A large-scale phishing campaign was conducted by threat actors who abused Google Classroom to distribute over 115,000 malicious emails to more than 13,500 organizations globally.
The campaign uncovered by Check Point unfolded in five distinct waves between August 6 and August 12, 2025, and weaponized the trusted educational platform to bypass conventional security filters.
The attack targeted organizations across various industries in North America, Europe, the Middle East, and Asia.
The effectiveness of the campaign originates from its abuse of a legitimate and trusted service. Attackers created fake “classrooms” and sent invitations from the official no-reply@classroom.google.com email address.
Because the emails originated from a valid Google domain, they were more likely to bypass security gateways that rely on sender reputation and standard filtering rules.
Instead of legitimate educational content, the malicious invitations contained unrelated commercial lures. As seen in samples of the phishing emails, the messages offered services such as SEO optimization or pitches for product reselling, Check Point said in a report shared with Cyber Security News.
One such lure read, “Hello, we have checked your website and it looks like SEO isn’t working properly… We can rank you in the TOP3 on Google.”
The ultimate goal was to move the conversation to an unmonitored channel. Each email prompted the recipient to contact the scammers via a WhatsApp phone number, a classic social engineering tactic designed to evade enterprise security controls and lead potential victims into fraud schemes.
| Feature | Description |
|---|---|
| Scale | 115,000+ phishing emails sent in five waves between August 6–12, 2025. |
| Targets | 13,500+ organizations worldwide across various industries in North America, Europe, the Middle East, and Asia. |
| Lure | Fake Google Classroom invitations with commercial offers unrelated to education, such as SEO services or product reselling partnerships. |
| Call to Action | Directing recipients to contact the scammers via a WhatsApp phone number to move the conversation to an unmonitored channel. |
| Delivery Method | Abusing the legitimate Google Classroom invitation system to send emails from a trusted Google domain, bypassing traditional email security filters. |
The operation demonstrated significant scale and coordination, delivering a high volume of emails in just one week. The use of a widely used collaboration tool like Google Classroom allowed the attackers to reach a broad, multi-sector audience with minimal initial effort.
To counter such threats, security experts recommend the following measures:
As attackers continue to innovate, organizations must adopt a multi-layered defense strategy capable of detecting and neutralizing threats that hide in plain sight.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.
Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…
CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…