Security researcher at Check Point Software has discovered a new phishing via cloud services campaign where cybercriminals exploit trusted SaaS platforms to spread fraudulent emails globally. Over 130,000 emails have been sent to more than 20,000 organizations worldwide.
Unlike traditional phishing attacks that rely on fake domains or malicious links, the attackers have instead abused built-in features in well-known cloud services such as Microsoft Zoom Amazon PayPal and YouTube. By placing untrustworthy content in fields such as account names, subscription information, or invitation messages, the platforms themselves have sent emails that look completely legitimate and pass technical security checks.
The emails often pretend to be about subscription invoices or account changes and urge the recipient to call a specified support number. This way, attackers avoid links altogether and move the scam to a phone call where social engineering takes over. This method makes the attacks significantly harder to detect for both users and automated protection systems.
The current campaign generated over 130,000 phishing emails and impacted more than 20,000 businesses and organizations globally. According to Check Point, this is part of a rapidly escalating trend where cybercriminals are leveraging trusted brands and cloud-based workflows to maximize deliverability, credibility and reach.
How cloud-based phishing bypasses traditional protection
Over the past three months, over 460,000 phishing emails have been linked to this type of SaaS-based abuse. This shows that this is not a temporary increase but a strategic shift in how phishing is carried out. Particularly vulnerable are technology companies, industrial companies and the education sector, where legitimate system notifications are a natural part of everyday life and therefore arouse less suspicion.
– This marks a clear shift in what phishing looks like, says Fredrik Sandström, security expert at Check Point Software. Attackers no longer need to build their own infrastructure or create fake senders. By leveraging trusted cloud services, they automatically inherit trust, making attacks both scalable and harder to stop.
The discovery shows that organizations can no longer assume that properly signed and seemingly authentic emails are automatically secure. As cloud services become the hub for business communications, security solutions are required that can identify when legitimate functions are being used maliciously even when everything looks correct on the surface.
Organizations are therefore urged to strengthen protection against phishing via cloud services through advanced email analysis, behavioral-based security and continuous training of users about new attack methods.








