iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance Govt Debunks AI-Generated Fake Video of Finance Minister Nirmala Sitharaman Promoting Investment Scheme UPS Unveils Digital Tools to Attract Small Businesses Amid Strategic Shift from Low-Margin E-Commerce CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports Domestic Sugar Prices to Remain Firm in Short-Term, Says Triveni Engineering Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance Govt Debunks AI-Generated Fake Video of Finance Minister Nirmala Sitharaman Promoting Investment Scheme UPS Unveils Digital Tools to Attract Small Businesses Amid Strategic Shift from Low-Margin E-Commerce CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports Domestic Sugar Prices to Remain Firm in Short-Term, Says Triveni Engineering
Home ›› Technology ›› Cybersecurity ›› Phishing campaign exploiting Google Cloud links reaches 12,000 servers worldwide

Phishing campaign exploiting Google Cloud links reaches 12,000 servers worldwide

An investigation by Comparitech revealed a coordinated phishing and spam network spanning 12,704 servers across 55 countries. Attackers use Google Cloud Storage links to evade detection, with fake New York Times pages as decoys. 99.8% of servers run end-of-life software, and 89% had no prior abuse history, indicating a rapidly rotating infrastructure aimed at bypassing traditional security tools.

iG
iGEN Editorial
June 11, 2026
Phishing campaign exploiting Google Cloud links reaches 12,000 servers worldwide

When a suspicious email arrives promising a financial reward or demanding urgent payment, the infrastructure behind it is likely far more elaborate than a simple malicious link. According to an investigation by Comparitech, a coordinated phishing and spam network has been discovered operating across 12,704 servers in 55 countries, all linked to a single campaign that relies on trusted Google Cloud domains to evade detection.

The scale of the operation

The research identified the network through a single CSS file pathassets/ayt/css/main.css — repeated identically across thousands of servers. This pattern, Comparitech reported, points to a centralized deployment rather than independent operators. Of the 12,704 servers identified, 99.8% ran end-of-life software with no active security updates. The servers were spread across 412 hosting providers in dozens of jurisdictions, a geographic spread almost certainly deliberate: takedowns targeting one provider leave the rest of the network intact.

Metric Value
Total servers 12,704
Countries involved 55
Servers running end-of-life software 99.8%
Servers with no prior abuse history 89% (of 5,000 checked)
Hosting providers 412

Checking 5,000 of those servers against a crowd-sourced IP reputation database revealed that 89% carried no prior abuse history. Comparitech noted that this suggests the infrastructure was either recently provisioned or rotated frequently enough to stay ahead of antivirus and threat intelligence systems.

How the phishing campaign works

The campaign begins with unsolicited emails promoting financial rewards, health products, gambling offers, or urgent payment requests through embedded links. Rather than directing recipients immediately to attacker-controlled websites, the links first route through Google Cloud Storage pages hosted on Google's infrastructure. Comparitech explained that this matters because familiar Google domains generally attract less scrutiny from users and automated filtering systems than unknown websites. Google-owned URLs passed easily through email gateways, firewalls, and reputation filters that routinely extend trust to Google domains without deeper inspection.

Researchers found that attackers uploaded simple HTML and JavaScript files to cloud storage locations, allowing them to redirect visitors elsewhere without placing obviously malicious content on Google's servers. This separation between the initial link and the final destination also provides operational flexibility: redirect destinations can be changed at any time without requiring modifications to emails already distributed.

During testing, researchers repeatedly encountered nearly identical landing pages displaying news content copied from The New York Times. These pages appeared designed to serve as harmless decoys for security products, researchers, and visitors who did not meet specific selection criteria.

Consequences for victims

Anyone who entered personal information on any page reached through one of these emails should treat that data as compromised. Comparitech advised that such users must change their passwords immediately, especially where the password is reused across multiple services. It is also important to constantly monitor all financial accounts for unusual activities, no matter how small.

Clicking a link without entering any information still carried a consequence: that click confirmed to the operators that the email address was live and active. This means the email is likely to receive increased volumes of spam in the future, raising the risk of exposure to additional phishing attempts and fraudulent schemes.

Implications for supply chain cybersecurity

For enterprise technology decision-makers, especially those in supply chain and logistics, this campaign highlights the growing sophistication of phishing operations that can bypass conventional email security. Supply chain personnel often receive invoices, payment requests, and shipping notifications—making them prime targets for scams that impersonate trusted partners. The use of Google Cloud as a redirector underscores the need for security awareness training that includes recognizing legitimate-looking but malicious links, even on trusted domains.

The scale—12,704 servers in 55 countries—and the fact that 89% of checked servers had no prior abuse history indicate that threat actors are investing in infrastructure that can evade reputation-based blocklists. Supply chain technology leaders should consider layered defenses: email authentication, URL sandboxing, and user education focused on verifying unexpected financial or shipping requests through secondary channels.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

Hackers Use TikTok Videos Promising Free Spotify Premium to Deploy Malware Technology

Hackers Use TikTok Videos Promising Free Spotify Premium to Deploy Malware

A report from ReversingLabs reveals hackers are using TikTok and Instagram Reels videos offering fake free subscriptions to Spotify Premium, Windows, Office, and Adobe to trick victims into running malicious PowerShell commands. The attack installs the Vidar infostealer, which steals passwords, cookies, session tokens, and cryptocurrency wallet data. This marks a shift from email phishing to social engineering on short-form video platforms.

June 12, 2026
Malware Chain Concealed in Trusted Windows Tools Technology

Malware Chain Concealed in Trusted Windows Tools

A sophisticated malware campaign exploits Google's ad infrastructure to disguise its activities, embedding itself within trusted Windows tools. This five-stage attack leverages legitimate processes to evade detection.

June 10, 2026
Google Selfie Video Sign-In Offers Account Recovery, Enterprise Implications Technology

Google Selfie Video Sign-In Offers Account Recovery, Enterprise Implications

Google has rolled out a new selfie video sign-in option for account recovery, allowing users to verify their identity with a short video. The feature includes liveness detection to prevent deepfake attacks and offers users control over whether their data is used for training. For enterprise security teams, the method demonstrates evolving authentication approaches beyond traditional passwords and passkeys.

July 23, 2026
New LLM Framework Detects Phishing Emails with Over 90% Accuracy Technology

New LLM Framework Detects Phishing Emails with Over 90% Accuracy

A paper on arXiv introduces LLMPEA, a framework using GPT-4o, Claude Sonnet 4, and Grok-3 to detect phishing emails with over 90% accuracy. The study also reveals vulnerabilities to adversarial attacks, prompt injection, and multilingual attacks, emphasizing the need for hardening before deployment.

June 16, 2026