GPPStorm Google Partners enrollment phishing campaign
Campaign
Summary
Hide ▲
Show ▼
GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and steal credentials in real time. The lure mimics a legitimate partner-enrollment flow, making the login prompt appear credible. The campaign puts Google account holders at immediate account-takeover risk because captured credentials can be used as soon as they are entered. It combines a named operation, a branded lure, and a direct credential-capture flow.
Related Happenings
Google Account selfie video sign-in and recovery
Security Tool/Service
H score11
First: 23.07.2026 13:00
Last: 23.07.2026 13:00
Sources 1
About this happening:
Google introduced an opt-in selfie video sign-in and account-recovery method for Google Accounts. Users can enroll by recording a short face video with guided head movements, then...
Google Account selfie video sign-in and recovery
Security Tool/ServiceAbout this happening: Google introduced an opt-in selfie video sign-in and account-recovery method for Google Accounts. Users can enroll by recording a short face video with guided head movements, then...
Famous Chollima ClickFake Interview recruitment scam campaign
Campaign
H score34
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
About this happening:
A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...
Famous Chollima ClickFake Interview recruitment scam campaign
CampaignAbout this happening: A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
AccountDumpling Google AppSheet Facebook phishing campaign
Campaign
H score31
First: 01.05.2026 21:09
Last: 01.05.2026 21:09
Sources 1
About this happening:
A Vietnamese-linked operation dubbed AccountDumpling is using Google AppSheet as a phishing relay to steal Facebook credentials, enabling account takeover at scale...
AccountDumpling Google AppSheet Facebook phishing campaign
CampaignAbout this happening: A Vietnamese-linked operation dubbed AccountDumpling is using Google AppSheet as a phishing relay to steal Facebook credentials, enabling account takeover at scale...
Timeline
-
13.07.2026 16:03 2 articles · 13d ago
GPPStorm uses bogus Google partner enrollment lures to steal Google credentials
Initial DisclosurePhishing emails using bogus Google Partners and Google Premier Partner enrollment workflows redirect recipients to a fake Google sign-in page to capture credentials in real time, putting Google account holders at risk of account takeover. The campaign is codenamed GPPStorm.
Show sources
- Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft — thehackernews.com — 13.07.2026 16:03
- Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft — thehackernews.com — 13.07.2026 16:03