain Monitoring.


Run a free audit at audit.emailmenow.com or contact EmailMeNow for DMARC / MTA-STS and phishing response aimed at the 100% ideal.


Sources: KnowBe4 Threat Lab, Sept 4, 2026 · Paubox · Mimecast — Google redirect abuse · Google security keys / Authenticator / passkeys · KnowBe4 MFA apps · ConnectWise account security. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 8, 2026. Domain scores: audit.emailmenow.com only. No IoC dump.