A phishing campaign has targeted marketing professionals with fake job interview invitations and scheduling requests that impersonate recruiters from major brands including Netflix, Coca-Cola, Adidas, and FIFA. Researchers said the activity has been ongoing for at least five months and relies on dozens of lookalike domains—at least 34 identified so far—to make the offers appear legitimate and draw victims into the hiring workflow.
The attackers use a multi-step redirection chain to evade detection, abusing legitimate services such as the HR platform PeopleForce and a domain tied to Salesforce Marketing Cloud before landing victims on the final phishing site. That page displays a counterfeit Google sign-in prompt embedded inside the webpage, rather than a real browser authentication window, to capture credentials. Reporting also linked the operation to a similar campaign documented earlier that used Coca-Cola and Ferrari-themed job lures to steal Facebook credentials.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Analysis of the campaign showed attackers routing victims through a multi-step redirection chain that abused legitimate services such as PeopleForce and a domain associated with Salesforce Marketing Cloud. The final phishing page displayed a fake Google login pop-up embedded in the webpage to capture credentials.
Reporting noted a similar campaign documented in April 2026 that used Coca-Cola and Ferrari-themed fake job lures to steal Facebook credentials. This earlier activity was cited as related context for the later marketer-targeting campaign.
A phishing campaign active for at least five months targeted marketing professionals with fake interview invitations and scheduling requests impersonating recruiters from brands including Netflix, Coca-Cola, Adidas, and FIFA. Researchers identified at least 34 lookalike domains used in the operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.