Google Tasks phishing campaign targets corporate users through fake notifications from Google Tasks, according to Kaspersky. The scheme uses legitimate Google domains to evade email filters. Attackers aim to steal login credentials for unauthorized access.
How the Google Tasks Phishing Campaign Operates
Victims receive emails mimicking Google Tasks notifications with the subject “You have a new task.” These messages suggest the company has adopted the tool. They include urgency elements like high-priority flags and tight deadlines.
Clicking the link leads to a fake “employee verification” form. Users enter corporate credentials there. Attackers then use these for data theft or further attacks. Moreover, the campaign exploits trust in Google’s @google.com domain.
Expert Insights on the Threat
“Google’s vast ecosystem of services gets exploited by scammers. The scheme with Google Tasks is part of a broader trend observed before and continuing into 2026, where cybercriminals misuse legitimate platforms to distribute scams and phishing. Notifications originating from legitimate domains naturally evade many spam and phishing filters, while the social engineering aspect – making it seem like an internal company process – lowers the victim’s guard,”
Roman Dedenok, Anti-Spam Expert at Kaspersky
The discovery occurred on February 26, 2026. Kaspersky noted this as part of ongoing trends. In addition, similar tactics have appeared previously.
Google Tasks Phishing Campaign in Broader Context
Phishing attacks using trusted services rose in recent years. Cybersecurity firms report increased exploitation of platforms like Google. This Google Tasks phishing campaign highlights vulnerabilities in notification systems.
Businesses in Saudi Arabia face growing risks amid digital transformation under Saudi Vision 2030. Consequently, corporate credential theft can disrupt operations. Furthermore, it aligns with global patterns where social engineering bypasses technical defenses.
Recommendations to Counter Phishing Threats
- Treat unsolicited invitations from platforms with suspicion, even from trusted sources.
- Inspect URLs carefully before clicking.
- Avoid calling phone numbers in suspicious emails; use official websites instead.
- Report suspicious emails to providers and enable multi-factor authentication.
Kaspersky, founded in 1997, protects over one billion devices. The company serves nearly 200,000 corporate clients worldwide. Its threat intelligence tracks such evolving tactics.
Future Outlook for Cybersecurity
Experts predict continued misuse of legitimate apps. Apps and services will remain prime targets. Organizations should invest in cybersecurity training. Meanwhile, multi-layered defenses, including machine learning, offer protection. As a result, awareness reduces successful attacks.





