Join our Newsletter — 33% off our NHI Course

Google Workspace AiTM phishing and the ad account governance gap

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: A long-running phishing campaign used Calendly-themed lures, AiTM tooling, browser-in-the-browser pop-ups, and targeted anti-analysis checks to steal Google Workspace and Facebook Business access, according to Push Security. The pattern shows how identity front doors, not just inbox filters, now determine whether business ad management accounts can be taken over and reused.

Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “Uncovering a Calendly-themed phishing campaign targeting business ad manager accounts”.

By the numbers:

  • Push Security identified 31 unique URLs associated with the same campaign.

Key questions

Q: What breaks when AiTM phishing reaches the primary enterprise IdP?

A: The main failure is that one successful login can become a bridge into native apps, downstream SSO services, and business systems that were never meant to be controlled by a single stolen session.

Q: Why do attacker-in-the-middle attacks increase Google Workspace account risk?

A: Because they can capture a live authenticated session after the victim has completed sign-in.

Q: What signals indicate a phishing page is designed to evade analysis?

A: Signals include long redirect chains, trusted-host relays, human verification gates such as CAPTCHA or Turnstile, and page elements that change at runtime.

Practitioner guidance

  • Map IdP reach into ad platforms Inventory which Google Workspace or other primary identity accounts can reach ad-management systems, business apps, and SSO-connected tools.
  • Harden sign-in journeys against AiTM relay Require phishing-resistant authentication where possible and look for anomalous handoff patterns such as CAPTCHA gating, repeated login prompts, and browser-in-the-browser behaviour during authentication.
  • Separate revenue-adjacent access from general productivity access Treat ad-management accounts as a distinct governance class with tighter approval, recertification, and monitoring than ordinary collaboration accounts.

Bottom line: A single compromised enterprise identity can become a route into collaboration tools, downstream SSO applications, and ad-management systems.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Identity front doors, not inboxes, are now the control plane for ad-account risk. This campaign shows that the real attack surface is the account that brokers access into collaboration tools, SSO, and business platforms. When Google Workspace is the primary IdP, compromise of that identity is not a single-login event, but a route into the wider business stack. Practitioners should treat IdP governance and ad-account governance as linked controls, not separate queues.

A few things that frame the scale:

  • The IBM/Ponemon 2025 Cost of a Data Breach Report found that phishing-initiated breaches cost an average of $4.8M each.

A question worth separating out:

Q: How should teams govern accounts that manage digital ads?

A: Treat them as business-critical identities, not ordinary user accounts. Put ad-management access under tighter approval, review, and monitoring than standard collaboration access, and make sure the identity that reaches the ad platform is not the same one that unlocks broad enterprise SSO by default.

👉 Read our full editorial: AiTM phishing against Google Workspace exposes ad account risk


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.