5 min read By Excello Mail Team

Fake Recruiter Phishing Ring Impersonates 34 Brands and Hides Behind Legitimate SaaS Redirects to Steal Google Logins

Team Cymru has tracked a five-month phishing campaign spoofing 34 companies, including Adidas, Netflix, Coca-Cola and OpenAI, with fake marketing job offers. The attack chains through legitimate SaaS platforms before landing on a Google credential harvesting page, and DMARC on the real brands' domains cannot see any of it.

Will Thomas, a senior advisor at the threat intelligence firm Team Cymru, has spent the past several weeks pulling apart a phishing operation that has been running for at least five months without much attention. The pitch is simple and effective: a recruiting email offering a marketing role at a household-name company, complete with the name and photo of a real employee at that company to make the outreach feel personal. At least 34 brands have been impersonated so far, among them Adidas, Adobe, American Airlines, Booking.com, Coca-Cola, Delta Air Lines, FIFA, Levi’s, Louis Vuitton, ManpowerGroup, Marriott, McKinsey & Company, Netflix, OpenAI, PepsiCo, Red Bull, Sephora and United Airlines. The goal is not a resume. It is a Google account password, and the path to get it runs through a chain of legitimate, properly-hosted SaaS platforms that most security tooling has no reason to distrust.

A Redirect Chain Built Out of Real Infrastructure

What makes this campaign worth studying is not the lure, fake job offers are common, but the delivery mechanism. The phishing emails present themselves as messages from PeopleForce, a genuine cloud-based human resources platform used by real companies to manage hiring. Clicking through does not go straight to a phishing page. It first resolves through exct.net, a domain operated by Salesforce Marketing Cloud following its acquisition of the email platform ExactTarget, then forwards again through wiseagent.com, a cloud CRM built for real estate agents, before finally landing on the actual credential harvesting page. Three hops, three legitimate platforms, none of them the attacker’s own infrastructure. Early versions of the campaign sent from plain Outlook.com addresses with the impersonated company’s name typed into the display field, a technique that costs nothing and needs no domain registration at all.

Why DMARC Never Sees Any of This

None of the 34 impersonated companies have anything to authenticate here, because none of this traffic ever claims to come from their actual domains. The initial email is not spoofed mail from adidas.com or coca-cola.com; it is genuine mail from PeopleForce’s own infrastructure, or a plain Outlook.com account with a display name set to look like one. A brand’s DMARC record, no matter how strictly enforced at p=reject, only judges mail that asserts its domain in the From header. It has nothing to say about a message that never made that claim in the first place. The redirect hops compound the problem: exct.net and wiseagent.com are real, high-reputation SaaS domains with their own established sending history, so any link-reputation or domain-age check a security gateway performs along the way returns a clean result at every step except the last.

Why This Matters for DMARC, Deliverability and Brand Trust

This campaign is a useful reminder that DMARC enforcement is necessary but was never designed to be sufficient on its own against every impersonation pattern. It closes the door on someone sending mail that claims to be from your domain. It says nothing about someone using your name, your employee’s photo and a chain of unrelated SaaS platforms to build something that merely feels like it came from you. For the SaaS platforms themselves, this is also a deliverability and trust problem: PeopleForce, Salesforce Marketing Cloud and Wise Agent did not build their redirect and messaging infrastructure to be a laundering service for credential phishing, but that is exactly the role it is playing here, and every campaign that rides through exct.net or wiseagent.com without being caught quietly erodes the reputation those platforms have built with mailbox providers.

What Brands, Platforms and Job Seekers Should Do Now

Monitor for lookalike domains built around hiring language, not just your brand name. Patterns like “brandname-hiring.com” or “brandname-careers.com” are cheap to register and exactly what this campaign relied on; add these patterns to existing domain-watch tooling rather than assuming brand-name monitoring alone will catch them.

If you operate a multi-tenant platform with open redirects or link-forwarding, audit for abuse. PeopleForce, Salesforce Marketing Cloud and Wise Agent are being used as unwitting intermediaries specifically because their domains carry trust that a freshly registered phishing domain cannot. Any platform whose links can be chained by a third party is a target for the same pattern.

Job seekers should verify recruiter outreach independently of the email itself. Confirm an open role exists on the company’s own careers page and that the named recruiter has a verifiable profile before entering any credentials, regardless of how personalized or well-branded the email looks.

Treat this as a case study for why brand-protection and email authentication have to work together. Full DMARC enforcement on every domain you own remains the correct baseline. It just is not the layer that catches an attacker who never touches your domain at all.

The Takeaway

Thirty-four brands, five months, and not a single spoofed domain among the impersonated companies. This campaign succeeds precisely because it avoids the fight DMARC is built to win and instead borrows credibility from legitimate SaaS infrastructure and a convincingly personalized lure. Strong authentication on your own domains still matters, but this is a reminder that it is one layer in a defense that also needs domain monitoring, platform-abuse reporting, and a healthy dose of skepticism from the people receiving the email.


Excello Mail helps you keep every domain you own fully authenticated and enforced, so attackers can never spoof your name directly, while your team stays free to focus on the impersonation patterns that live outside DMARC’s reach. Sign up for free to Excello Mail to see exactly which sources are sending as you today.