Phishing Scam Targeting WordPress Agencies via Fake Google OAuth
Notify all agencies to avoid clicking the fake Google OAuth link and do not send credentials.
Notify all agencies to avoid clicking the fake Google OAuth link and do not send credentials.
Summary
A phishing campaign targeted WordPress agencies with a polished social‑engineering attack. The attacker began with a legitimate‑looking form submission, including a realistic budget range and business name. The prospect then sent a multi‑page technical specification that mimicked a procurement document. After a few days the attacker sent a link to a staging environment and asked the agency to complete a Google authorization, then forward the username and email. The link led to a fake Google OAuth form designed to harvest credentials. The spec was the social‑engineering layer, making the credential request appear natural. The email address used was [email protected]. Agencies should not click the link or send credentials.
Key changes
- Phishing email from [email protected].
- Fake Google OAuth link used to harvest credentials.
- Attack began with legitimate‑looking form submission and budget range.
- Multi‑page technical specification mimicked procurement document.
- Link led to staging environment asking for Google authorization.
- Agencies advised not to click link or send credentials.