- Mass campaign: 115.000 emails in five batches targeting 13.500 companies globally.
- Lure: Fake Google Classroom invitations with commercial offers and redirection to WhatsApp.
- Evasion: Using legitimate Google domains to bypass filters and reach corporate mailboxes.
- Defense: Training, AI-based prevention, and cloud app monitoring as a layered approach.

Check Point Research has uncovered A large-scale phishing operation that leveraged Google Classroom, a service widely used in educational settings, to infiltrate corporate networks across multiple industries.
In just one week, the attackers executed five synchronized rounds who sent more than 115.000 fraudulent messages to some 13.500 organizations in Europe, North America, the Middle East and Asia, exploiting the trust in legitimate Google notifications.
How the campaign operated
The main vector was fake invitations to join classes from Classroom that mimicked the actual flow of the platform, giving the emails a legitimate appearance and metadata.
According to researchers, the activity was concentrated in five waves between August 6 and 12, with a high level of coordination to maximize range and test the resilience of layered defenses.
The messages came from valid Google domains, a circumstance that increases the probability of overcoming reputation-based mail gateways and standard rules.
The campaign crossed borders and industries, impacting companies from multiple sectors and regions, which demonstrates how easily a mass-use service can amplify the attack radius.
Why did it bypass so many filters?
Many security systems tend to grant trust to traffic originating from Google services; when integrated with the native Classroom mechanism, the emails appeared to be routine communications.
This case reinforces a trend: cybercriminals are exploiting SaaS applications and cloud platforms to host or channel their attacks, moving into environments that organizations typically consider safe.
Using a known infrastructure reduced typical red flags and allowed Some messages will reach corporate mailboxes before countermeasures came into effect.
Lures and social engineering tactics
Instead of academic content, the invitations included commercial offers unrelated to education, from product resale to supposed SEO positioning services.
The real objective was move the conversation to WhatsApp, a less supervised external channel in the business environment and common in frauds to circumvent the organization's policies.
Among the baits detected were messages such as: “we have reviewed your website and your SEO is not performing…”, designed to provoke a rapid response and channel the user away from corporate email.
With this strategy, the attackers managed to long range with low initial effort, repurposing a legitimate flow (class invitations) to sow massive decoys.
Scope and chronology of the attack
The operation distributed more than 115.000 emails in a matter of days and affected some 13.500 companies, with reported impact in Europe, North America, the Middle East and Asia.
The operating pattern in five waves It allowed us to measure defensive responses, adjust decoys, and persevere in delivering until we exhausted the windows of opportunity.
Recommendations for organizations
Experts advocate a layered and proactive strategy that combines technology, processes and ongoing training, as well as guides for dealing with campaigns that mimic legitimate traffic.
- Constant training so that employees are wary of unexpected invitations, even from well-known platforms.
- Advanced prevention with AI capable of analyzing context and intent, not just the reputation of the sender or domain.
- Extend protection Beyond email: Covering collaboration tools, messaging, and other SaaS services.
- Raising awareness about diversions to external channels (such as WhatsApp), typical in social engineering tactics.
Likewise, it is recommended monitor cloud applications, activate phishing protection on endpoints and integrate risk signals between email, collaboration, and endpoints to break the attack chain.
Defensive response and market context
Check Point indicated that its technology SmartPhish by Harmony Email & Collaboration blocked most of the detected attempts, with additional defenses preventing the rest from reaching them.
The company has been recognized as leader in the GigaOm Radar for Anti-Phishing, a milestone that falls within the growing competition to detect fraud hidden behind reliable services.
Beyond specific suppliers, the incident puts the spotlight on the evolution from reactive to preventive: Anticipating patterns that exploit legitimate infrastructure will be key to reducing the attack surface.
The case illustrates how High-trust services can be manipulated For global campaigns, combining contextual detection technology, training, and policies that address SaaS abuse is essential to stopping these frauds before they flourish.
