Cyber Security News

Hackers Leverage Google Classroom in Phishing Attack Targeting Over 13,500 Organizations

A large-scale phishing campaign was conducted by threat actors who abused Google Classroom to distribute over 115,000 malicious emails to more than 13,500 organizations globally.

The campaign uncovered by Check Point unfolded in five distinct waves between August 6 and August 12, 2025, and weaponized the trusted educational platform to bypass conventional security filters.

The attack targeted organizations across various industries in North America, Europe, the Middle East, and Asia.

The effectiveness of the campaign originates from its abuse of a legitimate and trusted service. Attackers created fake “classrooms” and sent invitations from the official no-reply@classroom.google.com email address.

Because the emails originated from a valid Google domain, they were more likely to bypass security gateways that rely on sender reputation and standard filtering rules.

Phishing email leveraging Google Classroom

Instead of legitimate educational content, the malicious invitations contained unrelated commercial lures. As seen in samples of the phishing emails, the messages offered services such as SEO optimization or pitches for product reselling, Check Point said in a report shared with Cyber Security News.

One such lure read, “Hello, we have checked your website and it looks like SEO isn’t working properly… We can rank you in the TOP3 on Google.”

The ultimate goal was to move the conversation to an unmonitored channel. Each email prompted the recipient to contact the scammers via a WhatsApp phone number, a classic social engineering tactic designed to evade enterprise security controls and lead potential victims into fraud schemes.

FeatureDescription
Scale115,000+ phishing emails sent in five waves between August 6–12, 2025.
Targets13,500+ organizations worldwide across various industries in North America, Europe, the Middle East, and Asia.
LureFake Google Classroom invitations with commercial offers unrelated to education, such as SEO services or product reselling partnerships.
Call to ActionDirecting recipients to contact the scammers via a WhatsApp phone number to move the conversation to an unmonitored channel.
Delivery MethodAbusing the legitimate Google Classroom invitation system to send emails from a trusted Google domain, bypassing traditional email security filters.
Phishing email leveraging Google Classroom

The operation demonstrated significant scale and coordination, delivering a high volume of emails in just one week. The use of a widely used collaboration tool like Google Classroom allowed the attackers to reach a broad, multi-sector audience with minimal initial effort.

To counter such threats, security experts recommend the following measures:

  • Enhance User Training: Educate employees to scrutinize all unexpected invitations, even those from trusted services. The presence of non-contextual commercial offers or requests to communicate via personal messaging apps should be treated as major red flags.
  • Deploy Advanced Threat Prevention: Utilize modern, AI-driven security solutions that can analyze the context and intent of a message, rather than relying solely on sender reputation.
  • Extend Security to Collaboration Tools: Ensure that phishing protection extends beyond email to all cloud-based applications and collaboration platforms used within the organization.

As attackers continue to innovate, organizations must adopt a multi-layered defense strategy capable of detecting and neutralizing threats that hide in plain sight.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

8 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

12 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

18 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

24 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

35 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago