{"id":526,"date":"2026-07-09T14:10:27","date_gmt":"2026-07-09T08:40:27","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=526"},"modified":"2026-08-21T13:17:29","modified_gmt":"2026-08-21T07:47:29","slug":"fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/","title":{"rendered":"Fake Brand Interviews Use Browser-in-the-Browser Phishing to Steal Google Credentials"},"content":{"rendered":"<p>A new Google account phishing campaign is using fake big-brand job interview lures to steal credentials from marketing professionals. BleepingComputer reported that the campaign impersonates more than 30 brands, including Adobe, Netflix, Coca-Cola, OpenAI, Adidas, McKinsey &amp; Company, Marriott, and FIFA.<\/p>\n<p>The attack starts with recruiter-themed emails that use real recruiter names and images to build trust. Victims are then routed through legitimate services, including PeopleForce and a domain linked to Salesforce Marketing Cloud infrastructure, before landing on an attacker-controlled phishing page.<\/p>\n<h2>How the campaign works<\/h2>\n<p>The attack does not rely on a crude fake login page alone. It begins with recruiter phishing, where the promise of a job interview lowers suspicion and gives the victim a reason to click.<\/p>\n<p>Here\u2019s how the flow works:<\/p>\n<ul>\n<li>The victim receives a recruiter-themed email impersonating a well-known brand.<\/li>\n<li>The message uses a job interview lure to make the interaction feel legitimate.<\/li>\n<li>The link takes the victim through a fake scheduling workflow.<\/li>\n<li>The page asks the victim to continue with Google to proceed with the meeting request.<\/li>\n<\/ul>\n<p>Instead of opening a real Google <a href=\"https:\/\/www.hexnode.com\/blogs\/authentication-vs-authorization-understanding-the-difference\/\">authentication<\/a> window, the site displays a fake sign-in popup inside the phishing page.<\/p>\n<p>This is where browser-in-the-browser phishing enters the chain. The fake Google sign-in window can mimic the look of a real browser popup, but it is actually built with HTML and CSS inside the attacker-controlled page. BleepingComputer identified this as a browser-in-the-browser, or BitB, technique.<\/p>\n<p>This tactic is effective because it challenges common phishing awareness habits. Many users have been trained to look for obvious warning signs such as:<\/p>\n<ul>\n<li>Suspicious domains<\/li>\n<li>Broken branding<\/li>\n<li>Poor formatting<\/li>\n<li>Unusual login pages<\/li>\n<li>Spelling or design errors<\/li>\n<\/ul>\n<p>BitB phishing makes those checks less reliable. The fake popup can look like an OAuth-style sign-in prompt, complete with familiar visual cues. If the surrounding job interview workflow feels legitimate, the user may focus on the apparent Google sign-in window instead of checking whether a real browser-level authentication window has opened.<\/p>\n<p>The redirect chain adds another layer of credibility. When the link appears to pass through legitimate HR, marketing, or CRM services, users may assume the process is safe. This makes simple advice such as \u201ccheck the URL\u201d harder to apply, especially when the visible journey includes platforms employees already recognize or trust.<\/p>\n<h2>Why Google account phishing raises enterprise risk<\/h2>\n<p>A stolen Google account can be far more valuable than a single mailbox. Google Workspace includes business email, Drive cloud storage, Docs, Calendar, Meet, and other collaboration tools, meaning one compromised account may expose communications, shared documents, schedules, and connected workflows.<\/p>\n<p>For enterprises, the risk expands further when Google accounts connect to SaaS tools, analytics platforms, advertising environments, developer resources, or identity workflows. A successful Google account phishing attack can therefore become the opening move for account takeover, data theft, internal reconnaissance, lateral movement, or business email compromise.<\/p>\n<p>The campaign also shows why employee role context matters. Marketing teams often communicate with external agencies, vendors, recruiters, event partners, and platform providers. They may receive more legitimate third-party links than many other departments. Attackers can exploit that normal business pattern by placing phishing activity inside workflows that do not feel unusual.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-Hexnode-UEM.png?format=webp\" class=\"resource-box__image\" alt=\"Why-Hexnode-UEM\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-Hexnode-UEM.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-Hexnode-UEM-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-Hexnode-UEM-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-Hexnode-UEM-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Why-Hexnode-UEM\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why Hexnode UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Discover how Hexnode UEM simplifies endpoint management, strengthens security, and drives business success.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/brochures\/why-hexnode-uem\/'>\n                            Download the brochure\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Where Hexnode fits in the defense strategy<\/h2>\n<p>Stopping Google account phishing takes more than user awareness. Enterprises need layered controls that reduce the impact of stolen credentials and detect suspicious activity early.<\/p>\n<p>Hexnode helps strengthen this defense in three key ways:<\/p>\n<ul>\n<li><strong>Device compliance:<\/strong> Hexnode UEM lets admins define compliance criteria and mark devices non-compliant if they are not <strong>encrypted<\/strong>, do not meet password requirements, are missing required apps, or are identified as jailbroken.<\/li>\n<li><strong>Conditional access:<\/strong> With Microsoft Entra Conditional Access integration, Hexnode can report device compliance status so access to organizational resources can be granted or blocked based on compliant-device requirements for supported Android, iOS, and macOS 11+ devices.<\/li>\n<li><strong>Google Workspace integration:<\/strong> Hexnode can sync Google Workspace user and group inventory and simplify enrollment and user management operations for Windows, Android, macOS, and iOS devices.<\/li>\n<li><strong>Endpoint investigation:<\/strong> Hexnode XDR helps security teams analyze <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-endpoint-telemetry\/\">endpoint telemetry<\/a>, detect suspicious patterns, and investigate post-compromise activity.<\/li>\n<\/ul>\n<p>This matters because stolen credentials should not automatically grant full access. When Conditional Access is configured to require a compliant device, Microsoft Entra ID can use compliance status reported from Hexnode to help grant or block access.<\/p>\n<h2>Conclusion<\/h2>\n<p>This fake interview campaign shows how modern phishing now blends trusted brands, real recruiter identities, legitimate redirects, and polished scheduling pages. It also uses browser-in-the-browser phishing to make credential theft feel like a routine business interaction.<\/p>\n<p>Enterprises should respond with layered defenses such as phishing-resistant MFA, conditional access, device compliance checks, endpoint telemetry, and user verification habits.<\/p>\n<p>The key lesson is clear: Google account phishing is not just an email-security issue. It is an identity, endpoint, and access-control problem. Strong defenses should limit what attackers can do even when credentials are exposed.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Defend Against Modern Phishing Attacks<\/h5><p>Enforce trusted devices, detect threats, and protect credentials with Hexnode UEM and XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is browser-in-the-browser phishing?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Browser-in-the-browser phishing is a tactic where attackers create a fake login popup inside a malicious webpage. The window can look like a legitimate Google sign-in prompt, but it is only an HTML and CSS imitation designed to capture credentials.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How can enterprises protect against Google account phishing?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Enterprises can reduce Google account phishing risk by using phishing-resistant MFA, conditional access, device compliance checks, endpoint monitoring, and user awareness training. These controls help block access from unmanaged devices and detect suspicious activity after credentials are exposed.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A new Google account phishing campaign is using fake big-brand job interview lures to steal&#8230;<\/p>\n","protected":false},"author":6,"featured_media":528,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10,13],"class_list":["post-526","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-phishing","category-identity-abuse","product_category-identity-provider","main_category-featured","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Fake Job Interview Phishing Steals Google Account Credentials<\/title>\n<meta name=\"description\" content=\"Fake recruiter phishing uses browser-in-the-browser tactics to steal Google credentials. Google account phishing needs device-aware defenses.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Fake Job Interview Phishing Steals Google Account Credentials\" \/>\n<meta property=\"og:description\" content=\"Fake recruiter phishing uses browser-in-the-browser tactics to steal Google credentials. Google account phishing needs device-aware defenses.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-09T08:40:27+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-21T07:47:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Fake-Brand-Interviews-Use-Browser-in-the-Browser-Phishing-to-Steal-Google-Credentials.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"Fake Brand Interviews Use Browser-in-the-Browser Phishing to Steal Google Credentials\",\"datePublished\":\"2026-07-09T08:40:27+00:00\",\"dateModified\":\"2026-08-21T07:47:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/\"},\"wordCount\":936,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Fake-Brand-Interviews-Use-Browser-in-the-Browser-Phishing-to-Steal-Google-Credentials.png?format=webp\",\"articleSection\":[\"Phishing\",\"Identity Abuse\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/\",\"name\":\"Fake Job Interview Phishing Steals Google Account Credentials\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Fake-Brand-Interviews-Use-Browser-in-the-Browser-Phishing-to-Steal-Google-Credentials.png?format=webp\",\"datePublished\":\"2026-07-09T08:40:27+00:00\",\"dateModified\":\"2026-08-21T07:47:29+00:00\",\"description\":\"Fake recruiter phishing uses browser-in-the-browser tactics to steal Google credentials. Google account phishing needs device-aware defenses.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Fake-Brand-Interviews-Use-Browser-in-the-Browser-Phishing-to-Steal-Google-Credentials.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Fake-Brand-Interviews-Use-Browser-in-the-Browser-Phishing-to-Steal-Google-Credentials.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Fake-Brand-Interviews-Use-Browser-in-the-Browser-Phishing-to-Steal-Google-Credentials\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Fake Brand Interviews Use Browser-in-the-Browser Phishing to Steal Google Credentials\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Fake Job Interview Phishing Steals Google Account Credentials","description":"Fake recruiter phishing uses browser-in-the-browser tactics to steal Google credentials. Google account phishing needs device-aware defenses.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/","og_locale":"en_US","og_type":"article","og_title":"Fake Job Interview Phishing Steals Google Account Credentials","og_description":"Fake recruiter phishing uses browser-in-the-browser tactics to steal Google credentials. Google account phishing needs device-aware defenses.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-09T08:40:27+00:00","article_modified_time":"2026-08-21T07:47:29+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Fake-Brand-Interviews-Use-Browser-in-the-Browser-Phishing-to-Steal-Google-Credentials.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"Fake Brand Interviews Use Browser-in-the-Browser Phishing to Steal Google Credentials","datePublished":"2026-07-09T08:40:27+00:00","dateModified":"2026-08-21T07:47:29+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/"},"wordCount":936,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Fake-Brand-Interviews-Use-Browser-in-the-Browser-Phishing-to-Steal-Google-Credentials.png?format=webp","articleSection":["Phishing","Identity Abuse"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/","url":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/","name":"Fake Job Interview Phishing Steals Google Account Credentials","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Fake-Brand-Interviews-Use-Browser-in-the-Browser-Phishing-to-Steal-Google-Credentials.png?format=webp","datePublished":"2026-07-09T08:40:27+00:00","dateModified":"2026-08-21T07:47:29+00:00","description":"Fake recruiter phishing uses browser-in-the-browser tactics to steal Google credentials. Google account phishing needs device-aware defenses.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Fake-Brand-Interviews-Use-Browser-in-the-Browser-Phishing-to-Steal-Google-Credentials.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Fake-Brand-Interviews-Use-Browser-in-the-Browser-Phishing-to-Steal-Google-Credentials.png?format=webp","width":1340,"height":700,"caption":"Fake-Brand-Interviews-Use-Browser-in-the-Browser-Phishing-to-Steal-Google-Credentials"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-brand-interviews-use-browser-in-the-browser-phishing-to-steal-google-credentials\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Fake Brand Interviews Use Browser-in-the-Browser Phishing to Steal Google Credentials"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/526","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=526"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/526\/revisions"}],"predecessor-version":[{"id":529,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/526\/revisions\/529"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/528"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=526"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=526"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}