Calendly-themed brand-impersonation phishing campaign targeting ad manager accounts
Campaign
Summary
Hide ▲
Show ▼
An ongoing Calendly-themed phishing campaign is impersonating major brands to steal Google Workspace and Facebook business credentials, creating takeover risk for ad and enterprise accounts.
Related Happenings
GPPStorm Google Partners enrollment phishing campaign
Campaign
H score33
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...
GPPStorm Google Partners enrollment phishing campaign
CampaignAbout this happening: GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...
Hotel and hospitality photo-ZIP phishing campaign
Campaign
H score40
First: 26.06.2026 12:27
Last: 26.06.2026 12:27
Sources 1
About this happening:
An active phishing campaign is targeting hotel and hospitality organizations across Europe and Asia, increasing the risk of front-desk machine compromise and durab...
Hotel and hospitality photo-ZIP phishing campaign
CampaignAbout this happening: An active phishing campaign is targeting hotel and hospitality organizations across Europe and Asia, increasing the risk of front-desk machine compromise and durab...
Google Chrome DBSC rolls out session-cookie theft protection for all users
Security Tool/Service
H score10
First: 29.05.2026 15:08
Last: 29.05.2026 15:08
Sources 1
About this happening:
Google's Chrome Device Bound Session Credentials (DBSC) is now generally available and rolling out to all users, reducing the risk of account takeovers from stolen...
Google Chrome DBSC rolls out session-cookie theft protection for all users
Security Tool/ServiceAbout this happening: Google's Chrome Device Bound Session Credentials (DBSC) is now generally available and rolling out to all users, reducing the risk of account takeovers from stolen...
AccountDumpling Google AppSheet Facebook phishing campaign
Campaign
H score31
First: 01.05.2026 21:09
Last: 01.05.2026 21:09
Sources 1
About this happening:
A Vietnamese-linked operation dubbed AccountDumpling is using Google AppSheet as a phishing relay to steal Facebook credentials, enabling account takeover at scale...
AccountDumpling Google AppSheet Facebook phishing campaign
CampaignAbout this happening: A Vietnamese-linked operation dubbed AccountDumpling is using Google AppSheet as a phishing relay to steal Facebook credentials, enabling account takeover at scale...
OAuth device-code phishing campaign targeting SaaS accounts
Campaign
H score43
First: 04.04.2026 17:17
Last: 04.04.2026 17:17
Sources 1
About this happening:
A device code phishing campaign now includes EvilTokens, a phishing-as-a-service kit sold on Telegram that uses the OAuth 2.0 device authorization flow to hija...
OAuth device-code phishing campaign targeting SaaS accounts
CampaignAbout this happening: A device code phishing campaign now includes EvilTokens, a phishing-as-a-service kit sold on Telegram that uses the OAuth 2.0 device authorization flow to hija...
Timeline
-
02.12.2025 16:00 2 articles · 7mo ago
Calendly-themed brand impersonation targets business credentials
Initial DisclosureAn ongoing Calendly-themed phishing campaign impersonates over 75 brands, including Unilever, Disney, MasterCard, LVMH, and Uber, to steal Google Workspace, Facebook Business, and Google MCC ad manager credentials from targeted business users.
Show sources
- Fake Calendly invites spoof top brands to hijack ad manager accounts — www.bleepingcomputer.com — 02.12.2025 16:00
- Fake Calendly invites spoof top brands to hijack ad manager accounts — www.bleepingcomputer.com — 02.12.2025 16:00