Privacy News
The Login Page Was Real. That's How They Got In.
August 2026
Most advice about phishing boils down to one habit: check the address bar, make sure you're on the real login page before typing a password. Google's Threat Intelligence Group just published research on three suspected Russian espionage groups that don't need you to fall for a fake page at all — because the page they send you to is the real one.
How it actually works
The groups, tracked separately as UNC6293, UNC7005, and UNC5976, lure targets with things like fake conference invitations, diplomatic-themed documents, or file-sharing requests — usually sent over encrypted messaging apps rather than email. Clicking through leads to a genuine Google or Microsoft sign-in page. The victim enters real credentials on the real provider's site. Nothing about that step looks wrong, because nothing about it is fake.
The catch happens after authentication. Instead of landing back on a legitimate app, the victim gets redirected to an attacker-controlled cloud project that quietly captures the authentication token — the credential that proves you're logged in, without needing your password again. Some of the same groups also abuse app-specific passwords and device-linking flows on services like WhatsApp, which exist for legitimate convenience but work just as well for an attacker who talks someone into approving one.
Why "check the URL" doesn't catch this one
Standard phishing advice assumes the danger is a fake login page. Here, the login page is genuine at every step you'd normally check — the domain, the padlock, the branding. The compromise happens in what the account approves afterward, not in what it's tricked into typing. Google specifically flagged that these campaigns target personal accounts rather than corporate, domain-joined ones, which matters because personal accounts usually sit outside whatever monitoring an employer's IT team has in place.
Who's being targeted, and what to actually do
The current campaigns are aimed at a fairly narrow set of people — academics, journalists, defense and aerospace workers, government staff, and think-tank researchers across Europe and the US, with some activity concentrated around Ukraine and Armenia. But the technique itself isn't specific to any one target; it works on anyone who can be talked into approving something after a real login.
- Be as skeptical of what an account is asking you to approve after login as you are of the login page itself
- Treat unexpected conference invitations, "shared document" links, and device-linking prompts with the same suspicion as an unexpected password reset email
- Where possible, use hardware security keys rather than app-specific passwords, which are a common target in these campaigns
- Periodically review which third-party apps and devices have standing access to your Google, Microsoft, and WhatsApp accounts, and revoke anything you don't recognize
More from Offgrid Studio
Account takeover is a different problem from the one our apps solve — none of them require an account in the first place, so there's no login to trick you out of. But the underlying lesson applies broadly: convenience features built into legitimate platforms can become attack surface, and it's worth knowing which of your everyday habits an attacker could turn against you.