Cybercriminals are leveraging a trusted Google resource to launch a widespread phishing assault targeting thousands of educators and students worldwide, according to fresh research from Check Point.
According to the cyber firm’s researchers, the attackers are abusing Google Classroom, a platform designed to connect teachers and students through invitations to join digital classrooms, sending fake ‘invitations’ to take the conversation away from monitoring capabilities.
These emails steer victims to use WhatsApp, a tactic often linked to fraud schemes, by posing as businesses looking for product resellers or SEO experts who promise to bump up a victim’s website ranking.
Over the course of just one week, Check Point discovered the scammers had launched five coordinated waves, distributing more than 115,000 phishing emails aimed at 13,500 organisations across Europe, North America, the Middle East, and Asia.
Researchers said that the success of the phishing campaign lies in leveraging Google Classroom’s infrastructure, with attackers able to bypass security layers and reach the inboxes of thousands of potential victims before defences could kick in.
These stealthy phishing attacks are on the rise across industries, with research from Darktrace earlier this year finding that more than half of all phishing attempts it investigated had managed to pass through all existing security layers before detection.
Recommended reading
- Arctic Wolf Threat Report: Ransomware As A Service On the Rise
- Deepfake Fraud Explodes 2,000% In Three Years
- NHS Staff Don’t Think They’re Cyber Ready, BT Finds
This latest attack on Google Classroom marks yet another escalation in phishing tactics, with threat actors now often reaching victim counts in the hundreds of thousands. One of the most notorious examples is the Darcula phishing-as-a-service operation, which claimed more than 800,000 victims and fuelled luxurious lifestyles for the criminals behind it.
With the Google Classroom campaign ongoing, Check Point warned that organisations should try to harden users against social engineering and caution them to treat any unexpected invitations to take conversations off-platform as a risk.
They should also look to deploy more advanced threat protection tools, including AI-powered defenders, that can analyse the context and intent of these invitations, and look to monitor other cloud applications beyond email.





