Find notable cyber news and cases, enriched with sources, timelines, and signals.

GPPStorm Google Partners enrollment phishing campaign

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and steal credentials in real time. The lure mimics a legitimate partner-enrollment flow, making the login prompt appear credible. The campaign puts Google account holders at immediate account-takeover risk because captured credentials can be used as soon as they are entered. It combines a named operation, a branded lure, and a direct credential-capture flow.

Related Happenings

Google Account selfie video sign-in and recovery

Security Tool/Service
H score11 First: 23.07.2026 13:00 Last: 23.07.2026 13:00 Sources 1

About this happening: Google introduced an opt-in selfie video sign-in and account-recovery method for Google Accounts. Users can enroll by recording a short face video with guided head movements, then...

Famous Chollima ClickFake Interview recruitment scam campaign

Campaign
H score34 First: 21.07.2026 12:30 Last: 21.07.2026 12:30 Sources 1

About this happening: A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score37 First: 09.07.2026 17:39 Last: 09.07.2026 17:39 Sources 1

About this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...

Kali365 Microsoft 365 device-code phishing campaign

Campaign
H score46 First: 25.05.2026 15:45 Last: 25.05.2026 15:45 Sources 1

About this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...

AccountDumpling Google AppSheet Facebook phishing campaign

Campaign
H score31 First: 01.05.2026 21:09 Last: 01.05.2026 21:09 Sources 1

About this happening: A Vietnamese-linked operation dubbed AccountDumpling is using Google AppSheet as a phishing relay to steal Facebook credentials, enabling account takeover at scale...

Timeline

  1. 13.07.2026 16:03 2 articles · 13d ago

    GPPStorm uses bogus Google partner enrollment lures to steal Google credentials

    Initial Disclosure

    Phishing emails using bogus Google Partners and Google Premier Partner enrollment workflows redirect recipients to a fake Google sign-in page to capture credentials in real time, putting Google account holders at risk of account takeover. The campaign is codenamed GPPStorm.

    Show sources