The Link Says Google. That Doesn't Mean the Destination Is Safe.

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
KnowBe4 Threat Lab reported a phishing campaign that routes people through trusted Google services before reaching credential-harvesting or remote-access pages. Here is what UK SMEs should learn without treating every Google link as suspicious.
One of the oldest pieces of phishing advice is also one of the most useful: check the link before you click it.
That advice still matters. A strange domain, a misspelt company name or a link that has nothing to do with the supposed sender should all raise questions. But a recent KnowBe4 Threat Lab report shows why checking only the first visible domain is no longer enough. A phishing journey can begin on legitimate, trusted infrastructure and still end at a malicious destination.
The key distinction
A legitimate link and a legitimate destination are not the same thing.
The link looks legitimate — and that is the point
KnowBe4 Threat Lab reported an active phishing campaign that routes people through legitimate Google services and redirect paths before sending them to attacker-controlled infrastructure. The researchers say the final page can be used to harvest credentials, while some variants can lead to the installation of a remote-access tool.
The important point is not that Google has been hacked, or that Google links are generally unsafe. The reported abuse is of trusted infrastructure and redirect mechanisms as part of a wider attack chain. A trusted road can still lead somewhere dangerous if the destination changes after the journey has begun.
KnowBe4 Threat Lab: Bypassing the Gatekeepers →
What KnowBe4 found
According to KnowBe4's analysis, the campaign uses multiple Google properties across different redirect routes. That matters because email security gateways, firewalls and automated link scanners may see a familiar, reputable service during inspection rather than the page that a person eventually reaches.
The campaign was observed using familiar lures, including document reviews, expired credentials, package deliveries, payment notifications and voicemail messages. These are not unusual business subjects. They are the sort of requests that can make a busy person click first and ask questions later.
Why the final page can feel convincing
KnowBe4 reports that the landing pages can be personalised using information associated with the victim's email domain. Depending on the variant, a person may see:
- Their organisation's name or logo
- Imagery taken from the organisation's public website
- Their email address already filled into a sign-in form
- A familiar document, delivery, payment or voicemail theme
- Language that matches the browser or the expected audience
Those details do not prove that the page is genuine. They reduce the small moments of friction that normally help someone notice that a request is unusual. We have spent years teaching people to look for trusted domains. Attackers have learned that lesson too.
Why this matters to SMEs
Small businesses often depend on cloud sign-in pages, online document sharing, delivery notifications and supplier payment requests. Staff have also been taught to look for broken branding, poor spelling and unfamiliar domains. Those are still useful signals, but they cannot carry the whole responsibility for phishing protection.
The practical change is simple: assess the request, not only the link. Is the message expected? Does the urgency make sense? Is it asking for a password, payment, document, voicemail review or software installation? Would the sender normally use this route? A familiar-looking page should not override an unusual request.
Does Your Cyber Security Training Actually Work? →
What staff should do differently
- 1Treat unexpected requests for logins, documents, payments, voicemail or deliveries cautiously, even when the first URL looks familiar.
- 2Where practical, open the service independently using a saved bookmark or a new browser tab instead of signing in through the unexpected email link.
- 3Check the final page and the surrounding context, not only the first domain in the chain.
- 4Stop if a routine request suddenly asks you to install remote-access software or run a verification tool.
- 5Verify unusual payment, account or document requests using a separate trusted route, such as a known phone number.
- 6Report the message to the person or team responsible for security. Do not simply delete it and leave colleagues exposed.
Users should not be expected to decode a redirect chain manually. The goal is to notice when the request does not fit the normal process and to give the business a chance to investigate.
MFA helps, but it is not the whole answer
Multi-factor authentication remains an important control. It can make a stolen password less useful, but it should not be presented as an absolute shield against every phishing technique. A person can still approve a convincing prompt, disclose information on a fake page or install unwanted software after following a trusted-looking route.
Where appropriate, businesses should also consider phishing-resistant authentication such as passkeys or security keys. The choice should fit the organisation's devices, recovery arrangements and important applications.
Microsoft Is Making Passkeys the Default: Is Your Business Ready? →
What business owners should ask their IT provider
- Is MFA enforced for Microsoft 365 and other important services?
- Are suspicious sign-ins and unusual identity activity monitored?
- Does email or web security inspect redirect chains rather than trust a link solely because the first domain is reputable?
- Are remote-access tools controlled, approved and monitored?
- Can staff report suspicious messages easily, and who investigates them?
- Do we provide realistic phishing-awareness training and reinforce the reporting process?
The answers should describe layers rather than promise one perfect filter. Email filtering, URL inspection, MFA, identity monitoring, endpoint security, remote-tool controls, user awareness and clear escalation all address different points in the journey.
Microsoft 365 Security Checklist: 7 Controls Every Business Should Review →
Can Someone Pretend to Email Your Customers? →
A legitimate tool can still be used deceptively
KnowBe4 reports that one path in the campaign can lead to ScreenConnect, a legitimate remote-management product. ScreenConnect itself is not malicious, and organisations using it are not automatically compromised. The lesson is broader: an unexpected request to install remote-access software should trigger caution and independent verification, whatever the product name.
The IT Club view
The answer is not to block Google, distrust every redirect or tell staff that link checking is pointless. It is to stop treating the first familiar domain as the final verdict.
If something in an email does not feel right, do not try to untangle the whole attack chain yourself. Verify the request independently or ask your IT provider. If you have clicked or entered information, report it quickly; early information gives the business more options.
Found this useful? Forward it to another business owner.
Source and further reading
This is independent IT Club commentary for UK SMEs based on the KnowBe4 Threat Lab report published on 4 September 2026. Campaign-specific findings above are attributed to KnowBe4's analysis; IT Club has not independently investigated the campaign.
Plain-English Takeaway
A legitimate link and a legitimate destination are not the same thing. Staff should assess the whole request and its context, while businesses use several layers of email, identity, endpoint and reporting controls.
Frequently asked questions
Does a Google link mean an email is safe?
No. A link can pass through legitimate Google infrastructure and later take the browser to an attacker-controlled page. The Google service itself is not evidence of a breach or of malicious intent, but it is also not proof that the final destination is safe.
Should businesses block Google redirects?
No. Blocking Google services broadly would disrupt legitimate work and would not solve the general problem. Businesses should use layered email and web security, inspect the final destination where possible, monitor identities and make unusual requests easy to report.
Does MFA stop trusted-link phishing?
MFA remains important, but it is not an absolute shield against every phishing technique. Stronger phishing-resistant methods such as passkeys or security keys can reduce the chance of credentials being useful to an attacker, especially when combined with sign-in monitoring and sensible access controls.
Is ScreenConnect malicious software?
No. ScreenConnect is legitimate remote-management software. The risk described in the KnowBe4 report comes from deceptive or malicious installation and use. An unexpected request to install any remote-access tool should be independently verified.
Related Articles
Could a Browser Extension Be Reading Your AI Conversations?
Employees use AI chatbots for drafting, research and problem-solving — and sometimes paste in confidential information. The AI provider's privacy terms are not the only risk. A browser extension with the right permissions may already be reading the conversation.
Read articleWhich Apps Can Access Your Google or Microsoft Account?
Signing into another service with Google or Microsoft is convenient — but some applications request far more than basic identity information. That access may remain long after you stop using the service, and changing your password does not necessarily remove it.
Read articleCan AI Find Cyber Threats Hiding on the Dark Web?
Cyber criminals discuss companies, sell stolen credentials, advertise network access and publish stolen data across underground forums and ransomware leak sites. The difficult part has never been collecting that information — it has been deciding which fragments genuinely matter. Google is using Gemini to try to answer that question.
Read article