Cybercriminals Exploit Trusted Cloud Platforms to Launch Phishing Attacks Against Financial Firms 

September 2, 2026 | CXO Junction

Leave a Comment / CybersecurityData ProtectionEnterprise TechnologyIndustry News / By cxojunction 

Cybercriminals are increasingly abusing trusted cloud platforms such as Microsoft Azure, Google Cloud, Amazon Web Services, and Cloudflare to launch phishing attacks against financial organizations, making malicious traffic difficult to distinguish from legitimate business activity.

Trusted Infrastructure Phishing attacks targeting financial firms

Cybercriminals are increasingly abusing trusted cloud platforms such as Microsoft Azure, Google Cloud, Amazon Web Services, and Cloudflare to launch phishing attacks against financial organizations, making malicious traffic difficult to distinguish from legitimate business activity. 

This emerging tactic, known as Trusted Infrastructure Phishing, uses legitimate, enterprise-approved services throughout the attack, from delivering phishing messages to stealing credentials. Recent campaigns have abused Google Cloud Application Integration to send phishing emails from genuine google.com addresses, allowing them to pass SPF, DKIM, and DMARC checks. Victims are then routed through Google Cloud Storage links and CAPTCHA gates before reaching fake Microsoft 365 login pages hosted on AWS S3. Attackers have similarly manipulated Microsoft 365 tenant display names and used trusted Microsoft infrastructure to deliver phishing lures. 

Because these campaigns can operate as proxies between victims and legitimate services, attackers can steal session cookies and authentication tokens, making session hijacking harder to detect than traditional password theft. This is particularly concerning for banks and financial firms, where a compromised session can expose sensitive transaction data. Phishing toolkits such as Tycoon2FA, Sneaky2FA, and EvilProxy specialize in session and token theft, while financial organizations already face higher phishing investigation rates than the global benchmark. 

Traditional email gateways and domain-reputation tools offer limited protection because the infrastructure itself is legitimate. Security teams therefore need to focus on post-delivery behavioral signals, including unusual click activity, redirect chains, anomalous authentication events, unexpected login locations, and unusual access timing. Threat intelligence on emerging phishing kits and supply-chain-linked campaigns can also help analysts identify malicious infrastructure before attacks reach production environments. As generative AI makes phishing messages more convincing, the combination of AI-polished lures and trusted cloud infrastructure is creating an increasingly effective attack model. 

For organizations, this shift reinforces the need to move beyond domain-based trust and strengthen behavioral security controls. Cloud access security broker monitoring, regular audits of OAuth and third-party application permissions, phishing-resistant MFA such as FIDO2, continuous authentication monitoring, and strict email authentication policies can improve visibility and reduce the risk of account compromise. Out-of-band verification for financial transactions can provide an additional safeguard against unauthorized activity and financial fraud. 

CXO Junction remains dedicated to providing you with exclusive insights into transformative leadership journeys. Stay tuned for more updates as we continue to bring industry news to you.

Source: Attackers Abuse Trusted Cloud Services to Hide Phishing Attacks Against Financial Organizations The CyberSecurity News https://cybersecuritynews.com/trusted-cloud-services-phishing-attacks/ 

Latest News