03/13/2026
Here's a phrase I'd like to stop saying... Phishing campaigns are getting more sophisticated.
Phishing emails used to be easier to spot.
Bad grammar, sketchy links, weird formatting.
Now attackers are using legitimate cloud infrastructure including platforms like Google Cloud to host parts of phishing campaigns. That makes malicious pages look more trustworthy and harder for security tools to block.
Attackers are increasingly using the same tools legitimate companies rely on.
For everyday users and businesses, a few habits still go a long way:
• Double-check login pages before entering credentials
• Be cautious with links in unexpected emails
• Use MFA wherever possible
Phishing hasn’t gone away, just remember it’s just gotten a lot better at blending in.
In recent weeks, a highly organized phishing campaign has surfaced, characterized by its use of legitimate Google infrastructure to bypass standard security filters. I have identified more than 25 …